Trojan.Win32.Swrort.3_deedb4313c
Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR, GenericInjector.YR (Lavasoft MAS)
Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: deedb4313c88b71db702d48308355009
SHA1: 635962c615e06a3e7231975db0e31062cd56f639
SHA256: 6bf20d100572231167f86602669f05968a5d5e418319107c414c401222d1f737
SSDeep: 12288:p5h2ts3gjgkGXDDmEnTFLg0qEOSqqMhX5z849BjM9nZjoYN Ky8f7Eu6Ob55Vd8l:chASgFLg02G6BjM9Z2uEu6OV5Vdymrw
Size: 979752 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company:
Created at: 2013-09-27 10:25:50
Analyzed on: Windows7Ada SP1 64-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
GoogleUpdate.exe:1652
GoogleUpdate.exe:3992
GoogleUpdate.exe:2400
PlayFreeBrowser.exe:3128
PlayFreeBrowser.exe:556
PlayFreeBrowser.exe:3036
PlayFreeBrowser.exe:3100
PlayFreeBrowser.exe:3708
PlayFreeBrowser.exe:2056
PlayFreeBrowser.exe:3136
PlayFreeBrowser.exe:3120
PlayFreeBrowser.exe:2900
PlayFreeBrowser.exe:1688
PlayFreeBrowser.exe:1884
PlayFreeBrowser.exe:3080
42.0.2311.135_chrome_installer.exe:3312
%original file name%.exe:2636
taskeng.exe:3936
taskeng.exe:3464
MPCBrowserUpdater.exe:1108
MPCBrowserCrashHandler.exe:3684
setup.exe:272
setup.exe:2056
MPCBrowserUpdate.exe:1128
MPCBrowserUpdate.exe:3788
MPCBrowserUpdate.exe:1860
MPCBrowserUpdate.exe:1500
MPCBrowserUpdate.exe:1872
MPCBrowserUpdate.exe:1116
MPCBrowserUpdate.exe:3724
MPCBrowserUpdate.exe:1760
MPCBrowserUpdate.exe:3188
MPCBrowserUpdate.exe:1448
The Trojan injects its code into the following process(es):
PlayFreeBrowser.exe:3592
PlayFreeBrowser.exe:3540
PlayFreeBrowser.exe:992
PlayFreeBrowser.exe:2492
PlayFreeBrowser.exe:3740
PlayFreeBrowser.exe:3336
PlayFreeBrowser.exe:3528
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process GoogleUpdate.exe:2400 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files% (x86)\Google\Update\Install\{09D3F8A5-EB89-4712-A03A-55808701600F}\42.0.2311.135_chrome_installer.exe (336195 bytes)
%Program Files% (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\42.0.2311.135\42.0.2311.135_chrome_installer.exe (317324 bytes)
The process PlayFreeBrowser.exe:3128 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\pdfHandler-local.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\en-US\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-comment.svg (860 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\patch-worker.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\findbarButton-previous.png (371 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-help.svg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-viewThumbnail.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\DECODED_IMAGES (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\tr\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\viewer.js (7784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\pt-BR\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\da\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-newparagraph.svg (403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ru\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon128.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\viewer.html (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\l10n.js (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-paragraph.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon16.png (726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-menuArrows.png (237 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-note.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\vi\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-pageDown.png (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\viewer.css (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-bookmark.png (244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-download.png (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ko\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-presentationMode.png (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\findbarButton-next.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\zh-TW\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\fi\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-pageDown-rtl.png (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\pdfHandler.html (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\hide-xhtml-error.css (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\findbarButton-previous-rtl.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-pageUp.png (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\loading-icon.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\insertviewer.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\shadow.png (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-insert.svg (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-zoomOut.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ja\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\pdfHandler.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\es\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\fr\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\zh-CN\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\findbarButton-next-rtl.png (371 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\sr\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-openFile.png (417 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-pageUp-rtl.png (426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\pl\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\sv\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\lt\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\loading-small.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\cs\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ro\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-search.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-check.svg (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\he\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-viewOutline.png (300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\manifest.json (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon48.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-sidebarToggle.png (349 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ar\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-print.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\build\pdf.js (84591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\nl\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\de\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\debugger.js (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\it\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-zoomIn.png (228 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ca\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\texture.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\DECODED_MESSAGE_CATALOGS (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-key.svg (1 bytes)
The process PlayFreeBrowser.exe:3036 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\libglesv2.dll (720 bytes)
The process PlayFreeBrowser.exe:2492 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\viewer.js (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cookies (1858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\findbarButton-previous.png (371 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\images\login_button_fb.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\fsdata\logo_A.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-insert.svg (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Favicons (2040 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-comment.svg (860 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-download.png (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2170.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\scopes\scope_settings.xml (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\icon16.png (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\000002.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-pageDown.png (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\AF0E.tmp (38551 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ko\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\_locales\en\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\NPSWF32_11_8_800_94.dll (122455 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5473Q0TAYPRDFX6NRM7H.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\game.exe (162302 bytes)
C:\Users\"%CurrentUserName%"\Downloads\farm_frenzy-lp_en.zip:Zone.Identifier (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\json2.js (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\loading-icon.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\CRX_INSTALL\manifest.json (445 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\html\pf_share.zip (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-viewOutline.png (300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\logo_login.png (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\MANIFEST-000002 (69 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2F0E.tmp (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\[clone9900] widget.iml (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History Index 2015-05-journal (15684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\jquery-1.7.2.min.js (1202 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\GRC.crx (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon128.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\sr\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-key.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\facebook.crx (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\pdfHandler.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_ToOd9BrbTNRlHTg (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\000F7F8FAB2D96E6F8CBD5C9A3B4EC90 (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\_locales\en\messages.json (481 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PQ2990XBF0WREJ1BPPTU.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\_locales\ru\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-newparagraph.svg (403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\index (368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Download_new (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9XN2GUMRF2E7XT4U8AO8.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2F2E.tmp (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-viewThumbnail.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\styles\style.css (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\twitter_ON.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Squall.dll (31584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\LOG (46 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon19.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ar\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\all.js (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\findbarButton-next.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\000001.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\icon128.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\FlashPlayer.crx (59260 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\es\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\de\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\patch-worker.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\WIA9QC2H6UG4IKTT8PJK.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\twitter_OFF.png (674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1C66.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\popup.js (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2EED.tmp (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\20A3.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CRX_75DAF8CB7768\manifest.json (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\modules.xml (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\pl\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\CRX_INSTALL\manifest.json (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\facebook_OFF.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Bookmarks.bak (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\login_button_tw.png (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Local Storage\chrome-extension_gjogodjmdfhjnoemjocfpcoddjgnjilo_0.localstorage (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\data_2 (1208 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RD91OO4GHMTH46CIP39P.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\data_0 (274556 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\data_1 (56088 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ru\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cookies-journal (11033 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\twitter_OFF.png (674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-check.svg (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\4437.tmp (298 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-pageDown-rtl.png (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\website.url (249 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\000002.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\33A2.tmp (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\scopes\scope_settings.xml (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\manifest.json (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon19_1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\encodings.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\it\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\share.crx (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\build\pdf.js (9605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Visited Links (376 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\images\loader.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1EOBDSCXEHINOCPLF9UO.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ja\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\back.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\User StyleSheets\Custom.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\workspace.xml (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\findbarButton-next-rtl.png (371 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\f_000001 (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1C46.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\f_000003 (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\styles\style.css (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\LOG (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Top Sites (1952 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\f_000002 (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ro\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\2DB0.tmp (317 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\lt\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\ml.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Favicons-journal (18810 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Certificate Revocation Lists (197 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Login Data (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\findbarButton-previous-rtl.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\4024.tmp (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon48.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\popup.htm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon128.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-zoomIn.png (228 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\script.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PlayFree Browser.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\styles\reset.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon16.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\_locales\en\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\zh-TW\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\GRC.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PL0GYJBHX4X0M5T5SKO2.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\manifest.json (875 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\vcs.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5X4OGA8088NXTMJ22A2U.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\shadow.png (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-zoomOut.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\en.pack (52424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-menuArrows.png (237 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\workspace.xml (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\texture.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\vcs.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\login_button_fb.png (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\images\logo_login.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\_locales\en\messages.json (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-pageUp.png (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-openFile.png (417 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2090.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\modules.xml (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\pt-BR\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\gl.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\contentscript_tw.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\l10n.js (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CRX_75DAF8CB7768\crl-set (12984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Shortcuts (304 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Web Data-journal (2898 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\scripts\popup.js (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Bloom Prefix Set (2196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_R3BJM8AkQLyOEoA (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-help.svg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\_locales\en\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\facebook_OFF.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\icon48.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\D723.tmp (317 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\styles\reset.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2EFE.tmp (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\debugger.js (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Current Tabs (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\fsdata\splash2.jpg (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\README (186 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon48.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-search.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\[clone9900] widget.iml (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\background.html (300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2DD0.tmp (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\zh-CN\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\47A1.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\popup.htm (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\5AB5.tmp (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Shortcuts-journal (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\MANIFEST-000001 (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Cookies-journal (2799 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Current Session (15183 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\cs\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\play.exe (58761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\_locales\ru\messages.json (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\manifest.json (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-pageUp-rtl.png (426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Login Data-journal (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History Index 2015-05 (8680 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_ckRoEQSaVK0G9OY (1644 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\A095.tmp (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\207F.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-bookmark.png (244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\facebook_ON.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\twitter.crx (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\game_icon.ico (392 bytes)
C:\Users\"%CurrentUserName%"\Desktop\Farm Frenzy.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\fsdata\logo_A.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\nl\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DL50Z2U4JW7VRFSDMC25.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5NGZE6LEMNPGDMUSSE07.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\scripts\json2.js (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-presentationMode.png (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\fi\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\vi\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\_locales\ru\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2141.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\fsdata\logo_NA.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\pdfjs.crx (3361 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-sidebarToggle.png (349 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Preferences (521 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\data_3 (9112 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\main_share.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\JNGLoad.dll (25080 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\J4MOJVAMIWNH8CXGP7H1.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_FKtUz2u0dw8ZMH3 (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\misc.xml (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\scripts\jquery-1.7.2.min.js (601 bytes)
C:\Users\"%CurrentUserName%"\Desktop\PlayFree Browser.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\Downloads\favicon.ico:Zone.Identifier (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\hide-xhtml-error.css (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\manifest.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\contentscript.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\viewer.css (33 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\fsdata\splash2.jpg (5952 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\data.pack (971334 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon16.png (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\f_000004 (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\tw.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History-journal (15448 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\pdfHandler-local.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\sv\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2E9E.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\fsdata\logo_NA.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MYZUQOY8LK28EWMSZ2PR.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-print.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\tr\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1D34.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2091.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Top Sites-journal (6616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\ZeroClipboard.swf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\he\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Bloom_new (345668 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\fb.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\en-US\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Local Storage\chrome-extension_gjogodjmdfhjnoemjocfpcoddjgnjilo_0.localstorage-journal (5109 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\background.html (139 bytes)
C:\Users\"%CurrentUserName%"\Downloads\Unconfirmed 761892.crdownload (669378 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\loading-small.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Download Whitelist_new (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\20A2.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\fb_logined.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Csd Whitelist_new (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\loader.gif (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\fr\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\pdfHandler.html (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extensions\cmgompiogmpngbepkhaildjbcedihobe\2_0\GRC.dll (114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2130.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\Downloads\2B33.tmp (9586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\1D14.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\body_bg.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extensions\kmafafaebkfagbfockogghbkjblelpbh\2_0\NPSWF32_11_8_800_94.dll (5823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\da\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\ZeroClipboard.min.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\000003.log (6147 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\encodings.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\First Run (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\contentscript_fb.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\_locales\ru\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\misc.xml (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\insertviewer.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-paragraph.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\scripts\back.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\000001.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\Downloads\21EF.tmp (1651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Cookies (383 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Web Data (1784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\play.url (259 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\_locales\ru\messages.json (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\button_bg.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2XVWUNFBGLPKPOFZB0I7.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-note.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ca\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1CB5.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\000F7F8FAB2D96E6F8CBD5C9A3B4EC90 (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\viewer.html (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\main_share.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_sIpd8OdgdEGRWUc (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\images\login_button_tw.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\MANIFEST-000001 (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\MANIFEST-000002 (69 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History (5020 bytes)
The process PlayFreeBrowser.exe:3100 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\CRX_INSTALL\manifest.json (188 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\CRX_INSTALL\NPSWF32_11_8_800_94.dll (1038046 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\DECODED_MESSAGE_CATALOGS (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\DECODED_IMAGES (20 bytes)
The process PlayFreeBrowser.exe:2056 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\DECODED_MESSAGE_CATALOGS (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\DECODED_IMAGES (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\CRX_INSTALL\GRC.dll (7784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\CRX_INSTALL\manifest.json (172 bytes)
The process PlayFreeBrowser.exe:3136 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\modules.xml (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\DECODED_IMAGES (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\popup.htm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\vcs.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\_locales\en\messages.json (84 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\encodings.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\scopes\scope_settings.xml (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\scripts\back.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\fb_logined.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\facebook_OFF.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images\login_button_fb.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\[clone9900] widget.iml (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\scripts\popup.js (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\scripts\jquery-1.7.2.min.js (6984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images\logo_login.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\styles\style.css (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images\loader.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\facebook_ON.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\scripts\json2.js (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images\login_button_tw.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\_locales\ru\messages.json (84 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\DECODED_MESSAGE_CATALOGS (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\styles\reset.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\contentscript_fb.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\background.html (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\misc.xml (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\workspace.xml (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\manifest.json (960 bytes)
The process PlayFreeBrowser.exe:3120 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\manifest.json (898 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\DECODED_MESSAGE_CATALOGS (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\styles\style.css (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\scripts\jquery-1.7.2.min.js (6984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\scripts\back.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images\loader.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\DECODED_IMAGES (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images\login_button_tw.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\popup.htm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\modules.xml (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images\login_button_fb.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\styles\reset.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\background.html (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\vcs.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\misc.xml (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\scripts\popup.js (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\workspace.xml (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\_locales\ru\messages.json (84 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\scopes\scope_settings.xml (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\contentscript_tw.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\twitter_ON.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\encodings.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\_locales\en\messages.json (84 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\twitter_OFF.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\[clone9900] widget.iml (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\scripts\json2.js (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images\logo_login.png (392 bytes)
The process PlayFreeBrowser.exe:1688 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cookies (4892 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\16C2.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Favicons (4294 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Bookmarks.bak (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1584.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\15F4.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_zJj6ftdxrva1cUX (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_wgLkRtD2zydu15D (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\14C8.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cookies-journal (9804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History-journal (13708 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Web Data-journal (20782 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\000002.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\16B2.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History Index 2015-04-journal (15480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History (15190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Visited Links (284 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_VbhUrA3oYtzthvc (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\16C3.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\icudt.dll (437 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History Index 2015-04 (8776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\16B1.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1498.tmp (463 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_fhZAxJ0OtwgLlzb (3636 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_oqh3IwbKNHmnt6N (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1595.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\LOG (46 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History Provider Cache (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Favicons-journal (16064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\000001.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_Q2PnK9yoBhE4IbV (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Web Data (19725 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Archived History-journal (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\playfreebrowser.dll (5823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Network Action Predictor-journal (1690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\1604.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Network Action Predictor (254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\MANIFEST-000001 (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\MANIFEST-000002 (69 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Archived History (5797 bytes)
The process PlayFreeBrowser.exe:3080 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\jquery-1.7.2.min.js (6984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\ml.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\popup.htm (910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\login_button_tw.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\button_bg.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\all.js (11736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\login_button_fb.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\contentscript.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\background.html (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon48.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon19.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\DECODED_IMAGES (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\json2.js (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\fb.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon19_1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\_locales\en\messages.json (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\tw.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\html\pf_share.zip (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\styles\style.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\gl.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\back.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\ZeroClipboard.min.js (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\loader.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\popup.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\body_bg.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon16.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon128.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\logo_login.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\_locales\ru\messages.json (541 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\script.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\main_share.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\ZeroClipboard.swf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\DECODED_MESSAGE_CATALOGS (1 bytes)
The process 42.0.2311.135_chrome_installer.exe:3312 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\Temp\CR_6C700.tmp\SETUP.EX_ (348 bytes)
C:\Windows\Temp\CR_6C700.tmp\setup.exe (18111 bytes)
C:\Windows\Temp\CR_6C700.tmp\CHROME.PACKED.7Z (45884 bytes)
The process %original file name%.exe:2636 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\gameinfo[1].json (370 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\deedb4313c88b71db702d48308355009\EULA.txt (9084 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\deedb4313c88b71db702d48308355009\InstallLog_deedb4313c88b71db702d48308355009.txt (460558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Bookmarks (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\deedb4313c88b71db702d48308355009\PlayFreeBrowser_EULA.txt (9084 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GamePic.jpg (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\customization[1].json (5576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\GUID (647 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\icon.png (980 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\3.0.0.4\setup.exe (10145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\3.0.0.4\MPCBrowserUpdater.exe (4670 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pf.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\3.0.0.4\chrome.packed.7z (254922 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\VERSION (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\master_preferences (521 bytes)
The process MPCBrowserUpdater.exe:1108 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_te.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_bn.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_es-419.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ml.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_pt-PT.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_bg.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_zh-CN.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_id.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUTFF74.tmp (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_uk.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_mr.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_en-GB.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_th.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ur.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserUpdateOnDemand.exe (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserUpdateHelper.msi (45 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sv.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdate.dll (1702 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sk.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_hi.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_pl.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserCrashHandler.exe (120 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_fr.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_lt.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_vi.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\npGoogleUpdate3.dll (230 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\psuser.dll (162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_fil.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_da.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_hr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_is.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ro.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ru.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_zh-TW.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_nl.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ta.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_it.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_fa.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ja.dll (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_gu.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_kn.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_am.dll (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_hu.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserUpdateBroker.exe (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_cs.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ko.dll (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_en.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_fi.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_et.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_lv.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\psmachine.dll (162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserUpdate.exe (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_iw.dll (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sw.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_es.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_de.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_no.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ms.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_tr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_pt-BR.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ar.dll (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ca.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_el.dll (31 bytes)
The process setup.exe:272 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\th.pak (324 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl_ipc_irt_x86_32.nexe (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\et.pak (160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Installer\setup.exe (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fa.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_frame_helper.exe (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\tr.pak (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\el.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\bg.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\et.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fil.pak (181 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fi.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\en-GB.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sk.pak (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\it.pak (174 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\delegate_execute.exe (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ru.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlayFree Browser\PlayFree Browser.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ml.pak (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\am.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\npchrome_frame.dll (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\te.pak (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ar.pak (229 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\VisualElements\logo.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\uk.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sw.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_touch_100_percent.pak (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fa.pak (234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sv.pak (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\de.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\secondarytile.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hi.pak (328 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\GRC_PLUGIN.crx (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\VisualElements\smalllogo.png (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ar.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl64.exe (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\da.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fi.pak (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sl.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pt-BR.pak (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\icudt.dll (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_launcher.exe (80 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hu.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\bg.pak (273 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\VisualElementsManifest.xml (384 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\lt.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ru.pak (260 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\am.pak (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sr.pak (253 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\es.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ko.pak (181 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\share.crx (218 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sl.pak (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ca.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\lv.pak (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\mr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl_ipc_irt_x86_64.nexe (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ja.pak (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\wow_helper.exe (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\external_extensions.json (661 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\te.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ml.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\nl.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\tr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ro.pak (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\resources.pak (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\playfreebrowser.dll (64956 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ms.pak (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sv.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sk.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\gu.pak (319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\th.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\es-419.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\bn.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\kn.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\nb.pak (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hu.pak (184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ca.pak (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\mr.pak (321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\lv.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\chrome.7z (188259 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\en-GB.pak (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\el.pak (298 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ms.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pt-PT.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\vi.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ta.pak (374 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\zh-CN.pak (151 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ko.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\lt.pak (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\chrome_installer.log (1539 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\VisualElements\splash-620x300.png (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl_irt_x86_64.nexe (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\zh-TW.pak (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\playfreebrowser.exe (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\vi.pak (195 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\he.pak (195 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pl.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\metro_driver.dll (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\FlashPlayer.crx (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PlayFree Browser.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\es-419.pak (178 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\libglesv2.dll (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\en-US.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\gu.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\nl.pak (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\libegl.dll (130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hi.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\he.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\nb.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\de.pak (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\twitter.crx (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\en-US.pak (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\it.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pt-PT.pak (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\app_host.exe (239 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\cs.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\ppgooglenaclpluginchrome.dll (574 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pt-BR.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\da.pak (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ro.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\kn.pak (364 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fil.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\cs.pak (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hr.pak (170 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\es.pak (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\GRC.crx (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\id.pak (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\facebook.crx (93 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\id.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ta.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\uk.pak (261 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ja.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\pdfjs.crx (555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlayFree Browser\Uninstall PlayFree Browser.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\zh-CN.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_frame_helper.dll (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sw.pak (156 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fr.pak (187 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pl.pak (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe (8330 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl_irt_x86_32.nexe (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_100_percent.pak (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\zh-TW.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\bn.pak (332 bytes)
The process setup.exe:2056 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\tr.pak (596 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\fil.pak (611 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\VisualElements\smalllogo.png (21 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\d3dcompiler_47.dll (52 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\fr.pak (637 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\te.pak (1339 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\fi.pak (564 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\search.crx (54 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\secondarytile.png (641 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\kn.pak (1372 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ro.pak (611 bytes)
%Program Files% (x86)\Google\Chrome\Application\35.0.1916.114\default_apps (4 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\VisualElementsManifest.xml (403 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ko.pak (610 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sk.pak (621 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_elf.dll (268 bytes)
%Program Files% (x86)\Google\Chrome\Application\35.0.1916.114 (8 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\hu.pak (635 bytes)
%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\chrmstp.exe (22090 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\PepperFlash\pepflashplayer.dll (63 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\uk.pak (932 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\pt-BR.pak (579 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\es-419.pak (602 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_watcher.dll (692 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\vi.pak (685 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sv.pak (553 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin (4 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\gu.pak (1193 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\snapshot_blob.bin (1397 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ms.pak (456 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\widevinecdmadapter.dll (381 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\nacl64.exe (51 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\es.pak (612 bytes)
%Program Files% (x86)\Google\Chrome\Application\35.0.1916.114\Locales (8 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ru.pak (930 bytes)
%Program Files% (x86)\Google\Chrome\Application\chrome.exe (16874 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_200_percent.pak (50 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\drive.crx (53 bytes)
%Program Files% (x86)\Google\Chrome\Temp (4 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\nb.pak (545 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ml.pak (1570 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\docs.crx (12 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (6 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sw.pak (505 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Extensions\external_extensions.json (103 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\nacl_irt_x86_64.nexe (52 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\42.0.2311.135.manifest (228 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\nacl_irt_x86_32.nexe (51 bytes)
C:\Windows\Temp\chrome_installer.log (129 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\youtube.crx (47 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\bg.pak (995 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\chrome.7z (259253 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\en-US.pak (498 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\icudtl.dat (59 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\da.pak (545 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\lt.pak (594 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\xinput1_3.dll (162 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\en-GB.pak (498 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ja.pak (720 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome.dll (27081 bytes)
%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe (22090 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\libglesv2.dll (50 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\et.pak (529 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\he.pak (692 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\natives_blob.bin (825 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\VisualElements\logo.png (7 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\mr.pak (1211 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\cs.pak (602 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\wow_helper.exe (146 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\nl.pak (579 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\libegl.dll (161 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ta.pak (1432 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\el.pak (1086 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\ffmpegsumo.dll (50 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sr.pak (907 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\delegate_execute.exe (1405 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\fa.pak (857 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_child.dll (41165 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\pl.pak (595 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\zh-TW.pak (489 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\de.pak (522 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\hi.pak (1232 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sl.pak (554 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\external_extensions.json (5 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\zh-CN.pak (488 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\th.pak (1208 bytes)
C:\Users\Public\Desktop\Google Chrome.lnk (6 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\hr.pak (561 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\chrome.exe (1627 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\am.pak (826 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\id.pak (539 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\resources.pak (65 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\libexif.dll (621 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\lv.pak (604 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\bn.pak (1267 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\VisualElements\splash-620x300.png (22 bytes)
%Program Files% (x86)\Google\Chrome\Application\35.0.1916.114\VisualElements (4 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\PepperFlash\manifest.json (6 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ca.pak (603 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\it.pak (587 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ar.pak (799 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\gmail.crx (48 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\metro_driver.dll (955 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_100_percent.pak (50 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\pt-PT.pak (594 bytes)
The process MPCBrowserUpdate.exe:1128 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psuser.dll (163 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdate.dll (790 bytes)
The process MPCBrowserUpdate.exe:1860 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_en.dll (28 bytes)
The process MPCBrowserUpdate.exe:1872 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ta.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psuser.dll (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\MPCBrowserUpdate.exe (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_no.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_th.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_et.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_is.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateOnDemand.exe (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_es.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sk.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_da.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_lt.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_nl.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_en.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_gu.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_cs.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_id.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_te.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pl.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserCrashHandler.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_am.dll (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_zh-TW.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdate.dll (790 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateBroker.exe (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_de.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_iw.dll (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sv.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateHelper.msi (45 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ur.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ar.dll (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ca.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hi.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fi.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pt-BR.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ms.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hu.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fa.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_lv.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_bn.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ru.dll (29 bytes)
C:\Windows\Tasks\MPCBrowserUpdateTaskUserS-1-5-21-2858020935-2156992550-3658131804-1003UA.job (940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_en-GB.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_tr.dll (30 bytes)
C:\Windows\Tasks\MPCBrowserUpdateTaskUserS-1-5-21-2858020935-2156992550-3658131804-1003Core.job (888 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdate.dll (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_es-419.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fr.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ml.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fil.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psmachine.dll (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\npGoogleUpdate3.dll (1514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ja.dll (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_bg.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_en.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_kn.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_mr.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pt-PT.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_it.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_zh-CN.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sw.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ro.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ko.dll (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdate.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_uk.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_vi.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_el.dll (31 bytes)
The process MPCBrowserUpdate.exe:1116 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 (656 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarCEC.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabCEB.tmp (48 bytes)
Registry activity
The process GoogleUpdate.exe:1652 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Google\Update\proxy]
"source" = "IEWPAD"
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"uid"
"old-uid"
The process GoogleUpdate.exe:3992 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"IsMSIHelperRegistered" = "1"
"LastStartedAU" = "1430454120"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"uid"
"old-uid"
The process GoogleUpdate.exe:2400 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"ActivePingDayStartSec" = "1430377200"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\CurrentState]
"DownloadProgressPercent" = "0"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{FDA71E6F-AC4C-4A00-8B70-9958A68906BF}]
"DayOfLastRollCall" = "3041"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"LastCheckSuccess" = "1430454150"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState]
"StateValue" = "16"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{FDA71E6F-AC4C-4A00-8B70-9958A68906BF}]
"RollCallDayStartSec" = "1430377200"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"LastCheckSuccess" = "1430454196"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"RollCallDayStartSec" = "1430377200"
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastChecked" = "1430454150"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"pv" = "35.0.1916.153"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\CurrentState]
"InstallTimeRemainingMs" = "4294967295"
[HKCU\Software\Google\Update\proxy]
"source" = "IEWPAD"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{FDA71E6F-AC4C-4A00-8B70-9958A68906BF}]
"pv" = "35.0.1916.153"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\CurrentState]
"DownloadTimeRemainingMs" = "4294967295"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"DayOfLastActivity" = "3041"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"LastInstallerResult" = "0"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"RollCallDayStartSec" = "1430377200"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"UpdateTime" = "1430454196"
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerResult" = "0"
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\CurrentState]
"InstallProgressPercent" = "4294967295"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"pv" = "1.3.26.9"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"RollCallDayStartSec" = "1430377200"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"DayOfLastRollCall" = "3041"
"ActivePingDayStartSec" = "1430377200"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"LastInstallerError" = "2"
[HKCU\Software\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"dr" = "0"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"LastCheckSuccess" = "1430454150"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{FDA71E6F-AC4C-4A00-8B70-9958A68906BF}\CurrentState]
"StateValue" = "17"
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerError" = "2"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"UpdateAvailableCount" = "1"
"DayOfLastActivity" = "3041"
"DayOfLastRollCall" = "3041"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\CurrentState]
"StateValue" = "3"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"DayOfLastRollCall" = "3041"
[HKCU\Software\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"dr" = "0"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"pv" = "35.0.1916.153"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\CurrentState]
"StateValue" = "7"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"UpdateAvailableSince" = "Type: REG_QWORD, Length: 8"
The Trojan deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}\CurrentState]
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{FDA71E6F-AC4C-4A00-8B70-9958A68906BF}\CurrentState]
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\CurrentState]
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\CurrentState]
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"UpdateAvailableSince"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"LastInstallerSuccessLaunchCmdLine"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerSuccessLaunchCmdLine"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"LastInstallerExtraCode1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"UpdateAvailableCount"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerExtraCode1"
"LastInstallerResult"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"UpdateAvailableSince"
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"old-uid"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"InstallerError"
"LastInstallerResult"
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"uid"
"LastInstallerResultUIString"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"iid"
"LastInstallerResultUIString"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"dr"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"LastInstallerError"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"UpdateAvailableCount"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"UpdateAvailableSince"
[HKLM\SOFTWARE\Wow6432Node\Google\Update]
"LastInstallerError"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"UpdateAvailableCount"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"tttoken"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"dr"
"tttoken"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"tttoken"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"InstallerResult"
The process PlayFreeBrowser.exe:2492 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"tel" = "ChromiumHTM.Mpc"
[HKCU\Software\Classes\ftp\shell]
"(Default)" = "open"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer]
"GlobalAssocChangedCounter" = "54"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"mailto" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".html" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"SetupUri" = "http://files.playfree.org/gametab/farm_frenzy-lp_en.zip"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"Title" = "Farm Frenzy"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".htm" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "C8 18 39 DE C5 83 D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 45 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".xhtml" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\Classes\http\shell\open\ddeexec]
"(Default)" = ""
[HKCU\Software\Classes\ftp]
"URL Protocol" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"nntp" = "ChromiumHTM.Mpc"
[HKCR\.html\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKCU\Software\Classes\.xht]
"(Default)" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"smsto" = "ChromiumHTM.Mpc"
"https" = "ChromiumHTM.Mpc"
[HKCU\Software\Classes\.shtml]
"(Default)" = "ChromiumHTM.Mpc"
[HKCU\Software\Classes\ftp\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKCU\Software\Classes\https]
"URL Protocol" = ""
[HKCU\Software\Classes\https\shell\open\ddeexec]
"(Default)" = ""
[HKCR\.xhtml\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"sms" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\RegisteredApplications]
"PlayFree Browser.Mpc" = "Software\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities"
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"site" = "lp_en"
[HKCR\ChromiumHTM.Mpc\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe -- %1"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"IconsVisible" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\Classes\http\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKCU\Software\Classes\ftp\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe -- %1"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc]
"(Default)" = "PlayFree Browser"
[HKCR\ChromiumHTM.Mpc]
"(Default)" = "Chromium HTML Document"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PlayFreeBrowser.exe]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application"
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"Installing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"ShowIconsCommand" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe --show-icons"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"http" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKCU\Software\Classes\https\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"HideIconsCommand" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe --hide-icons"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKCR\.htm\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"ExePath" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\play.exe"
[HKCU\Software\Classes\https\shell]
"(Default)" = "open"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationName" = "PlayFree Browser"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCR\ChromiumHTM.Mpc\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
"WpadDecisionTime" = "4B 05 3F D4 C5 83 D0 01"
[HKCR\ChromiumHTM.Mpc]
"URL Protocol" = ""
[HKCU\Software\Classes\.html]
"(Default)" = "ChromiumHTM.Mpc"
[HKCU\Software\Classes\http\shell]
"(Default)" = "open"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe"
[HKCU\Software\Classes\http]
"URL Protocol" = ""
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"LGP" = "farm_frenzy"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PlayFreeBrowser.exe]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".shtml" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"urn" = "ChromiumHTM.Mpc"
[HKCU\Software\Classes\.htm]
"(Default)" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"Description" = "Get mad about farming and start your first business now!"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"news" = "ChromiumHTM.Mpc"
[HKCR\.xht\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"ftp" = "ChromiumHTM.Mpc"
"webcal" = "ChromiumHTM.Mpc"
[HKCU\Software\Classes\ftp\shell\open\ddeexec]
"(Default)" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationDescription" = "PlayFree Browser is a web browser that runs webpages and applications with lightning speed. It's fast, stable, and easy to use. Browse the web more safely with malware and phishing protection built into PlayFree Browser."
[HKCR\.shtml\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"mms" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"irc" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".xht" = "ChromiumHTM.Mpc"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"lastrun" = "13074927502386248"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"IconUri" = "http://mpcstatic.com/gn/128x128/468_128x128.png"
[HKCU\Software\Classes\.xhtml]
"(Default)" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\Startmenu]
"StartMenuInternet" = "PlayFree Browser.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\Clients\StartmenuInternet]
"(Default)" = "PlayFree Browser.Mpc"
[HKCU\Software\Classes\https\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe -- %1"
[HKCU\Software\Classes\http\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe -- %1"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"ReinstallCommand" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe --make-default-browser"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum]
"Implementing" = "1C 00 00 00 01 00 00 00 DF 07 05 00 05 00 01 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\PlayFreeBrowser\Tags]
"GAME_SITE"
[HKCU\Software\PlayFreeBrowser\Games\farm_frenzy-lp_en]
"Installing"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
"Progid"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
"Progid"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
"Progid"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
"Progid"
[HKCU\Software\PlayFreeBrowser\Tags]
"GAMES_DOWNLOAD_URL"
"IS_NOWINDOW"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
"Progid"
The process PlayFreeBrowser.exe:1688 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
The process 42.0.2311.135_chrome_installer.exe:3312 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"ap" = "-multi-chrome-full"
The process %original file name%.exe:2636 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\PlayFreeBrowser\Tags]
"ABOUTUS_URL" = "YWJvdXQtdXMv"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\news\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionTime" = "4B 05 3F D4 C5 83 D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer]
"GlobalAssocChangedCounter" = "35"
[HKCR\ChromiumHTML.Mpc\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe %1"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice]
"Progid" = "ChromiumHTML.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".html" = "ChromiumHTML.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"ORIGIN" = "Z3M="
"GAME_SITE" = "gs_en"
[HKCR\ChromiumHTML.Mpc]
"URL Protocol" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
"Progid" = "ChromiumHTML.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
"Progid" = "ChromiumHTML.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".htm" = "ChromiumHTML.Mpc"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\sms\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"PRIVACY_POLICY_URL" = "cHJpdmFjeS1wb2xpY3kv"
"NEWTAB_BOOKMARK_5" = ""
"UNINSTALL_URL" = "aHR0cDovL3d3dy5wbGF5ZnJlZS5vcmcvZW4vdW5pbnN0YWxsLmh0bWw/dXRtX3NvdXJjZT1nc19lbiZ1dG1fbWVkaXVtPXVuaW5zdGFsbA=="
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 43 00 00 00 09 00 00 00 00 00 00 00"
[HKCR\ChromiumHTML.Mpc\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".xhtml" = "ChromiumHTML.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecision" = "0"
[HKCU\Software\PlayFreeBrowser\Tags]
"NEWTAB_BOOKMARK_2" = ""
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\urn\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"https" = "ChromiumHTML.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"SEARCH_INDEX" = "213"
"GAMES_DOWNLOAD_URL" = "http://www.playfree.org/en/gametabinstall3.html?game=farm_frenzy"
[HKLM\SOFTWARE\RegisteredApplications]
"PlayFree Browser.Mpc" = "SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities"
[HKCU\Software\PlayFreeBrowser\Tags]
"HOWTOUNINSTALL_URL" = "aG93LXRvLXVuaW5zdGFsbC8="
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
"Progid" = "ChromiumHTML.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"help_url" = "aGVscC8="
"STORE_URL" = "http://games.playfree.org/en/?utm_source=gs_en&utm_medium=newtab"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc]
"(Default)" = "PlayFree Browser.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"http" = "ChromiumHTML.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadNetworkName" = "Network 4"
[HKCU\Software\PlayFreeBrowser\Tags]
"BrowserUid" = "PFBrowser"
"installationContract" = "{C132BADE-00A8-4386-BB5A-D30720EBAB87}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKCU\Software\PlayFreeBrowser\Tags]
"GAMES_INFO_URL" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationName" = "PlayFree Browser"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice]
"Progid" = "ChromiumHTML.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationDescription" = "PlayFree Browser"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\smsto\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"TOU_URL" = "dGVybXMtb2YtdXNl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "25 CC 85 1E BF 72 D0 01"
[HKCU\Software\PlayFreeBrowser\Tags]
"HomePage" = "aHR0cDovL2hvbWUucGxheWZyZWUub3JnL2VuLz91dG1fc291cmNlPWdzX2VuJnV0bV9tZWRpdW09aHA="
"SHOW_GAMES_SLIDE" = "1"
"NEWTAB_SEARCH_URL" = "MA=="
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\tel\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe %1"
[HKCU\Software\PlayFreeBrowser\Tags]
"se" = "09 6F 7A 55 3C 04 1E 12 50 5F 53 55 22 09 12 0E"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".shtml" = "ChromiumHTML.Mpc"
[HKCR\ChromiumHTML.Mpc]
"(Default)" = "PlayFree Browser.Mpc"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"uninstall" = "http://www.playfree.org/en/uninstall.html?utm_source=gs_en&utm_medium=uninstall"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\MMS\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\nntp\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"NEWTAB_BOOKMARK_7" = ""
"InstallDateStr" = "2015-05-01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc]
"LocalizedString" = "PlayFree Browser"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\PlayFreeBrowser\Tags]
"PLAY_URL" = "http://games.playfree.org/en/play.html?utm_source=gs_en&utm_medium=newtab"
"STORE_NAME" = "PlayFree Games"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\webcal\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"TARGET_REGION" = "ZW4="
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".xht" = "ChromiumHTML.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"SOURCE_SITE" = "ZW4="
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKCU\Software\PlayFreeBrowser\Tags]
"BROWSER_SUBID" = ""
"WEBSITE_URL" = "http://games.playfree.org/en/?utm_source=gs_en&utm_medium=gamebutton"
"STORE_ICON" = "http://customisations.playfree.org/icons/product_logo_128.png"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
"Progid" = "ChromiumHTML.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"newTab" = ""
"SUPPORT_URL" = "c3VwcG9ydC8="
"NEWTAB_BOOKMARK_8" = ""
"NEWTAB_BOOKMARK_6" = ""
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\irc\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"NEWTAB_BOOKMARK_4" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\Startmenu]
"StartMenuInternet" = "PlayFree Browser.Mpc"
[HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\mailto\UserChoice]
"Progid" = "ChromiumHTM.Mpc"
[HKCU\Software\PlayFreeBrowser\Tags]
"NEWTAB_BOOKMARK_3" = ""
"NEWTAB_BOOKMARK_1" = "aHR0cDovL2hvbWUucGxheWZyZWUub3JnL2VuLz91dG1fc291cmNlPWdzX2VuJnV0bV9tZWRpdW09bmV3dGFi"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCU\Software\PlayFreeBrowser\Tags]
"IS_NOWINDOW" = "true"
[HKCU\Software\Clients\StartmenuInternet]
"(Default)" = "PlayFree Browser.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"IconsVisible" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDecisionReason" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
"Progid" = "ChromiumHTML.Mpc"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"BrowserUid" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{AAB62F56-1F12-4B3C-A0EE-A1324874AB51}]
"WpadDetectedUrl"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
"Progid"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
"Progid"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
"Progid"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
"Progid"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
"Progid"
The process taskeng.exe:3936 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Handshake\{24C08E2E-282B-4C07-890C-CA52D3D35912}]
"data" = "4D 45 4F 57 01 00 00 00 E4 B7 BD 92 8B F2 A0 46"
The process taskeng.exe:3464 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Handshake\{3C2F6BC0-C96A-4741-8C10-11560F032AC1}]
"data" = "4D 45 4F 57 01 00 00 00 E4 B7 BD 92 8B F2 A0 46"
The process MPCBrowserCrashHandler.exe:3684 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
The process setup.exe:272 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"DisplayVersion" = "3.0.0.4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"Favorites" = "00 7C 01 00 00 14 00 1F 80 C8 27 34 1F 10 5C 10"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"Version" = "3.0.0.4"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKCR\.shtml\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"smsto" = "ChromiumHTM.Mpc"
"irc" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PlayFreeBrowser.exe]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"ap" = "-stage:refreshing_policy"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesVersion" = "2"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"InstallerResult" = "0"
[HKCR\.xhtml\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationDescription" = "PlayFree Browser is a web browser that runs webpages and applications with lightning speed. It's fast, stable, and easy to use. Browse the web more safely with malware and phishing protection built into PlayFree Browser."
[HKCU\Software\Classes\Wow6432Node\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}]
"(Default)" = "CommandExecuteImpl Class"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"sms" = "ChromiumHTM.Mpc"
[HKCU\Software\MPCBrowser\Update\Clients\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"Name" = "PlayFree Browser"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"mailto" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKCR\ChromiumHTM.Mpc\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe -- %1"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".html" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "4B 05 3F D4 C5 83 D0 01"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"DisplayName" = "PlayFree Browser"
[HKCR\ChromiumHTM.Mpc]
"(Default)" = "Chromium HTML Document"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"ftp" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"IconsVisible" = "1"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"InstallerExtraCode1" = "9"
[HKCU\Software\MPCBrowser\Update\Clients\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"pv" = "3.0.0.4"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"InstallerSuccessLaunchCmdLine" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"tel" = "ChromiumHTM.Mpc"
"mms" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\RegisteredApplications]
"PlayFree Browser.Mpc" = "Software\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities"
[HKCU\Software\MPCBrowser\Update\Clients\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\Commands\on-os-upgrade]
"CommandLine" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Installer\setup.exe --on-os-upgrade --verbose-logging"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\shell\open\command]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"webcal" = "ChromiumHTM.Mpc"
[HKCU\Software\MPCBrowser\Update\Clients\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"lang" = "en"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".htm" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"urn" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationName" = "PlayFree Browser"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".shtml" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"VersionMajor" = "0"
"NoModify" = "1"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc]
"(Default)" = "PlayFree Browser"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"InstallerError" = "0"
[HKCR\ChromiumHTM.Mpc]
"URL Protocol" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Installer\setup.exe --uninstall"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"HideIconsCommand" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe --hide-icons"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"NoRepair" = "1"
[HKCU\Software\Classes\Wow6432Node\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}\LocalServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\delegate_execute.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"InstallDate" = "20150501"
"Publisher" = "MyPlayCity, Inc."
[HKCR\ChromiumHTM.Mpc\DefaultIcon]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PlayFreeBrowser.exe]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"ReinstallCommand" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe --make-default-browser"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"UninstallArguments" = " --uninstall"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".xhtml" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesChanges" = "7"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\InstallInfo]
"ShowIconsCommand" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe --show-icons"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"InstallLocation" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\FileAssociations]
".xht" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"http" = "ChromiumHTM.Mpc"
"https" = "ChromiumHTM.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities]
"ApplicationIcon" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe,0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser]
"VersionMinor" = "4"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\Startmenu]
"StartMenuInternet" = "PlayFree Browser.Mpc"
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"nntp" = "ChromiumHTM.Mpc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesResolve" = "CC 02 00 00 4C 00 00 00 01 14 02 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"
[HKCR\.xht\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKCU\Software\Classes\Wow6432Node\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}\LocalServer32]
"ServerExecutable" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\delegate_execute.exe"
[HKCR\.html\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
[HKLM\SOFTWARE\Clients\StartMenuInternet\PlayFree Browser.Mpc\Capabilities\URLAssociations]
"news" = "ChromiumHTM.Mpc"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Installer\setup.exe"
[HKCU\Software\MPCBrowser\Update\Clients\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\Commands\on-os-upgrade]
"AutoRunOnOSUpgrade" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""
[HKCU\Software\MPCBrowser\Update\Clients\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"oopcrashes" = "1"
[HKCR\.htm\OpenWithProgids]
"ChromiumHTM.Mpc" = ""
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"InstallerExtraCode1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"ap"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process setup.exe:2056 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"ap" = "-stage:preconditions-multi-chrome-full"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"VersionMajor" = "2311"
"DisplayVersion" = "42.0.2311.135"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"InstallerExtraCode1" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"NoModify" = "1"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}]
"pv" = "42.0.2311.135"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"pv" = "42.0.2311.135"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"pv" = "42.0.2311.135"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"UninstallString" = "%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe"
"InstallerResult" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"DisplayName" = "Google Chrome"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"UninstallArguments" = " --uninstall --multi-install --system-level"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"UninstallArguments" = " --uninstall --multi-install --chrome --system-level"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"UninstallString" = "%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}]
"Name" = "Google Chrome App Launcher"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"UninstallString" = "%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe --uninstall --multi-install --chrome --system-level"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"InstallerError" = "2"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"Version" = "24,0,0,0"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"InstallerError" = "2"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"Version" = "42.0.2311.135"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"Name" = "Google Chrome"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}]
"ap" = "-multi-chrome-full"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level --multi-install --chrome"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"InstallLocation" = "%Program Files% (x86)\Google\Chrome\Application"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"Localized Name" = "Google Chrome"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade]
"CommandLine" = "%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe --on-os-upgrade --multi-install --chrome --system-level --verbose-logging"
[HKCR\Wow6432Node\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\LocalServer32]
"(Default)" = "%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\delegate_execute.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"VersionMinor" = "135"
"NoRepair" = "1"
[HKCR\Wow6432Node\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\LocalServer32]
"ServerExecutable" = "%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\delegate_execute.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"DisplayIcon" = "%Program Files% (x86)\Google\Chrome\Application\chrome.exe,0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"(Default)" = "Google Chrome"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade]
"AutoRunOnOSUpgrade" = "1"
[HKCR\Wow6432Node\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}]
"(Default)" = "CommandExecuteImpl Class"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}]
"Name" = "Google Chrome binaries"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
"Publisher" = "Google Inc."
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"IsInstalled" = "1"
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"InstallerResult" = "0"
The Trojan deletes the following registry key(s):
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\Commands\quick-enable-application-host]
[HKCR\Wow6432Node\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\LocalServer32]
[HKCR\Wow6432Node\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}]
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\install-extension]
[HKCR\Wow6432Node\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\Programmable]
[HKLM\SOFTWARE\Wow6432Node\Google\Update\Clients\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}\Commands\query-eula-acceptance]
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}]
"InstallerExtraCode1"
The process MPCBrowserUpdate.exe:1128 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Wow6432Node\Interface\{9BAAB6BF-50C3-47FE-9948-2B4282270A53}]
"(Default)" = "IGoogleUpdate3"
[HKCU\Software\Classes\MPCBrowserUpdate.OnDemandCOMClassUser]
"(Default)" = "MPCBrowser Update Legacy On Demand"
[HKCU\Software\Classes\Wow6432Node\Interface\{49A3A7BF-35D1-487D-A8AA-D1F06DE89E90}\NumMethods]
"(Default)" = "24"
[HKCU\Software\Classes\Wow6432Node\Interface\{859474E9-46A6-4D45-9166-FEFE4B240B57}]
"(Default)" = "IBrowserHttpRequest2"
[HKCU\Software\Classes\Wow6432Node\Interface\{B88CF891-2C0B-4A92-8F50-922324CE7929}]
"(Default)" = "IJobObserver"
[HKCU\Software\Classes\Wow6432Node\Interface\{9BAAB6BF-50C3-47FE-9948-2B4282270A53}\NumMethods]
"(Default)" = "10"
[HKCU\Software\Classes\MPCBrowserUpdate.OnDemandCOMClassUser.1.0]
"(Default)" = "MPCBrowser Update Legacy On Demand"
[HKCU\Software\Classes\Wow6432Node\CLSID\{466029E5-8543-46CA-8E94-2E5AA89AD1B4}\InProcServer32]
"ThreadingModel" = "Both"
[HKCU\Software\Classes\Wow6432Node\Interface\{B88CF891-2C0B-4A92-8F50-922324CE7929}\NumMethods]
"(Default)" = "13"
[HKCU\Software\Classes\Wow6432Node\Interface\{B5C953F4-714D-494E-9977-C7ECB97DA128}]
"(Default)" = "ICoCreateAsync"
[HKCU\Software\Classes\MPCBrowserUpdate.CredentialDialogUser\CLSID]
"(Default)" = "{EECE757E-E1CA-4A54-84CB-DEA5CB9A9FE1}"
[HKCU\Software\Classes\Wow6432Node\Interface\{0538BB09-4DAA-422B-AAF0-360423DD59A3}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{2B4C625A-5F03-43F2-9B66-8BC910611CCE}]
"(Default)" = "IRegistrationUpdateHook"
[HKCU\Software\Classes\Wow6432Node\CLSID\{466029E5-8543-46CA-8E94-2E5AA89AD1B4}]
"(Default)" = "PSFactoryBuffer"
[HKCU\Software\Classes\Wow6432Node\CLSID\{0F7755DE-8DA4-4F9D-B461-BA2C938CCF56}\InprocHandler32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psuser.dll"
[HKCU\Software\Classes\Wow6432Node\Interface\{42019950-3B2E-4EF8-B2F1-99304F087F0B}\NumMethods]
"(Default)" = "10"
[HKCU\Software\Classes\Wow6432Node\CLSID\{2A6166EA-245B-4A93-A86A-62187BE3A52B}\VersionIndependentProgID]
"(Default)" = "MPCBrowserUpdate.OnDemandCOMClassUser"
[HKCU\Software\Classes\Wow6432Node\CLSID\{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}]
"(Default)" = "MPCBrowser.OneClickProcessLauncher"
[HKCU\Software\Classes\Wow6432Node\Interface\{EC25F81E-CF51-402F-9757-A8C52C415E06}\NumMethods]
"(Default)" = "5"
[HKCU\Software\Classes\Wow6432Node\Interface\{2B4C625A-5F03-43F2-9B66-8BC910611CCE}\NumMethods]
"(Default)" = "8"
[HKCU\Software\Classes\Wow6432Node\Interface\{82D4ADAC-97BD-4562-B6BD-4631FB68DD15}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{12123A39-E19A-43BD-AEE2-38F073887B5C}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\MPCBrowser.OneClickProcessLauncherUser]
"(Default)" = "MPCBrowser.OneClickProcessLauncher"
[HKCU\Software\Classes\Wow6432Node\Interface\{72F678D7-2B87-4579-A57E-4A9F625F186E}\NumMethods]
"(Default)" = "4"
[HKCU\Software\Classes\Wow6432Node\CLSID\{2A6166EA-245B-4A93-A86A-62187BE3A52B}\LocalServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateOnDemand.exe"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3COMClassUser.1.0\CLSID]
"(Default)" = "{ACAAAF26-05BF-4EC4-BFD0-0326C2CC122A}"
[HKCU\Software\Classes\MPCBrowserUpdate.CredentialDialogUser\CurVer]
"(Default)" = "MPCBrowserUpdate.CredentialDialogUser.1.0"
[HKCU\Software\Classes\Wow6432Node\Interface\{88FA8BC3-5751-4260-82D3-C6A6D1D80E57}\NumMethods]
"(Default)" = "24"
[HKCU\Software\Classes\Wow6432Node\Interface\{859474E9-46A6-4D45-9166-FEFE4B240B57}\NumMethods]
"(Default)" = "4"
[HKCU\Software\Classes\MPCBrowser.OneClickProcessLauncherUser.1.0]
"(Default)" = "MPCBrowser.OneClickProcessLauncher"
[HKCU\Software\Classes\Wow6432Node\CLSID\{EECE757E-E1CA-4A54-84CB-DEA5CB9A9FE1}\ProgID]
"(Default)" = "MPCBrowserUpdate.CredentialDialogUser.1.0"
[HKCU\Software\Classes\Wow6432Node\CLSID\{E295A572-AC98-48DB-82CB-2FAF81BEB946}\InprocServer32]
"ThreadingModel" = "Both"
[HKCU\Software\Classes\Wow6432Node\Interface\{31B97BF2-E15F-42EF-8017-C9F6C2B07B7E}]
"(Default)" = "IGoogleUpdate3Web"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}]
"Policy" = "3"
[HKCU\Software\Classes\Wow6432Node\Interface\{0538BB09-4DAA-422B-AAF0-360423DD59A3}]
"(Default)" = "IApp"
[HKCU\Software\Classes\Wow6432Node\CLSID\{E462D8EF-0F29-41C1-9EDC-20989C987661}\ProgID]
"(Default)" = "MPCBrowserUpdate.Update3WebUser.1.0"
[HKCU\Software\Classes\Wow6432Node\CLSID\{0F7755DE-8DA4-4F9D-B461-BA2C938CCF56}\InprocHandler32]
"ThreadingModel" = "Both"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3WebUser\CLSID]
"(Default)" = "{E462D8EF-0F29-41C1-9EDC-20989C987661}"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3COMClassUser\CurVer]
"(Default)" = "MPCBrowserUpdate.Update3COMClassUser.1.0"
[HKCU\Software\Classes\Wow6432Node\CLSID\{466029E5-8543-46CA-8E94-2E5AA89AD1B4}\InProcServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psuser.dll"
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\Classes\MPCBrowserUpdate.CredentialDialogUser.1.0]
"(Default)" = "MPCBrowserUpdate CredentialDialog"
[HKCU\Software\Classes\Wow6432Node\Interface\{31B97BF2-E15F-42EF-8017-C9F6C2B07B7E}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{82D4ADAC-97BD-4562-B6BD-4631FB68DD15}\NumMethods]
"(Default)" = "4"
[HKCU\Software\Classes\Wow6432Node\Interface\{F475FDF4-0B16-4126-A620-F2C171F422E2}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\CLSID\{E462D8EF-0F29-41C1-9EDC-20989C987661}]
"(Default)" = "PlayFree GoogleUpdate Update3Web"
[HKCU\Software\Classes\Wow6432Node\Interface\{F475FDF4-0B16-4126-A620-F2C171F422E2}]
"(Default)" = "IProgressWndEvents"
[HKCU\Software\Classes\Wow6432Node\Interface\{859474E9-46A6-4D45-9166-FEFE4B240B57}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{04852F0F-7D7C-41EC-A743-A9F1D0BE8642}]
"(Default)" = "IGoogleUpdate3WebSecurity"
[HKCU\Software\Classes\MPCBrowserUpdate.OnDemandCOMClassUser.1.0\CLSID]
"(Default)" = "{2A6166EA-245B-4A93-A86A-62187BE3A52B}"
[HKCU\Software\Classes\Wow6432Node\Interface\{9EA74A84-12A5-4385-82A9-1C04A7E4F008}]
"(Default)" = "IAppVersion"
[HKCU\Software\Classes\Wow6432Node\CLSID\{E295A572-AC98-48DB-82CB-2FAF81BEB946}\InprocServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psuser.dll"
[HKCU\Software\Classes\MPCBrowser.OneClickProcessLauncherUser\CLSID]
"(Default)" = "{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}"
[HKCU\Software\Classes\MPCBrowserUpdate.CredentialDialogUser.1.0\CLSID]
"(Default)" = "{EECE757E-E1CA-4A54-84CB-DEA5CB9A9FE1}"
[HKCU\Software\Classes\Wow6432Node\Interface\{88FA8BC3-5751-4260-82D3-C6A6D1D80E57}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{12123A39-E19A-43BD-AEE2-38F073887B5C}\NumMethods]
"(Default)" = "10"
[HKCU\Software\Classes\MPCBrowserUpdate.OnDemandCOMClassUser\CLSID]
"(Default)" = "{2A6166EA-245B-4A93-A86A-62187BE3A52B}"
[HKCU\Software\Classes\Wow6432Node\CLSID\{2A6166EA-245B-4A93-A86A-62187BE3A52B}\ProgID]
"(Default)" = "MPCBrowserUpdate.OnDemandCOMClassUser.1.0"
[HKCU\Software\Classes\MPCBrowser.OneClickProcessLauncherUser.1.0\CLSID]
"(Default)" = "{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}"
[HKCU\Software\Classes\Wow6432Node\CLSID\{EECE757E-E1CA-4A54-84CB-DEA5CB9A9FE1}\VersionIndependentProgID]
"(Default)" = "MPCBrowserUpdate.CredentialDialogUser"
[HKCU\Software\Classes\Wow6432Node\Interface\{030BBAE0-BDD0-42E4-A303-5FD452DAB994}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{04852F0F-7D7C-41EC-A743-A9F1D0BE8642}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{CC65CB68-B45F-47CD-839E-2FCA129FA253}\NumMethods]
"(Default)" = "6"
[HKCU\Software\Classes\Wow6432Node\Interface\{42019950-3B2E-4EF8-B2F1-99304F087F0B}]
"(Default)" = "IPackage"
[HKCU\Software\Classes\Wow6432Node\Interface\{04852F0F-7D7C-41EC-A743-A9F1D0BE8642}\NumMethods]
"(Default)" = "4"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3COMClassUser\CLSID]
"(Default)" = "{ACAAAF26-05BF-4EC4-BFD0-0326C2CC122A}"
[HKCU\Software\Classes\Wow6432Node\Interface\{9BAAB6BF-50C3-47FE-9948-2B4282270A53}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\CLSID\{ACAAAF26-05BF-4EC4-BFD0-0326C2CC122A}\ProgID]
"(Default)" = "MPCBrowserUpdate.Update3COMClassUser.1.0"
[HKCU\Software\Classes\Wow6432Node\CLSID\{E462D8EF-0F29-41C1-9EDC-20989C987661}\LocalServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateOnDemand.exe"
[HKCU\Software\Classes\Wow6432Node\Interface\{C0FC3ADC-9E8A-4DDD-A5E7-F712D10FD94F}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{F475FDF4-0B16-4126-A620-F2C171F422E2}\NumMethods]
"(Default)" = "9"
[HKCU\Software\Classes\Wow6432Node\CLSID\{ACAAAF26-05BF-4EC4-BFD0-0326C2CC122A}\VersionIndependentProgID]
"(Default)" = "MPCBrowserUpdate.Update3COMClassUser"
[HKCU\Software\Classes\Wow6432Node\Interface\{030BBAE0-BDD0-42E4-A303-5FD452DAB994}]
"(Default)" = "IAppBundle"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3WebUser]
"(Default)" = "PlayFree GoogleUpdate Update3Web"
[HKCU\Software\Classes\Wow6432Node\Interface\{2B4C625A-5F03-43F2-9B66-8BC910611CCE}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{49A3A7BF-35D1-487D-A8AA-D1F06DE89E90}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{EC25F81E-CF51-402F-9757-A8C52C415E06}]
"(Default)" = "IGoogleUpdate"
[HKCU\Software\Classes\Wow6432Node\Interface\{42019950-3B2E-4EF8-B2F1-99304F087F0B}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{9EA74A84-12A5-4385-82A9-1C04A7E4F008}\NumMethods]
"(Default)" = "10"
[HKCU\Software\Classes\Wow6432Node\Interface\{CC65CB68-B45F-47CD-839E-2FCA129FA253}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{B88CF891-2C0B-4A92-8F50-922324CE7929}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\CLSID\{ACAAAF26-05BF-4EC4-BFD0-0326C2CC122A}\LocalServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\MPCBrowserUpdate.exe"
[HKCU\Software\Classes\Wow6432Node\Interface\{2EE55099-A152-41B9-B814-3E6E51C90EBC}]
"(Default)" = "IOneClickProcessLauncher"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3WebUser\CurVer]
"(Default)" = "MPCBrowserUpdate.Update3WebUser.1.0"
[HKCU\Software\Classes\Wow6432Node\Interface\{E335B93A-7D0B-4E85-A484-12A8313EA61C}\NumMethods]
"(Default)" = "10"
[HKCU\Software\Classes\Wow6432Node\Interface\{72F678D7-2B87-4579-A57E-4A9F625F186E}]
"(Default)" = "ICredentialDialog"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3COMClassUser]
"(Default)" = "Update3COMClass"
[HKCU\Software\Classes\Wow6432Node\CLSID\{EECE757E-E1CA-4A54-84CB-DEA5CB9A9FE1}\LocalServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateOnDemand.exe"
[HKCU\Software\Classes\Wow6432Node\Interface\{B5C953F4-714D-494E-9977-C7ECB97DA128}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{9EA74A84-12A5-4385-82A9-1C04A7E4F008}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{72F678D7-2B87-4579-A57E-4A9F625F186E}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{E335B93A-7D0B-4E85-A484-12A8313EA61C}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{CC65CB68-B45F-47CD-839E-2FCA129FA253}]
"(Default)" = "IProcessLauncher"
[HKCU\Software\Classes\Wow6432Node\Interface\{2EE55099-A152-41B9-B814-3E6E51C90EBC}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\MPCBrowserUpdate.CredentialDialogUser]
"(Default)" = "MPCBrowserUpdate CredentialDialog"
[HKCU\Software\Classes\Wow6432Node\Interface\{88FA8BC3-5751-4260-82D3-C6A6D1D80E57}]
"(Default)" = "IAppBundleWeb"
[HKCU\Software\Classes\Wow6432Node\CLSID\{EECE757E-E1CA-4A54-84CB-DEA5CB9A9FE1}]
"(Default)" = "MPCBrowserUpdate CredentialDialog"
[HKCU\Software\Classes\Wow6432Node\Interface\{31B97BF2-E15F-42EF-8017-C9F6C2B07B7E}\NumMethods]
"(Default)" = "8"
[HKCU\Software\Classes\Wow6432Node\Interface\{2EE55099-A152-41B9-B814-3E6E51C90EBC}\NumMethods]
"(Default)" = "4"
[HKCU\Software\Classes\MPCBrowserUpdate.OnDemandCOMClassUser\CurVer]
"(Default)" = "MPCBrowserUpdate.OnDemandCOMClassUser.1.0"
[HKCU\Software\Classes\Wow6432Node\Interface\{49A3A7BF-35D1-487D-A8AA-D1F06DE89E90}]
"(Default)" = "ICurrentState"
[HKCU\Software\Classes\Wow6432Node\CLSID\{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}\LocalServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateOnDemand.exe"
[HKCU\Software\Classes\Wow6432Node\Interface\{0538BB09-4DAA-422B-AAF0-360423DD59A3}\NumMethods]
"(Default)" = "40"
[HKCU\Software\Classes\Wow6432Node\CLSID\{E462D8EF-0F29-41C1-9EDC-20989C987661}\VersionIndependentProgID]
"(Default)" = "MPCBrowserUpdate.Update3WebUser"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3WebUser.1.0]
"(Default)" = "PlayFree GoogleUpdate Update3Web"
[HKCU\Software\Classes\MPCBrowser.OneClickProcessLauncherUser\CurVer]
"(Default)" = "MPCBrowser.OneClickProcessLauncherUser.1.0"
[HKCU\Software\Classes\Wow6432Node\Interface\{C0FC3ADC-9E8A-4DDD-A5E7-F712D10FD94F}\NumMethods]
"(Default)" = "14"
[HKCU\Software\Classes\Wow6432Node\Interface\{E335B93A-7D0B-4E85-A484-12A8313EA61C}]
"(Default)" = "ICoCreateAsyncStatus"
[HKCU\Software\Classes\Wow6432Node\Interface\{B5C953F4-714D-494E-9977-C7ECB97DA128}\NumMethods]
"(Default)" = "4"
[HKCU\Software\Classes\Wow6432Node\CLSID\{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}\VersionIndependentProgID]
"(Default)" = "MPCBrowser.OneClickProcessLauncherUser"
[HKCU\Software\Classes\Wow6432Node\CLSID\{2A6166EA-245B-4A93-A86A-62187BE3A52B}]
"(Default)" = "MPCBrowser Update Legacy On Demand"
[HKCU\Software\Classes\Wow6432Node\CLSID\{ACAAAF26-05BF-4EC4-BFD0-0326C2CC122A}]
"(Default)" = "Update3COMClass"
[HKCU\Software\Classes\Wow6432Node\Interface\{030BBAE0-BDD0-42E4-A303-5FD452DAB994}\NumMethods]
"(Default)" = "39"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3WebUser.1.0\CLSID]
"(Default)" = "{E462D8EF-0F29-41C1-9EDC-20989C987661}"
[HKCU\Software\Classes\Wow6432Node\Interface\{82D4ADAC-97BD-4562-B6BD-4631FB68DD15}]
"(Default)" = "IGoogleUpdateCore"
[HKCU\Software\Classes\Wow6432Node\Interface\{C0FC3ADC-9E8A-4DDD-A5E7-F712D10FD94F}]
"(Default)" = "IAppWeb"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}]
"CLSID" = "{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}"
[HKCU\Software\Classes\Wow6432Node\CLSID\{EFFA15AD-39AC-4C86-88B5-34B2CF65786E}\ProgID]
"(Default)" = "MPCBrowser.OneClickProcessLauncherUser.1.0"
[HKCU\Software\Classes\MPCBrowserUpdate.Update3COMClassUser.1.0]
"(Default)" = "Update3COMClass"
[HKCU\Software\Classes\Wow6432Node\Interface\{EC25F81E-CF51-402F-9757-A8C52C415E06}\ProxyStubClsid32]
"(Default)" = "{466029E5-8543-46CA-8E94-2E5AA89AD1B4}"
[HKCU\Software\Classes\Wow6432Node\Interface\{12123A39-E19A-43BD-AEE2-38F073887B5C}]
"(Default)" = "IAppVersionWeb"
The Trojan deletes the following registry key(s):
[HKCU\Software\Classes\Wow6432Node\CLSID\{0F7755DE-8DA4-4F9D-B461-BA2C938CCF56}]
[HKCU\Software\Classes\Wow6432Node\CLSID\{0F7755DE-8DA4-4F9D-B461-BA2C938CCF56}\InprocHandler32]
[HKCU\Software\Classes\Wow6432Node\CLSID\{E295A572-AC98-48DB-82CB-2FAF81BEB946}]
[HKCU\Software\Classes\Wow6432Node\CLSID\{E295A572-AC98-48DB-82CB-2FAF81BEB946}\InprocServer32]
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
"sk"
The process MPCBrowserUpdate.exe:3788 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\MPCBrowser\Update\proxy]
"source" = "IE"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
"sk"
The process MPCBrowserUpdate.exe:1860 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update]
"eulaaccepted"
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
"sk"
The process MPCBrowserUpdate.exe:1500 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\MPCBrowser\Update\proxy]
"source" = "IE"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
"sk"
The process MPCBrowserUpdate.exe:1872 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=3]
"vendor" = "MyPlayCity, Inc."
[HKCU\Software\Classes\Wow6432Node\CLSID\{74B93321-B3E4-4F84-8E9C-DE30CD0D0F4F}]
"(Default)" = "MPCBrowser Update Plugin"
[HKCU\Software\Classes\MPCBrowser.Update3WebControl.3\CLSID]
"(Default)" = "{ADA98CFC-FB4D-4411-8D21-524D303F9459}"
[HKCU\Software\Classes\Wow6432Node\CLSID\{ADA98CFC-FB4D-4411-8D21-524D303F9459}\ProgID]
"(Default)" = "MPCBrowser.Update3WebControl.3"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"InstallTime" = "1430453895"
[HKCU\Software\Classes\Wow6432Node\CLSID\{74B93321-B3E4-4F84-8E9C-DE30CD0D0F4F}\InprocServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\npGoogleUpdate3.dll"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ADA98CFC-FB4D-4411-8D21-524D303F9459}]
"AppName" = "MPCBrowserUpdateOnDemand.exe"
"AppPath" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"brand" = "GGLS"
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\MPCBrowser\Update]
"Version" = "1.3.27.0"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=3]
"ProductName" = "MPCBrowser Update"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74B93321-B3E4-4F84-8E9C-DE30CD0D0F4F}]
"AppName" = "MPCBrowserUpdate.exe"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=3]
"Version" = "3"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=9]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\npGoogleUpdate3.dll"
[HKCU\Software\Classes\Wow6432Node\CLSID\{74B93321-B3E4-4F84-8E9C-DE30CD0D0F4F}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCU\Software\MPCBrowser\Update]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\MPCBrowserUpdate.exe"
[HKCU\Software\MPCBrowser\Update\Clients\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"pv" = "1.3.27.0"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=3]
"Description" = "MPCBrowser Update"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74B93321-B3E4-4F84-8E9C-DE30CD0D0F4F}]
"Policy" = "3"
"AppPath" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update"
[HKCU\Software\MPCBrowser\Update\Clients\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"Name" = "MPCBrowser Update"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"pv" = "1.3.27.0"
[HKCU\Software\Classes\MPCBrowser.Update3WebControl.3]
"(Default)" = "MPCBrowser Update Plugin"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=9]
"Version" = "9"
[HKCU\Software\Classes\Wow6432Node\CLSID\{74B93321-B3E4-4F84-8E9C-DE30CD0D0F4F}\ProgID]
"(Default)" = "MPCBrowser.OneClickCtrl.9"
[HKCU\Software\Classes\MPCBrowser.OneClickCtrl.9\CLSID]
"(Default)" = "{74B93321-B3E4-4F84-8E9C-DE30CD0D0F4F}"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=9]
"Description" = "MPCBrowser Update"
[HKCU\Software\Classes\Wow6432Node\CLSID\{ADA98CFC-FB4D-4411-8D21-524D303F9459}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ADA98CFC-FB4D-4411-8D21-524D303F9459}]
"Policy" = "3"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=9]
"ProductName" = "MPCBrowser Update"
[HKCU\Software\Classes\MIME\Database\Content Type\application/x-vnd.omaha.playfree.oneclickctrl.9]
"CLSID" = "{74B93321-B3E4-4F84-8E9C-DE30CD0D0F4F}"
[HKCU\Software\Classes\MIME\Database\Content Type\application/x-vnd.omaha.playfree.update3webcontrol.3]
"CLSID" = "{ADA98CFC-FB4D-4411-8D21-524D303F9459}"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=3]
"Path" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\npGoogleUpdate3.dll"
[HKCU\Software\MozillaPlugins\@omaha.playfree.org/MPCBrowser Update;version=9]
"vendor" = "MyPlayCity, Inc."
[HKCU\Software\Classes\Wow6432Node\CLSID\{ADA98CFC-FB4D-4411-8D21-524D303F9459}]
"(Default)" = "MPCBrowser Update Plugin"
[HKCU\Software\Classes\MPCBrowser.OneClickCtrl.9]
"(Default)" = "MPCBrowser Update Plugin"
[HKCU\Software\Classes\Wow6432Node\CLSID\{ADA98CFC-FB4D-4411-8D21-524D303F9459}\InprocServer32]
"(Default)" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\npGoogleUpdate3.dll"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"MPCBrowser Update" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\MPCBrowserUpdate.exe /c"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update]
"eulaaccepted"
"LastChecked"
[HKCU\Software\MPCBrowser\Update\network\secure]
"sk"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"UpdateAvailableSince"
[HKCU\Software\MPCBrowser\Update]
"ui"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"UpdateAvailableCount"
[HKCU\Software\MPCBrowser\Update]
"uid"
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
The process MPCBrowserUpdate.exe:1116 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"lang" = "en"
"pv" = "3.0.0.4"
[HKCU\Software\MPCBrowser\Update\proxy]
"source" = "IE"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
[HKCU\Software\MPCBrowser\Update]
"uid"
[HKCU\Software\MPCBrowser\Update\network\secure]
"sk"
The process MPCBrowserUpdate.exe:3724 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
The process MPCBrowserUpdate.exe:1760 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2C\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\MPCBrowser\Update\proxy]
"source" = "IE"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 5D 82 AD B9"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"2796BAE63F1801E277261BA0D77770028F20EEE4"
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
"sk"
The process MPCBrowserUpdate.exe:3188 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
[HKCU\Software\MPCBrowser\Update\proxy]
"source" = "IE"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"pv" = "3.0.0.4"
"LastCheckSuccess" = "1430454182"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"LastCheckSuccess" = "1430454182"
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\MPCBrowser\Update]
"LastChecked" = "1430454182"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"RollCallDayStartSec" = "1430370000"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"pv" = "1.3.27.0"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4]
"Blob" = "04 00 00 00 01 00 00 00 10 00 00 00 91 DE 06 25"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"lang" = "en"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"RollCallDayStartSec" = "1430370000"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"UpdateAvailableSince"
"UpdateAvailableCount"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\MPCBrowser\Update\network\secure]
"sk"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\MPCBrowser\Update\ClientState\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}]
"tttoken"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"UpdateAvailableSince"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"UpdateAvailableCount"
[HKCU\Software\MPCBrowser\Update]
"uid"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"2796BAE63F1801E277261BA0D77770028F20EEE4"
[HKCU\Software\MPCBrowser\Update\ClientState\{00337EA4-7B9A-44A6-B45B-B1722CD4343E}]
"tttoken"
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
The process MPCBrowserUpdate.exe:1448 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\MPCBrowser\Update\network\secure]
"c"
"sk"
Dropped PE files
| MD5 | File path |
|---|---|
| e49f2fb0d9f02031b404b787eb716115 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\Installer\chrmstp.exe |
| e49f2fb0d9f02031b404b787eb716115 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe |
| e208d26a00595997f1dd378e88a38fd4 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\PepperFlash\pepflashplayer.dll |
| 1a723da82ed26889181bd06afc4194b0 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\chrome.dll |
| a67946d8e726a9a5435fd79eda5fe6cb | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\chrome_child.dll |
| 74eef8f51efd57e72a4d08c28ca2ed76 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\chrome_elf.dll |
| 0e313b5e621db0c5caf4f2abfea6a5fe | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\chrome_watcher.dll |
| c5b362bce86bb0ad3149c4540201331d | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\d3dcompiler_47.dll |
| 3e90522c28991bf839e0c0a34c7a2d2e | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\delegate_execute.exe |
| 7533fe5e6bcab8a2dff1e933cd650cfc | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\ffmpegsumo.dll |
| 4c76235c1d82d114ca32a44bb85dc9c7 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libegl.dll |
| aa0f48a75fb075263cd202b96607079b | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libexif.dll |
| 71c4f46c76abcd76f81a88346b012242 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\libglesv2.dll |
| 7daf0589ba5687c39a6c25ae63a05aa2 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\metro_driver.dll |
| f3593e58ce3de3f19d662bd28864463e | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\nacl64.exe |
| 5e9df70a66ac3ddcb1927d8f32088c42 | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\widevinecdmadapter.dll |
| 77f595dee5ffacea72b135b1fce1312e | c:\Program Files (x86)\Google\Chrome\Application\42.0.2311.135\xinput1_3.dll |
| b4605d865bf030cd5cefcc3266a06c7f | c:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\42.0.2311.135\42.0.2311.135_chrome_installer.exe |
| b4605d865bf030cd5cefcc3266a06c7f | c:\Program Files (x86)\Google\Update\Install\{09D3F8A5-EB89-4712-A03A-55808701600F}\42.0.2311.135_chrome_installer.exe |
| 84c5634339f6c989096afe6abb31290d | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserCrashHandler.exe |
| 84c5634339f6c989096afe6abb31290d | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdate.exe |
| d31fb2072f380acc160b0d473a26a9c4 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateBroker.exe |
| 4ba187c621b7343693a3292e7ef30b85 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateOnDemand.exe |
| ebd871614bc512f3d1893bc93e526f11 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdate.dll |
| 0fbd15831e41a2b9b25b115fdf5dedc9 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_am.dll |
| 1bbf139b2df07361aa646196b6de9eaf | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ar.dll |
| ed9b88ad06a4e508858cc10dfac622a7 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_bg.dll |
| 34eba057b57f29da22a7dcb98dba7673 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_bn.dll |
| aa8af02bc3a16a347c2f03e6b26c50ad | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ca.dll |
| 1b199ec3ae62a4f39acdccb53675915e | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_cs.dll |
| 24ecb3378b2b9387e5e55e7fe62b7760 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_da.dll |
| 62a74752bb3d7d0f580f101e8ae93f8b | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_de.dll |
| 526142c50d11fc822cbb3a17bfefa84b | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_el.dll |
| 79e8c4274649d1d21762c7c411955578 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_en-GB.dll |
| 3a345b7de1c927546a72f2c9cd0582d1 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_en.dll |
| 3e2849e002c1400050aaa8a73a08f31c | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_es-419.dll |
| 628075a45d323bdfa6b809b8a51fca88 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_es.dll |
| dafd2c8ab02e8336fbdf51313ec1c0aa | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_et.dll |
| eaef19428b40ef496a72fdfff7b7908e | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fa.dll |
| 025e84f6a09e1a3c898ef091338ffdfb | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fi.dll |
| 37ea9beda0f41eb8f317eb32abd57218 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fil.dll |
| 7eb03edc8197a6992544e4fc0b277fa2 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fr.dll |
| 1583f4c9142d4bf3982733c0220ec724 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_gu.dll |
| 08708da9b8858ab78f4d8edc2f3a8af9 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hi.dll |
| 6b7006cbfe65982ba0fb826a17c8e2a0 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hr.dll |
| 8d1a584b3afc12b9ce1fada2d1372416 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hu.dll |
| 728f1a83fdf3f2c67fe62eb9fbc6368f | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_id.dll |
| e4e9c7cfc38857d89bf4804a7ded1053 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_is.dll |
| 1b372ff3342d338186e70e182bf4236c | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_it.dll |
| 30f04edeb07a4e810cbeb904a1dbf773 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_iw.dll |
| 62eb7ca11fdeeaa14837da231d3ff879 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ja.dll |
| cbe063378e39ddc2e29b5071a6430e77 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_kn.dll |
| 64cabc50741da383c3480e6261e33fa7 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ko.dll |
| 46d637f1171e71caf2ae402cfa9daedf | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_lt.dll |
| e0cbf0bd1c5fb418703406b66c218cf9 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_lv.dll |
| 84795fa1b13380551ee13b9c07e6a0a2 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ml.dll |
| 895c9574e6c3bca4001a7ebae8655fc0 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_mr.dll |
| 9bf98b78cd0e8f81ca759259c1fb5f42 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ms.dll |
| 895936f67297305a8d3c3b0cb70b75e3 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_nl.dll |
| 7f27be7f3436de4d260139219fb24297 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_no.dll |
| 4c2b85e9b3e1402875a4d59b46cd664a | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pl.dll |
| 483062809e6041d2cfd884470e7ddba0 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pt-BR.dll |
| 59c0f1e9bdbc4f4b0262ab8f5e6889cb | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pt-PT.dll |
| 36f59f8037b2b9cdbc6d978697902bd6 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ro.dll |
| 0c3b6f398092012ce1a3a0843e613eca | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ru.dll |
| eb77e49c8f6b7cf9b7a836c3dc94db59 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sk.dll |
| 9e546a2d759014b04282c86c0d539bdf | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sl.dll |
| 87c812997721156bb523d26d4643c203 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sr.dll |
| 7aa5982eea4f0ecdcf3e038bd2e7f10e | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sv.dll |
| 29776ac3fefd6f4932ed38f2e4c785e5 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sw.dll |
| 7248a406a3b981f012308b6c1ea02f41 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ta.dll |
| 094a3b503ac60082f0d254f2ccfba8d2 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_te.dll |
| 83ce8158528de0204acea0a2d29297d8 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_th.dll |
| 8a3906212e7864b3ebfc3e565c713467 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_tr.dll |
| 583645544813758118b082aac16c21e0 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_uk.dll |
| 1b053dbe8cccc50da6bbb9499ef19a84 | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ur.dll |
| 2fc265fc35e150b396645a0003fb1b3e | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_vi.dll |
| d583c0b2c34d3ff206bdcf468557e5be | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_zh-CN.dll |
| 91d93fcc690b9333f590675bd4de8eea | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_zh-TW.dll |
| 3ec326738598d04a2be1fe39b805043e | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\npGoogleUpdate3.dll |
| 9cdf8821c37ffd91450ae65a0cccc0fa | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psmachine.dll |
| e21d010030800faa180ca6c44a52970a | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psuser.dll |
| 28ca60853e1f3492dbaf5cc25f8b13bf | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\3.0.0.4\MPCBrowserUpdater.exe |
| aaafcb8cb6f4c07bad027f23a471299e | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\3.0.0.4\setup.exe |
| 84c5634339f6c989096afe6abb31290d | c:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\MPCBrowserUpdate.exe |
| aaafcb8cb6f4c07bad027f23a471299e | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Installer\setup.exe |
| 486a7a38e40693784c9d8d8d3c0aa66e | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\am.dll |
| 141eb14b1d21accc95af75f83de9a92e | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ar.dll |
| a23831fad4408d3734e697b0366155fe | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\bg.dll |
| 10bc9fdf9e9964993b3a3551bb522c30 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\bn.dll |
| a5c5cbef8194c3454f7e71faddc8d089 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ca.dll |
| 0710e57d30b30ca972a73fef2a68bc14 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\cs.dll |
| 4d84460644cdf710455ebe2f1eccac53 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\da.dll |
| bcb0d4c7045ba7d93299656267623553 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\de.dll |
| 1719db574609fe36f3d2b0affd8e97e9 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\el.dll |
| 315d749486c0547a04b7dc000bc649da | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\en-GB.dll |
| 6b31db92bc4fa1f48d255a1947f2acaa | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\en-US.dll |
| a44eb5c042184a05c5c8763aab046a9f | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\es-419.dll |
| fd21270cf7cd4bbfcbcb2e81fc1f8ac5 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\es.dll |
| e0f27f5052e72df81d748357ec1bd3be | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\et.dll |
| a0df01591c8e373b09893a2053e9a219 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\fa.dll |
| 9953da05d2fadeeb7a013188470c0336 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\fi.dll |
| 95fb8d0c1f61497d2c6adcc2c07ac5e8 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\fil.dll |
| dd3ca6e6343ebc140677a85ca77758db | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\fr.dll |
| 8cfaa3e756d7e6c4cccadb7cc18b4e4d | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\gu.dll |
| 49ea7fd0b0c4ad21aed51dac30b341f3 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\he.dll |
| 94a1c80bafe0c2c3cdffe5b1503c91e6 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\hi.dll |
| 37fde67a0da4898d53e95a9c66f8f07c | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\hr.dll |
| 70ef238a09d40d6c847924c14b721f57 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\hu.dll |
| 2679e9fc35aeeb9c45080a690703b164 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\id.dll |
| 7a7c098f429236e9928cb9830e0a392f | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\it.dll |
| d52b3c6ac6df5aee1e08e9631dbee0d8 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ja.dll |
| e5b9bf22e45a7eb971b1ee16677c6137 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\kn.dll |
| c7098fee4051d5a0ed7e2376ec7716ad | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ko.dll |
| 66d74c06548ae5f5bd997baf5043e7e2 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\lt.dll |
| 2170f1992ad36a3254ed9ca24681f9df | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\lv.dll |
| 553458fd70954a501564e15bb556a21a | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ml.dll |
| 574603842f7cd7166d656c6913f2b205 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\mr.dll |
| 1ee7962e0ed2637a2c98644c17a44250 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ms.dll |
| 7ebc64ee320b0be134b362da472dbc76 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\nb.dll |
| 5954f67b2f01c1e4a46691ddee636201 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\nl.dll |
| 3b40f625be1deab2daf2eddc80f12cd0 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\pl.dll |
| 2153aa1cdba72dc539dc35ae06d3b092 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\pt-BR.dll |
| 7cc2ff5494e80c8bc79dc1b540e0231e | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\pt-PT.dll |
| d1d1e1acdd7a91387b0940c42d1e6c10 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ro.dll |
| acc97ce897ab0bc295e237d981e88fb6 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ru.dll |
| 8ddc5a3481b030090968b378cde1a95e | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\sk.dll |
| 53a80482257cc4f7ff162bd2f3446ef2 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\sl.dll |
| 4a92e00d9b8cbf9aebb1bd8760a6f69f | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\sr.dll |
| 0d2bd7ff8b554cbe3718d1b89358887a | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\sv.dll |
| 5ade1db3f067c481f38cdad766e87d42 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\sw.dll |
| 8c8c2f553801902b3cf73b8222f9b58b | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\ta.dll |
| 252a3e6975252aef63ec31735fc8969d | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\te.dll |
| 0b8deb28508ab211647db26c0e9ae813 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\th.dll |
| b78eddd33f084cc29b5a8dbc5723b826 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\tr.dll |
| 37cb4ed0283f0fb468a70655a624d910 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\uk.dll |
| 02e1e705659ccf2dcd7f820087f24c4d | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\vi.dll |
| e8ec791fa9aebabb0738c06c70087d66 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\zh-CN.dll |
| 9406ffaa2255267d3f450158e0e12ab3 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Locales\zh-TW.dll |
| fc2b569048ff63b92b09bc28fab414c6 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\chrome_frame_helper.dll |
| 53eca236bfff55352a4258abd06246f9 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\chrome_frame_helper.exe |
| e3e6f2a3274c2acb2e45c18b74ec140f | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\chrome_launcher.exe |
| ad081c5a3d4b8805cb4d72af1b678015 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\delegate_execute.exe |
| 5434e18b933e03f274d8da59fda4c676 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\icudt.dll |
| 73b3393fb7aa22af8eb4b824a548cd1c | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\libegl.dll |
| 22ca8ab99291ed861df63a4f0159a823 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\libglesv2.dll |
| c287590fced0a0b8dd0eab4c6489399c | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\metro_driver.dll |
| 3796eccd94ef578c9a73c9d45a132f7b | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\nacl64.exe |
| 33664795d3303abc73855fff908254ff | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\npchrome_frame.dll |
| 98c3498ae7fb690775c2e61da5e3d8a0 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\playfreebrowser.dll |
| 24be300b52fbba1e482d27bb385a9c24 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\ppgooglenaclpluginchrome.dll |
| 9d075bd1ee0088968c6f334510fe1dd0 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe |
| 72c5553b89524c3a58dfe91b2cece127 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\JNGLoad.dll |
| e4450e7fd70c4c576a299b5ba945dea7 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Squall.dll |
| dcaac1d97788f8908f6039bc9bee7589 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\game.exe |
| c9c498890b3d1c646b13db567139fd3e | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\play.exe |
| adf1e02413aa7d77d1ad068b4a3646b9 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extensions\cmgompiogmpngbepkhaildjbcedihobe\2_0\GRC.dll |
| 0c8597dbc74aaf5179471ba013e3c6b4 | c:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extensions\kmafafaebkfagbfockogghbkjblelpbh\2_0\NPSWF32_11_8_800_94.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name:
Product Version: 1.0.0.0
Legal Copyright: Copyright (c) 2009
Legal Trademarks:
Original Filename: farm_frenzy.exe
Internal Name: farm_frenzy.exe
File Version: 0.0.0.0
File Description: gs_en farm_frenzy
Comments:
Language: Language Neutral
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 265654 | 265728 | 4.56983 | 71b758a0e76f09166d8b270d5c729f1d |
| .rdata | 270336 | 59884 | 59904 | 3.15445 | 570a8276cb39992fa705dd952717a624 |
| .data | 331776 | 16992 | 7680 | 2.86136 | 49c4be116c4eb68a46223fbab7c7ca52 |
| .rsrc | 352256 | 613644 | 613888 | 5.09408 | bbbc0db87a041f50ca708ed476fefc2f |
| .reloc | 966656 | 24730 | 25088 | 3.9397 | dd281b58164ef64b3327b78102ba84a6 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://www.playfree.org/customization/?bundle=gs_en | |
| hxxp://www.playfree.org/en/gameinfo/?game=farm_frenzy&browser=gs_en | |
| hxxp://www.playfree.org/icons/product_logo_128.png | |
| hxxp://mpcstatic.com/gn/468/farm-frenzy_71x71.jpg | |
| hxxp://files.playfree.org/PlayFreeBrowser/VERSION | |
| hxxp://files.playfree.org/PlayFreeBrowser/GUID | |
| hxxp://files.playfree.org/PlayFreeBrowser/setup.exe | |
| hxxp://files.playfree.org/PlayFreeBrowser/chrome.packed.7z | |
| hxxp://files.playfree.org/PlayFreeBrowser/MPCBrowserUpdater.exe | |
| hxxp://update.playfree.org/browser/updatechecker/?uid=PFBrowser&contract=C132BADE-00A8-4386-BB5A-D30720EBAB87&date=1430427600&version=3.0.0.4&build=gs_en&action=install&mode=installer | |
| hxxp://update.playfree.org/service/update2 | |
| hxxp://update.playfree.org/service/update2?w=3:KUuZkuoC7H8t1GILnNZ8kHg9xSafCQra5vhZDuzrPIy84ga3Jm6MJCU8kEVOE22Rl9a0cnj1Kq5i__mvd6itMjmMDN93A0guOwTCflpKx08iVu74hey4YZb6Lh-41BNcBwCze4rZ3nTS926S43CTAQX8sbxiX50uWVfvMVyScZ0 | |
| hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab?3957b92ea85f63c5 | |
| hxxp://update.playfree.org/browser/updatechecker/?uid=PFBrowser&contract=C132BADE-00A8-4386-BB5A-D30720EBAB87&date=1430427600&version=3.0.0.4&build=gs_en&action=run | |
| hxxp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp | |
| hxxp://www.playfree.org/en/gametabinstall3.html?game=farm_frenzy | |
| hxxp://home.playfree.org/en/main0.css | |
| hxxp://www.playfree.org/store_bundle/en/gameinfo3.php?lgp=farm_frenzy&browser=lp_en | |
| hxxp://home.playfree.org/en/acts.js | |
| hxxp://mpcstatic.com/i/mmo_banners.js | |
| hxxp://mpcstatic.com/gn/111x83/1819_111x83.jpg | |
| hxxp://mpcstatic.com/gn/111x83/1817_111x83.jpg | |
| hxxp://mpcstatic.com/gn/111x83/1813_111x83.jpg | |
| hxxp://mpcstatic.com/gn/111x83/1811_111x83.jpg | |
| hxxp://home.playfree.org/en/i/s_button.png | |
| hxxp://home.playfree.org/en/i/games_bg.png | |
| hxxp://mpcstatic.com/i/banners/mmo/Stormfall_300x250_en.jpg | |
| hxxp://www-google-analytics.l.google.com/ga.js | |
| hxxp://files.playfree.org/gametab/farm_frenzy-lp_en.zip | |
| hxxp://d7elgzrnbve23.cloudfront.net/search/lib/ptwidget-1.0.js | |
| hxxp://mpcstatic.com/gn/128x128/468_128x128.png | |
| hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.4&utms=1&utmn=719186822&utmhn=home.playfree.org&utmcs=UTF-8&utmsr=1716x901&utmvp=833x755&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=11.8 r800&utmdt=PlayFree Search&utmhid=2008743007&utmr=-&utmp=/en/?utm_source=gs_en&utm_medium=hp&utmht=1430453906475&utmac=UA-1217017-45&utmcc=__utma=120822935.470092875.1430453906.1430453906.1430453906.1;+__utmz=120822935.1430453906.1.1.utmcsr=gs_en|utmccn=(not%20set)|utmcmd=hp;&utmjid=470535854&utmredir=1&utmu=qBAAAAAAAAAAAAAAAAAAAAAE~ | |
| hxxp://www.playfree.org/favicon.ico | |
| hxxp://update.playfree.org/?twlogincheck=true | |
| hxxp://sba.yandex.net/downloads?client=PFBrowser&appver=2.3&pver=2.3&apikey=0151016567ffe9484fd45115e97569642d6f33617a2df7c019a2a8b33c | |
| hxxp://repository.certum.pl/ca.cer | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/bP9cwuh_axs0J-Nbuo42kmwnhgt4rWNfe0gHrOFh0Mk=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/bP9cwuh_axs0J-Nbuo42kmwnhgt4rWNfe0gHrOFh0Mk=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/qDo5pwKwKj9YxZJyWqEiDvFdZDuI5PahFwZOoPI4-7A=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qDo5pwKwKj9YxZJyWqEiDvFdZDuI5PahFwZOoPI4-7A=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/tFrZWBGYzrmSIkQD08neZlV3aJoQfKyKFZgZSg7ts88=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/tFrZWBGYzrmSIkQD08neZlV3aJoQfKyKFZgZSg7ts88=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/8TrlR6tjVYIn5nOzkeYe9TWzQniXkQUFt-m-_y4jm7A=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/8TrlR6tjVYIn5nOzkeYe9TWzQniXkQUFt-m-_y4jm7A=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/6REFNUxyRF2vLNuQD5eV-JDP4re7A_YwPBkbPa1JkfE=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/6REFNUxyRF2vLNuQD5eV-JDP4re7A_YwPBkbPa1JkfE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/tsOoy7JAp7Lz5F39t4GNxgnXgvcVKsoLv9IDzQgKTp4=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/tsOoy7JAp7Lz5F39t4GNxgnXgvcVKsoLv9IDzQgKTp4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Jj0fDeTYdxpkeaiXNqK7Ypwod0ePmqChmJPwBCFVIQk=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Jj0fDeTYdxpkeaiXNqK7Ypwod0ePmqChmJPwBCFVIQk=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/m8zTXWVYnt2StqmNe4n0gx7bH32b0Uex1h36Ocbxmp0=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/m8zTXWVYnt2StqmNe4n0gx7bH32b0Uex1h36Ocbxmp0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/rHqFII0PWn-x5sL4llxzm8PrL_k6RDogkhqBV80h3JU=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/rHqFII0PWn-x5sL4llxzm8PrL_k6RDogkhqBV80h3JU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Y0cCKitNdebmBGg2qVxMow9PkJ5C5cS4IunvOy1sG4I=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Y0cCKitNdebmBGg2qVxMow9PkJ5C5cS4IunvOy1sG4I=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/HTljzKj4oCu9PHBzGXK_dMaJUzy_2N0eWMp9W7Zt6QI=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/HTljzKj4oCu9PHBzGXK_dMaJUzy_2N0eWMp9W7Zt6QI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Bo9JfyHVL7b5NSgfR8eXJuvq1Sz1--op2i8kfamuRcI=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Bo9JfyHVL7b5NSgfR8eXJuvq1Sz1--op2i8kfamuRcI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Ccn3RlRn-KWmMNIgKEOIrNd9c9KzqusM19c-qz1fg1A=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Ccn3RlRn-KWmMNIgKEOIrNd9c9KzqusM19c-qz1fg1A=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/LkU_PzHi470rWlFlDx6vPOMdSCxN46QTXhBcM_R_KXc=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/LkU_PzHi470rWlFlDx6vPOMdSCxN46QTXhBcM_R_KXc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/ihvaXT0zxWqt0I1IIj7mFRJdHKF0OMXfAKRwiTwrFnk=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ihvaXT0zxWqt0I1IIj7mFRJdHKF0OMXfAKRwiTwrFnk=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/olMNSrIv3_9-5Zz2qU3JZv0ECEq0RlY7SE12jovxqOc=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/olMNSrIv3_9-5Zz2qU3JZv0ECEq0RlY7SE12jovxqOc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/y89AXj6vwBtPw01Gvvljk0iJ7w5X_ddoWa5ftRYPgU8=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/y89AXj6vwBtPw01Gvvljk0iJ7w5X_ddoWa5ftRYPgU8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/sJEvZc18T-F36DdkfLn5DgD2i3J2L2_5jaZ89QVBmvg=.chunk | |
| hxxp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/sJEvZc18T-F36DdkfLn5DgD2i3J2L2_5jaZ89QVBmvg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Jftr8wgkwo56H9yX6nJePhy2DKlA48l3kn4aJ2EZ6DY=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Jftr8wgkwo56H9yX6nJePhy2DKlA48l3kn4aJ2EZ6DY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/xEztrZ_otV4HLVyDpTFlDQBGcxzWLzBBBm4NsdzFEwc=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/xEztrZ_otV4HLVyDpTFlDQBGcxzWLzBBBm4NsdzFEwc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/iux_0kYqwLpBad2nO9MehhPZp_IurAi8AdwiLiyyVyY=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/iux_0kYqwLpBad2nO9MehhPZp_IurAi8AdwiLiyyVyY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/h_xpPnaTd4FhVPIkCA2nensqXe_s9gRnukwHWL_1IIM=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/h_xpPnaTd4FhVPIkCA2nensqXe_s9gRnukwHWL_1IIM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/NOmm6qIJGzLneEHWSVjp5adubXmIgV9QvN8DqpIxpMg=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/NOmm6qIJGzLneEHWSVjp5adubXmIgV9QvN8DqpIxpMg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/PNPgF0Jh61aGCyqcVnEpeT5gL8KFscgS6OjPTI44wis=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/PNPgF0Jh61aGCyqcVnEpeT5gL8KFscgS6OjPTI44wis=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/FHvKorYRa9bSJlD4xPUO7BZe3gbwe7hXGscMWGeHqIw=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/FHvKorYRa9bSJlD4xPUO7BZe3gbwe7hXGscMWGeHqIw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/wZBd-e3nlAYWe0lPx6hvMHNc-sDwWwuhlIin-owxthM=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wZBd-e3nlAYWe0lPx6hvMHNc-sDwWwuhlIin-owxthM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/p8jCP90AhLl5ufYMynxaluNFR688R-dqD2Twp15_Jiw=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/p8jCP90AhLl5ufYMynxaluNFR688R-dqD2Twp15_Jiw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/bV86Zyzwrz-XuBUsX9if0otATsDvqxKW9-y0KqjYYzA=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/bV86Zyzwrz-XuBUsX9if0otATsDvqxKW9-y0KqjYYzA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/GsrVhUq6AbrMVrXw4Ec6ftazfcF7150-LStN0PdRwKA=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/GsrVhUq6AbrMVrXw4Ec6ftazfcF7150-LStN0PdRwKA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Z-BZzgdR6niuNm6Dbw-4jp7KnREXbvzrB0Xn2C-u9d0=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Z-BZzgdR6niuNm6Dbw-4jp7KnREXbvzrB0Xn2C-u9d0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/S0qM3gmmlTfjfU09iNPuDLKQ-EcgLa4CykvNbVwOWz0=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/S0qM3gmmlTfjfU09iNPuDLKQ-EcgLa4CykvNbVwOWz0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/ALWeV724V9w89dwuc3ClyOUZxXY9wArCzxfS4TYmikU=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ALWeV724V9w89dwuc3ClyOUZxXY9wArCzxfS4TYmikU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/7bOJgy8Hm2aYptpm9nr6UfbSLV0FRWxA8aiAgMmpc3w=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/7bOJgy8Hm2aYptpm9nr6UfbSLV0FRWxA8aiAgMmpc3w=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/RbA3tgllhVw4uoreA9t0dnot91l0x4S0xbKnKLSSklM=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/RbA3tgllhVw4uoreA9t0dnot91l0x4S0xbKnKLSSklM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/CiVhTt28sFS93rXevnsokT4ntD6_q3CDbxSad31QNu0=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/CiVhTt28sFS93rXevnsokT4ntD6_q3CDbxSad31QNu0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/8XiZtdDw1DowEM1tM0Tx3-7Fu0YDRjcZv3cZUNkgNEI=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/8XiZtdDw1DowEM1tM0Tx3-7Fu0YDRjcZv3cZUNkgNEI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/quCU-R968hkl0cyruELC_MV3YrizvN33lCu_XyBmd4E=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/quCU-R968hkl0cyruELC_MV3YrizvN33lCu_XyBmd4E=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/htfrrZFnqTgSC2mR0kmzYfL1_FCaDvtToyAQP0dl3VM=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/htfrrZFnqTgSC2mR0kmzYfL1_FCaDvtToyAQP0dl3VM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/ZuAPRjyGYJlkTcv1FEc5TDP_4G-_uF22_OMHVkTckZw=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ZuAPRjyGYJlkTcv1FEc5TDP_4G-_uF22_OMHVkTckZw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/jEtUT_cL0M27Wn976ODIjlalYuMX3QGH-mjk2rUKFQA=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/jEtUT_cL0M27Wn976ODIjlalYuMX3QGH-mjk2rUKFQA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/wcDPbWwJTE2PtmVwcgnQhhl6hkrs-T-aO8g8Itcyd-U=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wcDPbWwJTE2PtmVwcgnQhhl6hkrs-T-aO8g8Itcyd-U=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/0D3N_cx0Jm-0zlRfzxtI1c1JCExEEO-3DUtScKCpOHs=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/0D3N_cx0Jm-0zlRfzxtI1c1JCExEEO-3DUtScKCpOHs=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Btt71EDwI8tUxpLjIa52nMtiSPr0jPATp90kyoijHJ0=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Btt71EDwI8tUxpLjIa52nMtiSPr0jPATp90kyoijHJ0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/-anZCDFwCsiDfCOfxIKUAJrW0FZfXw4lV2mDR_XwEwU=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/-anZCDFwCsiDfCOfxIKUAJrW0FZfXw4lV2mDR_XwEwU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/O9g5OJm4JRG7U6M0FrlMP6KS2sLifUb-a-mH5mfdXIc=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/O9g5OJm4JRG7U6M0FrlMP6KS2sLifUb-a-mH5mfdXIc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Tj7ZLCSSjPdV1SzabZFpEPSGnNkXuSnbXXrEG9YWUsc=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Tj7ZLCSSjPdV1SzabZFpEPSGnNkXuSnbXXrEG9YWUsc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/wEXpqs63b7RAaV1YPIGl6QqBL-E4S-69bDQwGU7vRBk=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wEXpqs63b7RAaV1YPIGl6QqBL-E4S-69bDQwGU7vRBk=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Sl6kTbztAG7gh4K9-UWT83pEpeufQD16QOSbGOMH940=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Sl6kTbztAG7gh4K9-UWT83pEpeufQD16QOSbGOMH940=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/-Pz-fPXqNiCqMKFOyFGBikrEmpIlZiMQ-guIaOYFwRo=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/-Pz-fPXqNiCqMKFOyFGBikrEmpIlZiMQ-guIaOYFwRo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/qDC0G_w_wSrAQ-0l04BWQgPpcKgZMDT6ciA2msBNIzY=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qDC0G_w_wSrAQ-0l04BWQgPpcKgZMDT6ciA2msBNIzY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/5QoMmAuV8US3Ysur3PVelYvOwlVagaglfaAafQ9_Yig=.chunk | |
| hxxp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/5QoMmAuV8US3Ysur3PVelYvOwlVagaglfaAafQ9_Yig=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/qnZ2HvzM37H8A8rLm-gJ0ujA5quc_OP3jtgBUBXCJmk=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qnZ2HvzM37H8A8rLm-gJ0ujA5quc_OP3jtgBUBXCJmk=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/47t5dK4QAJ1BiKhFGh-dfr0-SMJdePVognk64vffMd4=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/47t5dK4QAJ1BiKhFGh-dfr0-SMJdePVognk64vffMd4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/fhv1pKXYMHqded8rPqy-jx4dzaITAE7VPyaCqcXmEPI=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/fhv1pKXYMHqded8rPqy-jx4dzaITAE7VPyaCqcXmEPI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/2GIB_v116SbEk07Zs-UKwNZth2eBtM7lJtrdsWr_ITI=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/2GIB_v116SbEk07Zs-UKwNZth2eBtM7lJtrdsWr_ITI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/FfNH48w7DUHj48hUCP8YmqTLg961wKPqU4prBE4tEFY=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/FfNH48w7DUHj48hUCP8YmqTLg961wKPqU4prBE4tEFY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/0eYbR7AY1kV5MF7bqScyKku40te-z1-r0eu-Er90fgM=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/0eYbR7AY1kV5MF7bqScyKku40te-z1-r0eu-Er90fgM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/InCnLK-Y8LZ6JG7r-6OZj7o4DrW6iCbFTv3xbble6yQ=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/InCnLK-Y8LZ6JG7r-6OZj7o4DrW6iCbFTv3xbble6yQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/S7ivwxHcennvSEQHDpfGAO5hLoKWJSnvokyqYRJyLx4=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/S7ivwxHcennvSEQHDpfGAO5hLoKWJSnvokyqYRJyLx4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/YGfxA6S0Iv-jWOp8V1Su16gcyiJwlNoX7fjo0kbnqn8=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/YGfxA6S0Iv-jWOp8V1Su16gcyiJwlNoX7fjo0kbnqn8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/0CUhV4Pw6226fhXk7ayz0zEcPuXwbi30h1RwoGHxmII=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/0CUhV4Pw6226fhXk7ayz0zEcPuXwbi30h1RwoGHxmII=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/CBZSVliJ3jUTEovyUiGBSNmHnvKYhm043-gh-uvUrbg=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/CBZSVliJ3jUTEovyUiGBSNmHnvKYhm043-gh-uvUrbg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/kM4mzd_BuL56ZUjvvtfFU4OlLoZ0tcQBXhFE43FTkn4=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/kM4mzd_BuL56ZUjvvtfFU4OlLoZ0tcQBXhFE43FTkn4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/qZC_0gz5QY5TFOHvTQ0KoWe5B3G87JxkyA8cg5HkIiM=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qZC_0gz5QY5TFOHvTQ0KoWe5B3G87JxkyA8cg5HkIiM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/gGlRwSx8Dzo1uJ0yLqn9uPHpLoXJEVWw4QTefK6Bsn0=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/gGlRwSx8Dzo1uJ0yLqn9uPHpLoXJEVWw4QTefK6Bsn0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/TehQ2ixiUtxEpr0ycrxRN_kCJgW6Bhwks3x4Q93OUW8=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/TehQ2ixiUtxEpr0ycrxRN_kCJgW6Bhwks3x4Q93OUW8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/ttESbMYCl0F1zsR55cKlwxZJYMsyLjORkbBoc7Zm5gY=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ttESbMYCl0F1zsR55cKlwxZJYMsyLjORkbBoc7Zm5gY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/ueUlg7RwaptET2592qwxtihIaGM0Zy7pKwY5E8kERZE=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ueUlg7RwaptET2592qwxtihIaGM0Zy7pKwY5E8kERZE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/lRSiPs_nDoWaue8Z9Qu4rVd7SFCZjV2jZ7ug0nBaMDc=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/lRSiPs_nDoWaue8Z9Qu4rVd7SFCZjV2jZ7ug0nBaMDc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/ituihT2nIuOO6K7aEfwTkyN_MxBmCcdyz-1vcd_m2wE=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ituihT2nIuOO6K7aEfwTkyN_MxBmCcdyz-1vcd_m2wE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/mW94EcunmakWRnLV-MS5hq-LjJaiSXJCzVFzlQt6-NY=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/mW94EcunmakWRnLV-MS5hq-LjJaiSXJCzVFzlQt6-NY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/3Tj0bVUpKpSFrZPgfwQzX2xTELkpN6SDPWBdFeZ82hg=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/3Tj0bVUpKpSFrZPgfwQzX2xTELkpN6SDPWBdFeZ82hg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/QWJEMg5X_Yrd4iTgGTm7iFacTsiaurN1LIdYeVk8r3Y=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/QWJEMg5X_Yrd4iTgGTm7iFacTsiaurN1LIdYeVk8r3Y=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/WNYAEB6kHQLqH03rTAKlV4BJxP2z0dd2ogHtOf7kFoU=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/WNYAEB6kHQLqH03rTAKlV4BJxP2z0dd2ogHtOf7kFoU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/ua4zZ337Cq0_RFw8igoS2bdlDOvEwayBRDquwRRN0LQ=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ua4zZ337Cq0_RFw8igoS2bdlDOvEwayBRDquwRRN0LQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/GUm2SD84TFLXUY9w5Ml6upZqTjz35cgyPrGvWrBgYeI=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/GUm2SD84TFLXUY9w5Ml6upZqTjz35cgyPrGvWrBgYeI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/1K9aDMnPxpkE2R2aBK4b2E3IagxTFurTWM6YCJFB54g=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/1K9aDMnPxpkE2R2aBK4b2E3IagxTFurTWM6YCJFB54g=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/BN_fefG7YqPXI2wavBHdY_Gcg-YkjI4hH8Z1sED-s8s=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/BN_fefG7YqPXI2wavBHdY_Gcg-YkjI4hH8Z1sED-s8s=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/YG__nsDShaQvw9cK8iRvgEwVjCEJcjecHox6seWUdLQ=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/YG__nsDShaQvw9cK8iRvgEwVjCEJcjecHox6seWUdLQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/nB0tjQFotnc6cc-qs7MVBADJ66-XV6kfwDsAr-8FW9E=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/nB0tjQFotnc6cc-qs7MVBADJ66-XV6kfwDsAr-8FW9E=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/S68JNpsZmJZq6F4upq2Bd2Dw4N2MAoSZ_bdHW_x4e2g=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/S68JNpsZmJZq6F4upq2Bd2Dw4N2MAoSZ_bdHW_x4e2g=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/qzgYzW75oibJa6fwVg4hubmLlvrDL4ZEYWL5JJvg_H4=.chunk | |
| hxxp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qzgYzW75oibJa6fwVg4hubmLlvrDL4ZEYWL5JJvg_H4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/BC0-t8qDOZWMvEUrn6JXSuUN6qhlTVaqNx79F0rdNVc=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/BC0-t8qDOZWMvEUrn6JXSuUN6qhlTVaqNx79F0rdNVc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/lF47Sh_HLEdUNiXpguEQ9zZeeyjhHFGZNZVIF3fgnXw=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/lF47Sh_HLEdUNiXpguEQ9zZeeyjhHFGZNZVIF3fgnXw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/5S79mJ6464OwK7yKBT2PYdKWEZ4aQHolIEUHr4Tzyf4=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/5S79mJ6464OwK7yKBT2PYdKWEZ4aQHolIEUHr4Tzyf4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/VR8x-VIlD9su8cKntNAkoMX85wo3_9pJu8jiDHcZtHE=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/VR8x-VIlD9su8cKntNAkoMX85wo3_9pJu8jiDHcZtHE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/KUfgkRS_-x-xLthI9bemI07LuTOBbdjQXJVT1Gcc8Fs=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/KUfgkRS_-x-xLthI9bemI07LuTOBbdjQXJVT1Gcc8Fs=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/JfMelIF4lIIljMS8fg5WquzqYqSh-C6DIxDq6ByNvqo=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/JfMelIF4lIIljMS8fg5WquzqYqSh-C6DIxDq6ByNvqo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/Xg-BBhKSb2OnBWRaP9C4JWVmxAKB71AgLuAzzo9JV-4=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Xg-BBhKSb2OnBWRaP9C4JWVmxAKB71AgLuAzzo9JV-4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/V9yxb_-jWRKub_r_OycXW1yI82vShiVrr6LGvZYg2PI=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/V9yxb_-jWRKub_r_OycXW1yI82vShiVrr6LGvZYg2PI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/63xhlxiFMezs4dQO2Wo28dlZUouaROKHvZDLwt1eVSc=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/63xhlxiFMezs4dQO2Wo28dlZUouaROKHvZDLwt1eVSc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/oo-e1VxPfy8b3acjW9TlUivCKwFQYTLtR_ZXD2Rt2JU=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/oo-e1VxPfy8b3acjW9TlUivCKwFQYTLtR_ZXD2Rt2JU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/KyMR5Wziz02ixCTmA22bQKsv6wHxPwj9kjtJ_lLVou4=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/KyMR5Wziz02ixCTmA22bQKsv6wHxPwj9kjtJ_lLVou4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/jirNZVS0n4RradSHkZnbeYzGa2hV_bkuj5A7qemLfn8=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/jirNZVS0n4RradSHkZnbeYzGa2hV_bkuj5A7qemLfn8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/mMTuPD16d8c2k64LffvorHqu_-6USXYtJeOhBI7MOOs=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/mMTuPD16d8c2k64LffvorHqu_-6USXYtJeOhBI7MOOs=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/4QA7fZWgrqxa94GQcWGjO3rvLLV-E4WktLOUf4lHHrs=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/4QA7fZWgrqxa94GQcWGjO3rvLLV-E4WktLOUf4lHHrs=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/bY38XvWYcXsoQZ0FlaGOCgqYBcsM8Kjb72fvP8txRBY=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/bY38XvWYcXsoQZ0FlaGOCgqYBcsM8Kjb72fvP8txRBY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/1b7cTbKmHzzFa39lmYqZ5pm-PEkHzxCUXSEXIQ5m-0U=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/1b7cTbKmHzzFa39lmYqZ5pm-PEkHzxCUXSEXIQ5m-0U=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/7qBdfHoJ3SU-MMdqwyhr_IzMeAwQHON2YMpt_zQv5fI=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/7qBdfHoJ3SU-MMdqwyhr_IzMeAwQHON2YMpt_zQv5fI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/L8YfZVfXg6CBxtxY09kJVtVDgBO0dITHTfapA4cuPXw=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/L8YfZVfXg6CBxtxY09kJVtVDgBO0dITHTfapA4cuPXw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/8S0Q5rtA7KAKeU4Ehrg5Xv9EYVh3XYLrjsc_I2yPkxg=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/8S0Q5rtA7KAKeU4Ehrg5Xv9EYVh3XYLrjsc_I2yPkxg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/HKF3fPwAJeRm13miXe-4vI1FaGTPCwlI5utMJctwl8k=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/HKF3fPwAJeRm13miXe-4vI1FaGTPCwlI5utMJctwl8k=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/-4o5ao5EnwLZD9iXKCnEsuiZD1-825UgvePOW0l7Jig=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/-4o5ao5EnwLZD9iXKCnEsuiZD1-825UgvePOW0l7Jig=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/uZzH4jIf69GyNCTmL-lfy3mVpENyN_3F1IKOAXBxQwU=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/uZzH4jIf69GyNCTmL-lfy3mVpENyN_3F1IKOAXBxQwU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/tcGKeAaBBZVoTuDyPdwzKOYsyfhYjDXJQJGBQURKxGw=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/tcGKeAaBBZVoTuDyPdwzKOYsyfhYjDXJQJGBQURKxGw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/mmJ3t2zL0g6vWR1TMD1cCWQT8bHUYLHTQ62AC0A9DPM=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/mmJ3t2zL0g6vWR1TMD1cCWQT8bHUYLHTQ62AC0A9DPM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/8x86bntNswBvF8StUDkyBYJScNTywKW-WxR6azPXUFs=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/8x86bntNswBvF8StUDkyBYJScNTywKW-WxR6azPXUFs=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/CZ1HgPkzCwCBxfRKtpfyV_KRZan4m07k2DINWshHBs8=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/CZ1HgPkzCwCBxfRKtpfyV_KRZan4m07k2DINWshHBs8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/UD0bsq7CgMFsj1L2lGlt_qMLDOVILsZp0MO2uGBvQDw=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/UD0bsq7CgMFsj1L2lGlt_qMLDOVILsZp0MO2uGBvQDw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/k79kxi7KCBnYOCQAy1vwtvAw8-UsxI05yt5LtYK6gi8=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/k79kxi7KCBnYOCQAy1vwtvAw8-UsxI05yt5LtYK6gi8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/UIig0slspRhngV1ffZg2oait9i-ELqUx4qMoBUagOvs=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/UIig0slspRhngV1ffZg2oait9i-ELqUx4qMoBUagOvs=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/wzLxTSmOmorwmke1Edhp54wX_9dvNs5yPeP8oenPaK4=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wzLxTSmOmorwmke1Edhp54wX_9dvNs5yPeP8oenPaK4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/E34UBcOsmTNnqLeVWPOaryM0WWvyZOIzlDl7WR6cc80=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/E34UBcOsmTNnqLeVWPOaryM0WWvyZOIzlDl7WR6cc80=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/haIwPWO7cofJKKFQxp4j9ZcAT3JtguG88lgbYRgGl0s=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/haIwPWO7cofJKKFQxp4j9ZcAT3JtguG88lgbYRgGl0s=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/QFLQEh7X_zSIxjR1hvMBJtfwElFnYMMESeJW83KcD5I=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/QFLQEh7X_zSIxjR1hvMBJtfwElFnYMMESeJW83KcD5I=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/wE_jh56jwL0G3tMkWWfbENSe5bxNIfTAzlgY1brnafY=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wE_jh56jwL0G3tMkWWfbENSe5bxNIfTAzlgY1brnafY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/AKhP51LP6RbILIOwncigFP531tS2Yb9D8jtiZVa6uoo=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/AKhP51LP6RbILIOwncigFP531tS2Yb9D8jtiZVa6uoo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/k0cSSdexw9nzUo-SpJK5J2Fc6MX3OaEDyf9RhcxZqUM=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/k0cSSdexw9nzUo-SpJK5J2Fc6MX3OaEDyf9RhcxZqUM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/HM7dZNDeI2vQqgLnnwJfkuP4fRmUKMAJ7bTbK1qJ4Ho=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/HM7dZNDeI2vQqgLnnwJfkuP4fRmUKMAJ7bTbK1qJ4Ho=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-phish-shavar/7JE0yHlqxwcT2P3015xdKB--Hrdwr7-1wPzo1rfzEPM=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/7JE0yHlqxwcT2P3015xdKB--Hrdwr7-1wPzo1rfzEPM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/lRebbZGau64hCEQVXoOFwZoCHsX1jFGWIfTr05I6p_E=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/lRebbZGau64hCEQVXoOFwZoCHsX1jFGWIfTr05I6p_E=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/fkpIIcjuujT2rH2P7HowLNvnV_wY3RESjlhYbwey-Ek=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/fkpIIcjuujT2rH2P7HowLNvnV_wY3RESjlhYbwey-Ek=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/oB-hUus1Xvl_1EQENOruhBHfNyDrwfBHGVPnkkgwHvc=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/oB-hUus1Xvl_1EQENOruhBHfNyDrwfBHGVPnkkgwHvc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/Ly1fy95I4zNghg2731CfD358KsWzHvU85o0EXH2g6OQ=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Ly1fy95I4zNghg2731CfD358KsWzHvU85o0EXH2g6OQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/6uQWqaT1RCGblQ4ZpLsL58bVvNhg6v7DD891bikH8qM=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/6uQWqaT1RCGblQ4ZpLsL58bVvNhg6v7DD891bikH8qM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/LUeHOOMCOB-pQlzdlFGCbhZE9V9kaVRt04KOCVaJC4Y=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/LUeHOOMCOB-pQlzdlFGCbhZE9V9kaVRt04KOCVaJC4Y=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/nsXHQXzYI3AuGyYkuMQgRG7dxGi0A5Al7OIum9R-hyE=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/nsXHQXzYI3AuGyYkuMQgRG7dxGi0A5Al7OIum9R-hyE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/uvvnQK5OYRoXYoWaTdJwqggbRc-DJ2gBOcXBNFFsliI=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/uvvnQK5OYRoXYoWaTdJwqggbRc-DJ2gBOcXBNFFsliI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/qrBdq_vzXiEdm9iLCIY8GNMEvsBCJGveNQ3YWTzJMIM=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/qrBdq_vzXiEdm9iLCIY8GNMEvsBCJGveNQ3YWTzJMIM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/i5G2FM8_tLEjfy7aO0N4kmHdYf7-_pBv3JkZPz8emiA=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/i5G2FM8_tLEjfy7aO0N4kmHdYf7-_pBv3JkZPz8emiA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/dOYW8CT1uM5jIP3WOTesmR9-XVI73w_SIuLTAYZEGKk=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/dOYW8CT1uM5jIP3WOTesmR9-XVI73w_SIuLTAYZEGKk=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/QDOtk_76wVL3jPoaZs27-7533knjsMtnCdangZmx1Wo=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/QDOtk_76wVL3jPoaZs27-7533knjsMtnCdangZmx1Wo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/RoD_pMkmy2GVGX7YHD_unqfRObz58DE9_WPrAZIRyVA=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/RoD_pMkmy2GVGX7YHD_unqfRObz58DE9_WPrAZIRyVA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/34hObcShEQV4s6ck7ExkGQwcoXdmdgRIKIqoNG8qAkc=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/34hObcShEQV4s6ck7ExkGQwcoXdmdgRIKIqoNG8qAkc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/lDCWU4HFh7141Gk4nPtxKfqUBMi3DgioCNmziSQFSAY=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/lDCWU4HFh7141Gk4nPtxKfqUBMi3DgioCNmziSQFSAY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/AML77lIHrfObviL_zBFRuLttbdLev1tq5-ORUTccdyA=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/AML77lIHrfObviL_zBFRuLttbdLev1tq5-ORUTccdyA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/l0NbfG_xC03kXPH0E5TtymYBrP3rti1X7kASdMQdDBc=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/l0NbfG_xC03kXPH0E5TtymYBrP3rti1X7kASdMQdDBc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/XJS8JhoQCLrHvoi2N1Ve_rg1LE7dFSX2zXDYKWc9FXQ=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/XJS8JhoQCLrHvoi2N1Ve_rg1LE7dFSX2zXDYKWc9FXQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/Y7Bbdz8_yw6v_bqO-aA6L91DCfbRovNLkVFMxneEoig=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Y7Bbdz8_yw6v_bqO-aA6L91DCfbRovNLkVFMxneEoig=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/vkJyaujmHBeBaeLUaJI7i6fATIaUv4Yw7YdKiZ5VZDg=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/vkJyaujmHBeBaeLUaJI7i6fATIaUv4Yw7YdKiZ5VZDg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/vOZ7hV0kxCKHMixiB5_zjy6_Yc9TGBNyvnbfCylFdHo=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/vOZ7hV0kxCKHMixiB5_zjy6_Yc9TGBNyvnbfCylFdHo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/fUN4SJ-LG6yrIjmJB2RL0iC2b3UdNzVs5BMan6CE2JQ=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/fUN4SJ-LG6yrIjmJB2RL0iC2b3UdNzVs5BMan6CE2JQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/deP2PoX_aw5M32dEb99aAA1JFdH-yfSXVmSwGI6sQew=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/deP2PoX_aw5M32dEb99aAA1JFdH-yfSXVmSwGI6sQew=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/0R1tCv_0z65MW3lwpOOkUz0Cpddp4rD5-PMCI8oOhRM=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/0R1tCv_0z65MW3lwpOOkUz0Cpddp4rD5-PMCI8oOhRM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/6QP0kMWCUrsl3TMa6i0RJicPwULRgr-75UnuqkTrowg=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/6QP0kMWCUrsl3TMa6i0RJicPwULRgr-75UnuqkTrowg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/BewhhbJykgB1ha8-WMrSewfQIiANmgIGXucGjsl33Ks=.chunk | |
| hxxp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/BewhhbJykgB1ha8-WMrSewfQIiANmgIGXucGjsl33Ks=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/1qFV-RFKQ9Yksu28tM2AZeyfzp7v91bWYWwMI7_MNic=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/1qFV-RFKQ9Yksu28tM2AZeyfzp7v91bWYWwMI7_MNic=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/OypAprm_9JNXzDZt_V9HoRneNyy7siQEwJ3hHQjmCHY=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/OypAprm_9JNXzDZt_V9HoRneNyy7siQEwJ3hHQjmCHY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/yJ1ZF2okVJs_Cd8LPf5zbMQMveBa1SReufVugI1TKTY=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/yJ1ZF2okVJs_Cd8LPf5zbMQMveBa1SReufVugI1TKTY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/-vBQWF0p7_3PTuvUELHd7TmHz5DAfYsfy0VG-d6aB3Y=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/-vBQWF0p7_3PTuvUELHd7TmHz5DAfYsfy0VG-d6aB3Y=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/NneCNSI4ljllFsoAbEr4y8E1cx5_ihkhoIBbRdfJ6J0=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/NneCNSI4ljllFsoAbEr4y8E1cx5_ihkhoIBbRdfJ6J0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/1gJ-QLXRErQ4NiC1c9bYxQAG6x1mHAWYoJKg9Hiahlo=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/1gJ-QLXRErQ4NiC1c9bYxQAG6x1mHAWYoJKg9Hiahlo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/Lbqo50DoB6E0rsYdfnv8-3rJNk-O52A9UO9OtxxGEw8=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Lbqo50DoB6E0rsYdfnv8-3rJNk-O52A9UO9OtxxGEw8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/D_1Zrj0aSqF6XUXiWJ9r6ZYUEaVZYpvCWaBBaTVDy0o=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/D_1Zrj0aSqF6XUXiWJ9r6ZYUEaVZYpvCWaBBaTVDy0o=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/vxmVNy37oonjrrSDZBzDLPpqngc8zEScGiGMBTyDFcc=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/vxmVNy37oonjrrSDZBzDLPpqngc8zEScGiGMBTyDFcc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/Zc1p-chDcLtgTXbOPHgnX7g_F5Vddk2CGPFY7CZXFkA=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Zc1p-chDcLtgTXbOPHgnX7g_F5Vddk2CGPFY7CZXFkA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/Y-vgliRy7vwOHI7QAOD7H4oqSf-TJiaCBLsl-TOu6W4=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Y-vgliRy7vwOHI7QAOD7H4oqSf-TJiaCBLsl-TOu6W4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/IBkAcJkDe-UMa5JcZSHqewm1J1FPxuue9BBrv2HkV2M=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/IBkAcJkDe-UMa5JcZSHqewm1J1FPxuue9BBrv2HkV2M=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/KlYWl0YjuqklZ6Kr-iE6JwkoD1lGRDSYV3y1xtUJ6vE=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/KlYWl0YjuqklZ6Kr-iE6JwkoD1lGRDSYV3y1xtUJ6vE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/QrQXYdikSjRrXy_HcAZXyWr6KLoxu5WFidPMEx_OalQ=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/QrQXYdikSjRrXy_HcAZXyWr6KLoxu5WFidPMEx_OalQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/qMClo-a6ikkoEk0PRMBOLlihKTwko6nmtbIePa4G6cE=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/qMClo-a6ikkoEk0PRMBOLlihKTwko6nmtbIePa4G6cE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/Ze8uEZAqHBtd2fK7UD2v7hiXbNOJV9Huo6Wkh5s7vRw=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Ze8uEZAqHBtd2fK7UD2v7hiXbNOJV9Huo6Wkh5s7vRw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/oweDFIsK4aD4_rARvw_DFsYTnCHgAwkIyO-Cr1Sggq8=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/oweDFIsK4aD4_rARvw_DFsYTnCHgAwkIyO-Cr1Sggq8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/e05WcOZMZtbisUzbwMUQfS06o1PHFsMK1SygyXrIjls=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/e05WcOZMZtbisUzbwMUQfS06o1PHFsMK1SygyXrIjls=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/0_r7h7C_8wmcDtCoyZDTlAyHpqloSAKBngEZmJkLijc=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/0_r7h7C_8wmcDtCoyZDTlAyHpqloSAKBngEZmJkLijc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/F1IyfhgOm8mRwbTEWMWMuzVHUuC8Hgp5YQrngFJrcHk=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/F1IyfhgOm8mRwbTEWMWMuzVHUuC8Hgp5YQrngFJrcHk=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/I4cHXUB5lw3x_oo_3SLBgGOqm-L0Ppel0n5wNSMEYdk=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/I4cHXUB5lw3x_oo_3SLBgGOqm-L0Ppel0n5wNSMEYdk=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/bPzVXNtCxclsBHuqQnq_VFLS814vJ9YrJr0_ECYF23A=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/bPzVXNtCxclsBHuqQnq_VFLS814vJ9YrJr0_ECYF23A=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/upbUSLkFFgKYbxZEi1SDt8e2LlKATdvoZ-bwaW7Zj_Y=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/upbUSLkFFgKYbxZEi1SDt8e2LlKATdvoZ-bwaW7Zj_Y=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/xxhx3h0IzWuRG-tiUmGAPmqcSkzL7CgGn2_WLc4XndI=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/xxhx3h0IzWuRG-tiUmGAPmqcSkzL7CgGn2_WLc4XndI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/GgQ4WSYwIL2jgsYgnfOjR0qqfePaXmb-DX3XOtsW9Zc=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/GgQ4WSYwIL2jgsYgnfOjR0qqfePaXmb-DX3XOtsW9Zc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/Ns_Bo4UvBU6hqyUFEDzll7JPYJ-SQwlpuXzX7KRxY_Y=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Ns_Bo4UvBU6hqyUFEDzll7JPYJ-SQwlpuXzX7KRxY_Y=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/r26WN31Wqw5U0loQzRbt_kZT_vWxHj8ekoP9Sdr3ZIU=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/r26WN31Wqw5U0loQzRbt_kZT_vWxHj8ekoP9Sdr3ZIU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/QE5wpfxYC4_ZkRiYpgWBMaPIipoEvJ2MAg3pKTv6kqE=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/QE5wpfxYC4_ZkRiYpgWBMaPIipoEvJ2MAg3pKTv6kqE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/m9zSmPnZl43F61hsLKfueuH6VwYE7gGXeYYSB-pypy4=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/m9zSmPnZl43F61hsLKfueuH6VwYE7gGXeYYSB-pypy4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/uq-M1FCqWXfGGjcE0dku9n1tg5Z59jjylidsIBdF6NA=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/uq-M1FCqWXfGGjcE0dku9n1tg5Z59jjylidsIBdF6NA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/DFBYtvq866rJuHxVyLHxF65hHot39cLoMpvzYSy1k7o=.chunk | |
| hxxp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/DFBYtvq866rJuHxVyLHxF65hHot39cLoMpvzYSy1k7o=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/O9JgGROBQ5x0P5QtZJaM8u0jmTgbS8oXBKn-Ktuo18k=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/O9JgGROBQ5x0P5QtZJaM8u0jmTgbS8oXBKn-Ktuo18k=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/FDTTAe43Pc4fgrkoGNLqTPAl11sblwDJtByrMIJs2GY=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/FDTTAe43Pc4fgrkoGNLqTPAl11sblwDJtByrMIJs2GY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/5WSYaQ7LOD-v3GjZ6dJngOy3mUXWCdUykyYS_adogHo=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/5WSYaQ7LOD-v3GjZ6dJngOy3mUXWCdUykyYS_adogHo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/n1yFjPQFEChBHb2nPFdlSnxInZe06KGVB02Q5AxqI18=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/n1yFjPQFEChBHb2nPFdlSnxInZe06KGVB02Q5AxqI18=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/B9oFeiEQxNCzVOPSXAabZqrJjttO7a0CzH6NcQHUIYI=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/B9oFeiEQxNCzVOPSXAabZqrJjttO7a0CzH6NcQHUIYI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/7giqbAFh2S33m9VF3lXAepQAHn28qzEmckcfXXCSNJE=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/7giqbAFh2S33m9VF3lXAepQAHn28qzEmckcfXXCSNJE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/rJ5UiZfVNVY8I6QwHOGKfYO7eACujpZZ8S63AXGO_sU=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/rJ5UiZfVNVY8I6QwHOGKfYO7eACujpZZ8S63AXGO_sU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/iCqahQe97Rfv1mK1qV4HwQWuWFOF-fi0Z1SEHfHqiDo=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/iCqahQe97Rfv1mK1qV4HwQWuWFOF-fi0Z1SEHfHqiDo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/_LeYmVcLjaymWdywoaBs2fZ3zvbAC0b1zHa4o6BHJE8=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/_LeYmVcLjaymWdywoaBs2fZ3zvbAC0b1zHa4o6BHJE8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/2Co669pBX8sWhrvtK2V8n-iyxDvdICtpqxZfO4qFwdA=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/2Co669pBX8sWhrvtK2V8n-iyxDvdICtpqxZfO4qFwdA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/SBcYP83hLjrvJOk2McHsxGs6FsHWjiidYEUsQI1V2Fw=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/SBcYP83hLjrvJOk2McHsxGs6FsHWjiidYEUsQI1V2Fw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/skFus4cWDXN8GL8gnFtUdRf6nKmCCrZ4CR_AhQ0aau8=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/skFus4cWDXN8GL8gnFtUdRf6nKmCCrZ4CR_AhQ0aau8=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/77vHetNOt1hRHVuAH52FbCdQTJwqEgpbxZiNw8Hf92g=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/77vHetNOt1hRHVuAH52FbCdQTJwqEgpbxZiNw8Hf92g=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/QfkQ0yWr_4I0G1WQBVqa2lZJgzDfK_gsq3C_w3N4JYw=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/QfkQ0yWr_4I0G1WQBVqa2lZJgzDfK_gsq3C_w3N4JYw=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/EvqzcZp4bVd4cfZLC8AKSI9VMn_dz4QLBIdq4T2EPUs=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/EvqzcZp4bVd4cfZLC8AKSI9VMn_dz4QLBIdq4T2EPUs=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/mrShvsGmYWxwJ8bB2c4E3CxapAoOdyeN940T9aUr_4s=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/mrShvsGmYWxwJ8bB2c4E3CxapAoOdyeN940T9aUr_4s=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/7k0BpIfoAfdNOp4XXRDJ3lpFbLKfBQF4dcG9tVcjVgE=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/7k0BpIfoAfdNOp4XXRDJ3lpFbLKfBQF4dcG9tVcjVgE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/HcTDZdOAqbjP60mqsUDke9Xw0HITGpAZnncOOQKDDKQ=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/HcTDZdOAqbjP60mqsUDke9Xw0HITGpAZnncOOQKDDKQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/T_aMBLuw7gCWF9l5r-w4H8u5L6uL0GLJfqLot_fdaek=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/T_aMBLuw7gCWF9l5r-w4H8u5L6uL0GLJfqLot_fdaek=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/8pHhQz9xknZc2CVxwA-g54bDE_T_5LY6xJIORyAqCv4=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/8pHhQz9xknZc2CVxwA-g54bDE_T_5LY6xJIORyAqCv4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/mQG2X2AwB1UBKbcXP7oraGgK9_Js1nl7N2vjMKo_7Uo=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/mQG2X2AwB1UBKbcXP7oraGgK9_Js1nl7N2vjMKo_7Uo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/nhJUhSVWvHs0hfzlykFUz6TAZgIYTI2u0kvRVsqf6qQ=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/nhJUhSVWvHs0hfzlykFUz6TAZgIYTI2u0kvRVsqf6qQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/DaxhlnrV0XFnHcnQXoIcYI3Ok7env3ziAM9YJA0w0-Y=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/DaxhlnrV0XFnHcnQXoIcYI3Ok7env3ziAM9YJA0w0-Y=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/vDwva6A67JGbzpy7VPkWvdbtMgYd7qMQ8rFwR2vbEUA=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/vDwva6A67JGbzpy7VPkWvdbtMgYd7qMQ8rFwR2vbEUA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/jNaFSriOZfpnZyKuKOMt15IDydkN0sT32zGXqNfHpk0=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/jNaFSriOZfpnZyKuKOMt15IDydkN0sT32zGXqNfHpk0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/u_hXwLRpsoJeSOsazeFzQYvUWnjbcqzfxK5xvSHfm3c=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/u_hXwLRpsoJeSOsazeFzQYvUWnjbcqzfxK5xvSHfm3c=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/AFGjLCcPvpsG1HUPtkI98qT8qJteSviPkekn-QzuSyE=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/AFGjLCcPvpsG1HUPtkI98qT8qJteSviPkekn-QzuSyE=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/cnGzzgLWGwIcOtVgK2IvD7uAdng1hM9iLWbSHDXzFZ0=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/cnGzzgLWGwIcOtVgK2IvD7uAdng1hM9iLWbSHDXzFZ0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/cjyIJrK5F9M1n9xrACpzp-cw6OzC-MNqeGjrqaNgpCY=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/cjyIJrK5F9M1n9xrACpzp-cw6OzC-MNqeGjrqaNgpCY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/LUPMCPyJrbw1OieLTkZuI4-fa9veuo2URB_xdN46leQ=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/LUPMCPyJrbw1OieLTkZuI4-fa9veuo2URB_xdN46leQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/hK7NEVX0GuFHKMVPJRS41fUCr-UYuBOz0-nU7cXArDc=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/hK7NEVX0GuFHKMVPJRS41fUCr-UYuBOz0-nU7cXArDc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/M_uIHnItKjxLGZ6Y6sA3mLX9k8jkxrLA4WFXXMB8GPM=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/M_uIHnItKjxLGZ6Y6sA3mLX9k8jkxrLA4WFXXMB8GPM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/FFVlibTAzjsLur4NAXQOZA6peE6IVXVI3LCXkKUctgU=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/FFVlibTAzjsLur4NAXQOZA6peE6IVXVI3LCXkKUctgU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/MuNLeGrVYTt6Y1cOK2042BI3JSNbelnx-pT6Oqdi4yg=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/MuNLeGrVYTt6Y1cOK2042BI3JSNbelnx-pT6Oqdi4yg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/hlE57wFE9-b39VNjineSxYXaPA_KVKlB2kHnmNHWNAY=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/hlE57wFE9-b39VNjineSxYXaPA_KVKlB2kHnmNHWNAY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/LpJqp1zoQaivOKHY_YxfSfoQzXr8OBdeGyXfwZFuU88=.chunk | |
| hxxp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/LpJqp1zoQaivOKHY_YxfSfoQzXr8OBdeGyXfwZFuU88=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/U8XthtUjP3fHyhoWlkwxuCvAK1rcLrnp4IlOMe4QvKA=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/U8XthtUjP3fHyhoWlkwxuCvAK1rcLrnp4IlOMe4QvKA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/F0fpy84reqUnQmBQSuHR2vNOoa14FpI-dzipR4EF1LQ=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/F0fpy84reqUnQmBQSuHR2vNOoa14FpI-dzipR4EF1LQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/J52fEe2QVgYIVr0w6hxf-y0ETI71vjR26TUJdnGrq8Q=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/J52fEe2QVgYIVr0w6hxf-y0ETI71vjR26TUJdnGrq8Q=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/zPBY_ZsUBv6JGy4o-VialmS3BxJzABATPHbco1wNs3g=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/zPBY_ZsUBv6JGy4o-VialmS3BxJzABATPHbco1wNs3g=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/UDsJW951ls6hXgbEvhwDLWhn1cuoWuX5hKld43jlNko=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/UDsJW951ls6hXgbEvhwDLWhn1cuoWuX5hKld43jlNko=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/pqIY_e0O3hSWRoJAeaHMgDfMFzzIEueabEuZVNkuFCQ=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/pqIY_e0O3hSWRoJAeaHMgDfMFzzIEueabEuZVNkuFCQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/lrktrb3ULzYGcvSXgGL-wk_R08q3_A7yVtdfyRyz1IA=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/lrktrb3ULzYGcvSXgGL-wk_R08q3_A7yVtdfyRyz1IA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/684__O4vQZnuf-5-LkTjdfmz6aY3sfpIgE5Jb8qUdsU=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/684__O4vQZnuf-5-LkTjdfmz6aY3sfpIgE5Jb8qUdsU=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/tdaKepnAEP8GIBFsntEZotPvlWuEMLmm1oKs6ppIzjI=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/tdaKepnAEP8GIBFsntEZotPvlWuEMLmm1oKs6ppIzjI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/ULvy5kahSMHS-3gFwUXe6fqhBgBfxAEImQvAcX_9780=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/ULvy5kahSMHS-3gFwUXe6fqhBgBfxAEImQvAcX_9780=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/t7wD0vKOutL6XFFHiHuakC8aXB6YVLa1sj730VndEqM=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/t7wD0vKOutL6XFFHiHuakC8aXB6YVLa1sj730VndEqM=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/IJvxhg70GV20xTBQnxkJq9p6uz0Gge8MXTeEu5AhP78=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/IJvxhg70GV20xTBQnxkJq9p6uz0Gge8MXTeEu5AhP78=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/9eJHkKBM28o-0xZBdcbLTRTKn5i6bdxKBD16b5XNtEg=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/9eJHkKBM28o-0xZBdcbLTRTKn5i6bdxKBD16b5XNtEg=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/-zFjpKxKhsxytgDQNzMvJgyR8pvmFqwL1vXPvZg1oFo=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/-zFjpKxKhsxytgDQNzMvJgyR8pvmFqwL1vXPvZg1oFo=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/8NY5MEB8lUJJQjr0HAtADQtTEJjYvFsFmh9jeMOO_dI=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/8NY5MEB8lUJJQjr0HAtADQtTEJjYvFsFmh9jeMOO_dI=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/pNLUb43N-OFdIP7mjo2tzPuDNjNF2ERBwUeIMlDCOF4=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/pNLUb43N-OFdIP7mjo2tzPuDNjNF2ERBwUeIMlDCOF4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/-UtvLBU64lZsXS6mufZK4XOCHgYcH3F3q8TmeiT9jS4=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/-UtvLBU64lZsXS6mufZK4XOCHgYcH3F3q8TmeiT9jS4=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/fpYzgXlcgfr6ZD20Y8IItWMOIOC8C-p4aRguqTU9Ojc=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/fpYzgXlcgfr6ZD20Y8IItWMOIOC8C-p4aRguqTU9Ojc=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/DhmkbGq3IqOmH688Cmt9YunECJJ_kvFlB6mcbV-E4sQ=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/DhmkbGq3IqOmH688Cmt9YunECJJ_kvFlB6mcbV-E4sQ=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/POqsACfqD9umXojHJh63f3wzdU0jArUnh2RZWVlPo6U=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/POqsACfqD9umXojHJh63f3wzdU0jArUnh2RZWVlPo6U=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/a39oZB5GvsB3u7BxwIU71DqzAeakBAgZXyrOwzmZnik=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/a39oZB5GvsB3u7BxwIU71DqzAeakBAgZXyrOwzmZnik=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/Fejg5XK1yuNw_YRGnEjzcXe9IfHSn_fxKCR37v7LbfA=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Fejg5XK1yuNw_YRGnEjzcXe9IfHSn_fxKCR37v7LbfA=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/KLnyMTj-WDDYVL1nZ8HROsuR0XViDZpknDqSt3f8tZ0=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/KLnyMTj-WDDYVL1nZ8HROsuR0XViDZpknDqSt3f8tZ0=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/XXIH_VyGQMK6X1r6-qVTBZRUmfW6hzxd-YkgYKOoYjY=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/XXIH_VyGQMK6X1r6-qVTBZRUmfW6hzxd-YkgYKOoYjY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/lDMYCTCxctZtPK8ktsRW5E2Vn2pRjEfv7ILwgql5UKY=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/lDMYCTCxctZtPK8ktsRW5E2Vn2pRjEfv7ILwgql5UKY=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/5uO6Pab7G-Fdp1GqUSSzm2fYjQ24MkfLFcHw2lPcG48=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/5uO6Pab7G-Fdp1GqUSSzm2fYjQ24MkfLFcHw2lPcG48=.chunk | |
| hxxp://cdn.yandex.net/chunks/goog-malware-shavar/yblLd2E6Kl_fu3GsgarktrXxWijZbNqYOqggb8uZQ48=.chunk | |
| hxxp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/yblLd2E6Kl_fu3GsgarktrXxWijZbNqYOqggb8uZQ48=.chunk | |
| hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?73c63149da3361dd | |
| hxxp://a1363.dscg.akamai.net/pki/crl/products/WinPCA.crl | |
| hxxp://a1363.dscg.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl | |
| hxxp://clients.l.google.com/edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe | |
| hxxp://r2.sn-ugpva5o-3c2e.gvt1.com/edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?cms_redirect=yes&expire=1430468552&ip=37.57.16.189&ipbits=0&mm=28&mn=sn-ugpva5o-3c2e&ms=nvh&mt=1430454086&mv=u&pcm2cms=yes&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=26347A8AAAADD774630CF4C618EF0C0A5FC11F65.0E69BCDACB63B8EE5BFA7AE881E0B9EDF4DCB9C8&key=cms1 | |
| hxxp://r7.sn-3c27ln7e.gvt1.com/edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m | |
| hxxp://a1363.dscg.akamai.net/pki/crl/products/microsoftrootcert.crl | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEALa8SdwQh28+NjkQGqVhx8= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEGO+CyDUoFQBjrKVo87pCRc= | |
| hxxp://a1363.dscg.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEEhJyjx2Kj7S0x8cjJXTloQ= | |
| hxxp://e6845.ce.akamaiedge.net/ThawtePremiumServerCA.crl | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECECVRccvD8Qb29B4D63fPT+k= | |
| hxxp://update.playfree.org/service/update2?w=3:QEwJUu918gabi9_4v4ZCXohe4k_aFphJi5j2A6BwEZB-pjC258i8eQAf1dWV6qAR-a85v0lB6SfQVyclr06jCyjX1DxAumRSVTctealCogPFXZdsYghpnziAtOr2zw2HoPEwCdcMXfAz5Rw9Nrp_t3Ya9q4bmsU7lNiVgX66-5c | |
| hxxp://update.playfree.org/service/check2?appid={00337EA4-7B9A-44A6-B45B-B1722CD4343E}&appversion=1.3.27.0&applang=&machine=0&version=0.0.0.0&osversion=6.1&servicepack=Service Pack 1 | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U= | |
| hxxp://r7---sn-3c27ln7e.gvt1.com/edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/QFLQEh7X_zSIxjR1hvMBJtfwElFnYMMESeJW83KcD5I=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/D_1Zrj0aSqF6XUXiWJ9r6ZYUEaVZYpvCWaBBaTVDy0o=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/1K9aDMnPxpkE2R2aBK4b2E3IagxTFurTWM6YCJFB54g=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/p8jCP90AhLl5ufYMynxaluNFR688R-dqD2Twp15_Jiw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/RoD_pMkmy2GVGX7YHD_unqfRObz58DE9_WPrAZIRyVA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/8S0Q5rtA7KAKeU4Ehrg5Xv9EYVh3XYLrjsc_I2yPkxg=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/Fejg5XK1yuNw_YRGnEjzcXe9IfHSn_fxKCR37v7LbfA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/T_aMBLuw7gCWF9l5r-w4H8u5L6uL0GLJfqLot_fdaek=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/n1yFjPQFEChBHb2nPFdlSnxInZe06KGVB02Q5AxqI18=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/OypAprm_9JNXzDZt_V9HoRneNyy7siQEwJ3hHQjmCHY=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Jftr8wgkwo56H9yX6nJePhy2DKlA48l3kn4aJ2EZ6DY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/77vHetNOt1hRHVuAH52FbCdQTJwqEgpbxZiNw8Hf92g=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/dOYW8CT1uM5jIP3WOTesmR9-XVI73w_SIuLTAYZEGKk=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/63xhlxiFMezs4dQO2Wo28dlZUouaROKHvZDLwt1eVSc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/tFrZWBGYzrmSIkQD08neZlV3aJoQfKyKFZgZSg7ts88=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/k0cSSdexw9nzUo-SpJK5J2Fc6MX3OaEDyf9RhcxZqUM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/5S79mJ6464OwK7yKBT2PYdKWEZ4aQHolIEUHr4Tzyf4=.chunk | |
| hxxp://customisations.playfree.org/icons/product_logo_128.png | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/LUeHOOMCOB-pQlzdlFGCbhZE9V9kaVRt04KOCVaJC4Y=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/FDTTAe43Pc4fgrkoGNLqTPAl11sblwDJtByrMIJs2GY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/hlE57wFE9-b39VNjineSxYXaPA_KVKlB2kHnmNHWNAY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/a39oZB5GvsB3u7BxwIU71DqzAeakBAgZXyrOwzmZnik=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/F1IyfhgOm8mRwbTEWMWMuzVHUuC8Hgp5YQrngFJrcHk=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/mW94EcunmakWRnLV-MS5hq-LjJaiSXJCzVFzlQt6-NY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/mQG2X2AwB1UBKbcXP7oraGgK9_Js1nl7N2vjMKo_7Uo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/9eJHkKBM28o-0xZBdcbLTRTKn5i6bdxKBD16b5XNtEg=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/qrBdq_vzXiEdm9iLCIY8GNMEvsBCJGveNQ3YWTzJMIM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/S0qM3gmmlTfjfU09iNPuDLKQ-EcgLa4CykvNbVwOWz0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/CiVhTt28sFS93rXevnsokT4ntD6_q3CDbxSad31QNu0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/-anZCDFwCsiDfCOfxIKUAJrW0FZfXw4lV2mDR_XwEwU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/qnZ2HvzM37H8A8rLm-gJ0ujA5quc_OP3jtgBUBXCJmk=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/0D3N_cx0Jm-0zlRfzxtI1c1JCExEEO-3DUtScKCpOHs=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/LUPMCPyJrbw1OieLTkZuI4-fa9veuo2URB_xdN46leQ=.chunk | |
| hxxp://crl.microsoft.com/pki/crl/products/WinPCA.crl | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/O9g5OJm4JRG7U6M0FrlMP6KS2sLifUb-a-mH5mfdXIc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/6uQWqaT1RCGblQ4ZpLsL58bVvNhg6v7DD891bikH8qM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/KlYWl0YjuqklZ6Kr-iE6JwkoD1lGRDSYV3y1xtUJ6vE=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/h_xpPnaTd4FhVPIkCA2nensqXe_s9gRnukwHWL_1IIM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/xEztrZ_otV4HLVyDpTFlDQBGcxzWLzBBBm4NsdzFEwc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/S68JNpsZmJZq6F4upq2Bd2Dw4N2MAoSZ_bdHW_x4e2g=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/vDwva6A67JGbzpy7VPkWvdbtMgYd7qMQ8rFwR2vbEUA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/vxmVNy37oonjrrSDZBzDLPpqngc8zEScGiGMBTyDFcc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/cnGzzgLWGwIcOtVgK2IvD7uAdng1hM9iLWbSHDXzFZ0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/lDMYCTCxctZtPK8ktsRW5E2Vn2pRjEfv7ILwgql5UKY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/QWJEMg5X_Yrd4iTgGTm7iFacTsiaurN1LIdYeVk8r3Y=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/iux_0kYqwLpBad2nO9MehhPZp_IurAi8AdwiLiyyVyY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/uvvnQK5OYRoXYoWaTdJwqggbRc-DJ2gBOcXBNFFsliI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/CZ1HgPkzCwCBxfRKtpfyV_KRZan4m07k2DINWshHBs8=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/2Co669pBX8sWhrvtK2V8n-iyxDvdICtpqxZfO4qFwdA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/S7ivwxHcennvSEQHDpfGAO5hLoKWJSnvokyqYRJyLx4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/7qBdfHoJ3SU-MMdqwyhr_IzMeAwQHON2YMpt_zQv5fI=.chunk | |
| hxxp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/qZC_0gz5QY5TFOHvTQ0KoWe5B3G87JxkyA8cg5HkIiM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/Ly1fy95I4zNghg2731CfD358KsWzHvU85o0EXH2g6OQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/tcGKeAaBBZVoTuDyPdwzKOYsyfhYjDXJQJGBQURKxGw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/IBkAcJkDe-UMa5JcZSHqewm1J1FPxuue9BBrv2HkV2M=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Btt71EDwI8tUxpLjIa52nMtiSPr0jPATp90kyoijHJ0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/8NY5MEB8lUJJQjr0HAtADQtTEJjYvFsFmh9jeMOO_dI=.chunk | |
| hxxp://crl.thawte.com/ThawtePremiumServerCA.crl | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/lF47Sh_HLEdUNiXpguEQ9zZeeyjhHFGZNZVIF3fgnXw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/jEtUT_cL0M27Wn976ODIjlalYuMX3QGH-mjk2rUKFQA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/yJ1ZF2okVJs_Cd8LPf5zbMQMveBa1SReufVugI1TKTY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/VR8x-VIlD9su8cKntNAkoMX85wo3_9pJu8jiDHcZtHE=.chunk | |
| hxxp://omaha.playfree.org/service/check2?appid={00337EA4-7B9A-44A6-B45B-B1722CD4343E}&appversion=1.3.27.0&applang=&machine=0&version=0.0.0.0&osversion=6.1&servicepack=Service Pack 1 | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/rJ5UiZfVNVY8I6QwHOGKfYO7eACujpZZ8S63AXGO_sU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/7k0BpIfoAfdNOp4XXRDJ3lpFbLKfBQF4dcG9tVcjVgE=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Jj0fDeTYdxpkeaiXNqK7Ypwod0ePmqChmJPwBCFVIQk=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/mrShvsGmYWxwJ8bB2c4E3CxapAoOdyeN940T9aUr_4s=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/YG__nsDShaQvw9cK8iRvgEwVjCEJcjecHox6seWUdLQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/pNLUb43N-OFdIP7mjo2tzPuDNjNF2ERBwUeIMlDCOF4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/tsOoy7JAp7Lz5F39t4GNxgnXgvcVKsoLv9IDzQgKTp4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/yblLd2E6Kl_fu3GsgarktrXxWijZbNqYOqggb8uZQ48=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/SBcYP83hLjrvJOk2McHsxGs6FsHWjiidYEUsQI1V2Fw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Tj7ZLCSSjPdV1SzabZFpEPSGnNkXuSnbXXrEG9YWUsc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/0_r7h7C_8wmcDtCoyZDTlAyHpqloSAKBngEZmJkLijc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/fUN4SJ-LG6yrIjmJB2RL0iC2b3UdNzVs5BMan6CE2JQ=.chunk | |
| hxxp://omaha.playfree.org/service/update2 | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/Y-vgliRy7vwOHI7QAOD7H4oqSf-TJiaCBLsl-TOu6W4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/ZuAPRjyGYJlkTcv1FEc5TDP_4G-_uF22_OMHVkTckZw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/qDC0G_w_wSrAQ-0l04BWQgPpcKgZMDT6ciA2msBNIzY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/r26WN31Wqw5U0loQzRbt_kZT_vWxHj8ekoP9Sdr3ZIU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/qMClo-a6ikkoEk0PRMBOLlihKTwko6nmtbIePa4G6cE=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/KLnyMTj-WDDYVL1nZ8HROsuR0XViDZpknDqSt3f8tZ0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/MuNLeGrVYTt6Y1cOK2042BI3JSNbelnx-pT6Oqdi4yg=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/k79kxi7KCBnYOCQAy1vwtvAw8-UsxI05yt5LtYK6gi8=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/vkJyaujmHBeBaeLUaJI7i6fATIaUv4Yw7YdKiZ5VZDg=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/fpYzgXlcgfr6ZD20Y8IItWMOIOC8C-p4aRguqTU9Ojc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/upbUSLkFFgKYbxZEi1SDt8e2LlKATdvoZ-bwaW7Zj_Y=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/XXIH_VyGQMK6X1r6-qVTBZRUmfW6hzxd-YkgYKOoYjY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/ihvaXT0zxWqt0I1IIj7mFRJdHKF0OMXfAKRwiTwrFnk=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/ua4zZ337Cq0_RFw8igoS2bdlDOvEwayBRDquwRRN0LQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/nsXHQXzYI3AuGyYkuMQgRG7dxGi0A5Al7OIum9R-hyE=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/1qFV-RFKQ9Yksu28tM2AZeyfzp7v91bWYWwMI7_MNic=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/5uO6Pab7G-Fdp1GqUSSzm2fYjQ24MkfLFcHw2lPcG48=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/EvqzcZp4bVd4cfZLC8AKSI9VMn_dz4QLBIdq4T2EPUs=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/vOZ7hV0kxCKHMixiB5_zjy6_Yc9TGBNyvnbfCylFdHo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/5WSYaQ7LOD-v3GjZ6dJngOy3mUXWCdUykyYS_adogHo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Xg-BBhKSb2OnBWRaP9C4JWVmxAKB71AgLuAzzo9JV-4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/JfMelIF4lIIljMS8fg5WquzqYqSh-C6DIxDq6ByNvqo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/0CUhV4Pw6226fhXk7ayz0zEcPuXwbi30h1RwoGHxmII=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/6REFNUxyRF2vLNuQD5eV-JDP4re7A_YwPBkbPa1JkfE=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/KyMR5Wziz02ixCTmA22bQKsv6wHxPwj9kjtJ_lLVou4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/3Tj0bVUpKpSFrZPgfwQzX2xTELkpN6SDPWBdFeZ82hg=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/iCqahQe97Rfv1mK1qV4HwQWuWFOF-fi0Z1SEHfHqiDo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/8TrlR6tjVYIn5nOzkeYe9TWzQniXkQUFt-m-_y4jm7A=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/olMNSrIv3_9-5Zz2qU3JZv0ECEq0RlY7SE12jovxqOc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/QrQXYdikSjRrXy_HcAZXyWr6KLoxu5WFidPMEx_OalQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/0eYbR7AY1kV5MF7bqScyKku40te-z1-r0eu-Er90fgM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/oB-hUus1Xvl_1EQENOruhBHfNyDrwfBHGVPnkkgwHvc=.chunk | |
| hxxp://publishers.playfree.org/en/gameinfo/?game=farm_frenzy&browser=gs_en | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/HM7dZNDeI2vQqgLnnwJfkuP4fRmUKMAJ7bTbK1qJ4Ho=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/ttESbMYCl0F1zsR55cKlwxZJYMsyLjORkbBoc7Zm5gY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/YGfxA6S0Iv-jWOp8V1Su16gcyiJwlNoX7fjo0kbnqn8=.chunk | |
| hxxp://www.google-analytics.com/ga.js | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/GsrVhUq6AbrMVrXw4Ec6ftazfcF7150-LStN0PdRwKA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/L8YfZVfXg6CBxtxY09kJVtVDgBO0dITHTfapA4cuPXw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/jirNZVS0n4RradSHkZnbeYzGa2hV_bkuj5A7qemLfn8=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/U8XthtUjP3fHyhoWlkwxuCvAK1rcLrnp4IlOMe4QvKA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/ueUlg7RwaptET2592qwxtihIaGM0Zy7pKwY5E8kERZE=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/InCnLK-Y8LZ6JG7r-6OZj7o4DrW6iCbFTv3xbble6yQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/m8zTXWVYnt2StqmNe4n0gx7bH32b0Uex1h36Ocbxmp0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/fhv1pKXYMHqded8rPqy-jx4dzaITAE7VPyaCqcXmEPI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/UDsJW951ls6hXgbEvhwDLWhn1cuoWuX5hKld43jlNko=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/deP2PoX_aw5M32dEb99aAA1JFdH-yfSXVmSwGI6sQew=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Sl6kTbztAG7gh4K9-UWT83pEpeufQD16QOSbGOMH940=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/bP9cwuh_axs0J-Nbuo42kmwnhgt4rWNfe0gHrOFh0Mk=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/gGlRwSx8Dzo1uJ0yLqn9uPHpLoXJEVWw4QTefK6Bsn0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/lrktrb3ULzYGcvSXgGL-wk_R08q3_A7yVtdfyRyz1IA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/ALWeV724V9w89dwuc3ClyOUZxXY9wArCzxfS4TYmikU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/m9zSmPnZl43F61hsLKfueuH6VwYE7gGXeYYSB-pypy4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/DaxhlnrV0XFnHcnQXoIcYI3Ok7env3ziAM9YJA0w0-Y=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/HKF3fPwAJeRm13miXe-4vI1FaGTPCwlI5utMJctwl8k=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEALa8SdwQh28+NjkQGqVhx8= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/B9oFeiEQxNCzVOPSXAabZqrJjttO7a0CzH6NcQHUIYI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/BN_fefG7YqPXI2wavBHdY_Gcg-YkjI4hH8Z1sED-s8s=.chunk | |
| hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?73c63149da3361dd | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/wE_jh56jwL0G3tMkWWfbENSe5bxNIfTAzlgY1brnafY=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/TehQ2ixiUtxEpr0ycrxRN_kCJgW6Bhwks3x4Q93OUW8=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/POqsACfqD9umXojHJh63f3wzdU0jArUnh2RZWVlPo6U=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/mmJ3t2zL0g6vWR1TMD1cCWQT8bHUYLHTQ62AC0A9DPM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/J52fEe2QVgYIVr0w6hxf-y0ETI71vjR26TUJdnGrq8Q=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/haIwPWO7cofJKKFQxp4j9ZcAT3JtguG88lgbYRgGl0s=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/uZzH4jIf69GyNCTmL-lfy3mVpENyN_3F1IKOAXBxQwU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/8x86bntNswBvF8StUDkyBYJScNTywKW-WxR6azPXUFs=.chunk | |
| hxxp://www.google-analytics.com/r/__utm.gif?utmwv=5.6.4&utms=1&utmn=719186822&utmhn=home.playfree.org&utmcs=UTF-8&utmsr=1716x901&utmvp=833x755&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=11.8 r800&utmdt=PlayFree Search&utmhid=2008743007&utmr=-&utmp=/en/?utm_source=gs_en&utm_medium=hp&utmht=1430453906475&utmac=UA-1217017-45&utmcc=__utma=120822935.470092875.1430453906.1430453906.1430453906.1;+__utmz=120822935.1430453906.1.1.utmcsr=gs_en|utmccn=(not%20set)|utmcmd=hp;&utmjid=470535854&utmredir=1&utmu=qBAAAAAAAAAAAAAAAAAAAAAE~ | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/l0NbfG_xC03kXPH0E5TtymYBrP3rti1X7kASdMQdDBc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/oweDFIsK4aD4_rARvw_DFsYTnCHgAwkIyO-Cr1Sggq8=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/bPzVXNtCxclsBHuqQnq_VFLS814vJ9YrJr0_ECYF23A=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/e05WcOZMZtbisUzbwMUQfS06o1PHFsMK1SygyXrIjls=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/V9yxb_-jWRKub_r_OycXW1yI82vShiVrr6LGvZYg2PI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/UIig0slspRhngV1ffZg2oait9i-ELqUx4qMoBUagOvs=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/47t5dK4QAJ1BiKhFGh-dfr0-SMJdePVognk64vffMd4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/tdaKepnAEP8GIBFsntEZotPvlWuEMLmm1oKs6ppIzjI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/UD0bsq7CgMFsj1L2lGlt_qMLDOVILsZp0MO2uGBvQDw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Ccn3RlRn-KWmMNIgKEOIrNd9c9KzqusM19c-qz1fg1A=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/WNYAEB6kHQLqH03rTAKlV4BJxP2z0dd2ogHtOf7kFoU=.chunk | |
| hxxp://omaha.playfree.org/service/update2?w=3:QEwJUu918gabi9_4v4ZCXohe4k_aFphJi5j2A6BwEZB-pjC258i8eQAf1dWV6qAR-a85v0lB6SfQVyclr06jCyjX1DxAumRSVTctealCogPFXZdsYghpnziAtOr2zw2HoPEwCdcMXfAz5Rw9Nrp_t3Ya9q4bmsU7lNiVgX66-5c | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/NOmm6qIJGzLneEHWSVjp5adubXmIgV9QvN8DqpIxpMg=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/xxhx3h0IzWuRG-tiUmGAPmqcSkzL7CgGn2_WLc4XndI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/u_hXwLRpsoJeSOsazeFzQYvUWnjbcqzfxK5xvSHfm3c=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/uq-M1FCqWXfGGjcE0dku9n1tg5Z59jjylidsIBdF6NA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/1b7cTbKmHzzFa39lmYqZ5pm-PEkHzxCUXSEXIQ5m-0U=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/wcDPbWwJTE2PtmVwcgnQhhl6hkrs-T-aO8g8Itcyd-U=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/lDCWU4HFh7141Gk4nPtxKfqUBMi3DgioCNmziSQFSAY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/XJS8JhoQCLrHvoi2N1Ve_rg1LE7dFSX2zXDYKWc9FXQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/CBZSVliJ3jUTEovyUiGBSNmHnvKYhm043-gh-uvUrbg=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/hK7NEVX0GuFHKMVPJRS41fUCr-UYuBOz0-nU7cXArDc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/oo-e1VxPfy8b3acjW9TlUivCKwFQYTLtR_ZXD2Rt2JU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/y89AXj6vwBtPw01Gvvljk0iJ7w5X_ddoWa5ftRYPgU8=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/GUm2SD84TFLXUY9w5Ml6upZqTjz35cgyPrGvWrBgYeI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/rHqFII0PWn-x5sL4llxzm8PrL_k6RDogkhqBV80h3JU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/-UtvLBU64lZsXS6mufZK4XOCHgYcH3F3q8TmeiT9jS4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/sJEvZc18T-F36DdkfLn5DgD2i3J2L2_5jaZ89QVBmvg=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/7giqbAFh2S33m9VF3lXAepQAHn28qzEmckcfXXCSNJE=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/-Pz-fPXqNiCqMKFOyFGBikrEmpIlZiMQ-guIaOYFwRo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/DhmkbGq3IqOmH688Cmt9YunECJJ_kvFlB6mcbV-E4sQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/wEXpqs63b7RAaV1YPIGl6QqBL-E4S-69bDQwGU7vRBk=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/8XiZtdDw1DowEM1tM0Tx3-7Fu0YDRjcZv3cZUNkgNEI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/1gJ-QLXRErQ4NiC1c9bYxQAG6x1mHAWYoJKg9Hiahlo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Y0cCKitNdebmBGg2qVxMow9PkJ5C5cS4IunvOy1sG4I=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/-zFjpKxKhsxytgDQNzMvJgyR8pvmFqwL1vXPvZg1oFo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/Zc1p-chDcLtgTXbOPHgnX7g_F5Vddk2CGPFY7CZXFkA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/PNPgF0Jh61aGCyqcVnEpeT5gL8KFscgS6OjPTI44wis=.chunk | |
| hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?3957b92ea85f63c5 | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/GgQ4WSYwIL2jgsYgnfOjR0qqfePaXmb-DX3XOtsW9Zc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/qzgYzW75oibJa6fwVg4hubmLlvrDL4ZEYWL5JJvg_H4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/M_uIHnItKjxLGZ6Y6sA3mLX9k8jkxrLA4WFXXMB8GPM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/-vBQWF0p7_3PTuvUELHd7TmHz5DAfYsfy0VG-d6aB3Y=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/8pHhQz9xknZc2CVxwA-g54bDE_T_5LY6xJIORyAqCv4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/KUfgkRS_-x-xLthI9bemI07LuTOBbdjQXJVT1Gcc8Fs=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/NneCNSI4ljllFsoAbEr4y8E1cx5_ihkhoIBbRdfJ6J0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/E34UBcOsmTNnqLeVWPOaryM0WWvyZOIzlDl7WR6cc80=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/bY38XvWYcXsoQZ0FlaGOCgqYBcsM8Kjb72fvP8txRBY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/AFGjLCcPvpsG1HUPtkI98qT8qJteSviPkekn-QzuSyE=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/AML77lIHrfObviL_zBFRuLttbdLev1tq5-ORUTccdyA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/skFus4cWDXN8GL8gnFtUdRf6nKmCCrZ4CR_AhQ0aau8=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/pqIY_e0O3hSWRoJAeaHMgDfMFzzIEueabEuZVNkuFCQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/QE5wpfxYC4_ZkRiYpgWBMaPIipoEvJ2MAg3pKTv6kqE=.chunk | |
| hxxp://r2---sn-ugpva5o-3c2e.gvt1.com/edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?cms_redirect=yes&expire=1430468552&ip=37.57.16.189&ipbits=0&mm=28&mn=sn-ugpva5o-3c2e&ms=nvh&mt=1430454086&mv=u&pcm2cms=yes&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=26347A8AAAADD774630CF4C618EF0C0A5FC11F65.0E69BCDACB63B8EE5BFA7AE881E0B9EDF4DCB9C8&key=cms1 | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/nhJUhSVWvHs0hfzlykFUz6TAZgIYTI2u0kvRVsqf6qQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/Ze8uEZAqHBtd2fK7UD2v7hiXbNOJV9Huo6Wkh5s7vRw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/FFVlibTAzjsLur4NAXQOZA6peE6IVXVI3LCXkKUctgU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/cjyIJrK5F9M1n9xrACpzp-cw6OzC-MNqeGjrqaNgpCY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/QDOtk_76wVL3jPoaZs27-7533knjsMtnCdangZmx1Wo=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/quCU-R968hkl0cyruELC_MV3YrizvN33lCu_XyBmd4E=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/LpJqp1zoQaivOKHY_YxfSfoQzXr8OBdeGyXfwZFuU88=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/I4cHXUB5lw3x_oo_3SLBgGOqm-L0Ppel0n5wNSMEYdk=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Bo9JfyHVL7b5NSgfR8eXJuvq1Sz1--op2i8kfamuRcI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/ULvy5kahSMHS-3gFwUXe6fqhBgBfxAEImQvAcX_9780=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/-4o5ao5EnwLZD9iXKCnEsuiZD1-825UgvePOW0l7Jig=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/lRebbZGau64hCEQVXoOFwZoCHsX1jFGWIfTr05I6p_E=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/7bOJgy8Hm2aYptpm9nr6UfbSLV0FRWxA8aiAgMmpc3w=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/i5G2FM8_tLEjfy7aO0N4kmHdYf7-_pBv3JkZPz8emiA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/LkU_PzHi470rWlFlDx6vPOMdSCxN46QTXhBcM_R_KXc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/F0fpy84reqUnQmBQSuHR2vNOoa14FpI-dzipR4EF1LQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/IJvxhg70GV20xTBQnxkJq9p6uz0Gge8MXTeEu5AhP78=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/bV86Zyzwrz-XuBUsX9if0otATsDvqxKW9-y0KqjYYzA=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/Z-BZzgdR6niuNm6Dbw-4jp7KnREXbvzrB0Xn2C-u9d0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/684__O4vQZnuf-5-LkTjdfmz6aY3sfpIgE5Jb8qUdsU=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/0R1tCv_0z65MW3lwpOOkUz0Cpddp4rD5-PMCI8oOhRM=.chunk | |
| hxxp://redirector.gvt1.com/edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/BewhhbJykgB1ha8-WMrSewfQIiANmgIGXucGjsl33Ks=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/DFBYtvq866rJuHxVyLHxF65hHot39cLoMpvzYSy1k7o=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/HcTDZdOAqbjP60mqsUDke9Xw0HITGpAZnncOOQKDDKQ=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/HTljzKj4oCu9PHBzGXK_dMaJUzy_2N0eWMp9W7Zt6QI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/FfNH48w7DUHj48hUCP8YmqTLg961wKPqU4prBE4tEFY=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/Lbqo50DoB6E0rsYdfnv8-3rJNk-O52A9UO9OtxxGEw8=.chunk | |
| hxxp://omaha.playfree.org/service/update2?w=3:KUuZkuoC7H8t1GILnNZ8kHg9xSafCQra5vhZDuzrPIy84ga3Jm6MJCU8kEVOE22Rl9a0cnj1Kq5i__mvd6itMjmMDN93A0guOwTCflpKx08iVu74hey4YZb6Lh-41BNcBwCze4rZ3nTS926S43CTAQX8sbxiX50uWVfvMVyScZ0 | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/zPBY_ZsUBv6JGy4o-VialmS3BxJzABATPHbco1wNs3g=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/htfrrZFnqTgSC2mR0kmzYfL1_FCaDvtToyAQP0dl3VM=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEGO+CyDUoFQBjrKVo87pCRc= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/t7wD0vKOutL6XFFHiHuakC8aXB6YVLa1sj730VndEqM=.chunk | |
| hxxp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/FHvKorYRa9bSJlD4xPUO7BZe3gbwe7hXGscMWGeHqIw=.chunk | |
| hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/34hObcShEQV4s6ck7ExkGQwcoXdmdgRIKIqoNG8qAkc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/RbA3tgllhVw4uoreA9t0dnot91l0x4S0xbKnKLSSklM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/Y7Bbdz8_yw6v_bqO-aA6L91DCfbRovNLkVFMxneEoig=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/fkpIIcjuujT2rH2P7HowLNvnV_wY3RESjlhYbwey-Ek=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEEhJyjx2Kj7S0x8cjJXTloQ= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/wzLxTSmOmorwmke1Edhp54wX_9dvNs5yPeP8oenPaK4=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/lRSiPs_nDoWaue8Z9Qu4rVd7SFCZjV2jZ7ug0nBaMDc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/AKhP51LP6RbILIOwncigFP531tS2Yb9D8jtiZVa6uoo=.chunk | |
| hxxp://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECECVRccvD8Qb29B4D63fPT+k= | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/O9JgGROBQ5x0P5QtZJaM8u0jmTgbS8oXBKn-Ktuo18k=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/mMTuPD16d8c2k64LffvorHqu_-6USXYtJeOhBI7MOOs=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/jNaFSriOZfpnZyKuKOMt15IDydkN0sT32zGXqNfHpk0=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/ituihT2nIuOO6K7aEfwTkyN_MxBmCcdyz-1vcd_m2wE=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/5QoMmAuV8US3Ysur3PVelYvOwlVagaglfaAafQ9_Yig=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/6QP0kMWCUrsl3TMa6i0RJicPwULRgr-75UnuqkTrowg=.chunk | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= | |
| hxxp://imagecdn.infospace.com/search/lib/ptwidget-1.0.js | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/QfkQ0yWr_4I0G1WQBVqa2lZJgzDfK_gsq3C_w3N4JYw=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/_LeYmVcLjaymWdywoaBs2fZ3zvbAC0b1zHa4o6BHJE8=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/7JE0yHlqxwcT2P3015xdKB--Hrdwr7-1wPzo1rfzEPM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/qDo5pwKwKj9YxZJyWqEiDvFdZDuI5PahFwZOoPI4-7A=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-malware-shavar/Ns_Bo4UvBU6hqyUFEDzll7JPYJ-SQwlpuXzX7KRxY_Y=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/4QA7fZWgrqxa94GQcWGjO3rvLLV-E4WktLOUf4lHHrs=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/wZBd-e3nlAYWe0lPx6hvMHNc-sDwWwuhlIin-owxthM=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/nB0tjQFotnc6cc-qs7MVBADJ66-XV6kfwDsAr-8FW9E=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/BC0-t8qDOZWMvEUrn6JXSuUN6qhlTVaqNx79F0rdNVc=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/2GIB_v116SbEk07Zs-UKwNZth2eBtM7lJtrdsWr_ITI=.chunk | |
| hxxp://sba.cdn.yandex.net/chunks/goog-phish-shavar/kM4mzd_BuL56ZUjvvtfFU4OlLoZ0tcQBXhFE43FTkn4=.chunk | |
| clients3.google.com | |
| translate.googleapis.com | |
| clients4.google.com | |
| www.gstatic.com | |
| plarium.com | |
| ssl.gstatic.com | |
| tools.google.com | |
| www.google.com | |
| games.playfree.org | |
| social.playfree.org |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
SURICATA UDPv4 invalid checksum
SURICATA IPv4 invalid checksum
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected
SURICATA STREAM SHUTDOWN RST invalid ack
SURICATA STREAM Packet with invalid ack
Traffic
GET /ca.cer HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: repository.certum.pl
HTTP/1.1 200 OK
Date: Fri, 01 May 2015 04:21:29 GMT
Server: Apache
Last-Modified: Fri, 07 Mar 2014 10:05:14 GMT
ETag: "34231-310-63d6aa80"
Accept-Ranges: bytes
Content-Length: 784
Connection: close
Content-Type: text/plain; charset=UTF-80...0............ 0...*.H........0>1.0...U....PL1.0...U....Unizeto
Sp. z o.o.1.0...U....Certum CA0...020611104639Z..270611104639Z0>1.0
...U....PL1.0...U....Unizeto Sp. z o.o.1.0...U....Certum CA0.."0...*.H
.............0.............O|.%..>O..o.js.[Q......\...u......#R...3
..-..v. 9....K...x.sC{.a..X..lf~...^Uc.......0h..<..n..Z.N4.6....P.
m.B......AK.jk...~b.g..&_.&..O..W(....E.n.%].n9.../.G.r...[..S?....V.n
..f.&...S.....O).B.^... ..h.......Fc..."....FY~.5,...].H3.T...o.......
.;.Y.......0.0...U.......0....0...*.H.......................D.l.9>.
.n..!w..w... A......c..7..v$...L.=.go-...e1p......`{mX..I.c2.k.:...;..
..Q....4.. ...`.'l2w...r....?..$B..W..&C.......T(>.?..M.j.:...;.#.c
.?..'y.LQ....].;..s.....nd.ZV....Lt..q;..G.io...^...|R......Yg...p...i
[email protected].)f.!.,.`*[email protected].$...,s..
GET /chunks/goog-phish-shavar/WNYAEB6kHQLqH03rTAKlV4BJxP2z0dd2ogHtOf7kFoU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/WNYAEB6kHQLqH03rTAKlV4BJxP2z0dd2ogHtOf7kFoU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/oo-e1VxPfy8b3acjW9TlUivCKwFQYTLtR_ZXD2Rt2JU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/oo-e1VxPfy8b3acjW9TlUivCKwFQYTLtR_ZXD2Rt2JU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/t7wD0vKOutL6XFFHiHuakC8aXB6YVLa1sj730VndEqM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/t7wD0vKOutL6XFFHiHuakC8aXB6YVLa1sj730VndEqM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
POST /service/update2 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: MPCBrowser Update/1.3.27.0;winhttp
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Content-Length: 510
Host: omaha.playfree.org
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" version="1.3.27.0" ismachine="0" sessionid="{17D31739-CE97-41F0-B418-534DA8AFFCEB}" installsource="otherinstallcmd" testsource="auto" requestid="{D623BE7B-EE80-4B30-806A-8337210A014A}"><os platform="win" version="6.1" sp="Service Pack 1" arch="x64"/><app appid="{00337EA4-7B9A-44A6-B45B-B1722CD4343E}" version="" nextversion="1.3.27.0" lang="en" brand="" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0"/></app></request>
HTTP/1.1 200 OK
Server: nginx/1.4.1
Date: Fri, 01 May 2015 04:18:17 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.15
Set-Cookie: pid=7g9d8jov9j24q32mufcr2ljjd7; expires=Sat, 02-May-2015 04:18:16 GMT; path=/; domain=.omaha.playfree.org
Cache-Control: private, max-age=10800, pre-check=10800
Last-Modified: Tue, 27 Nov 2012 07:34:24 GMTc6..<?xml version="1.0"?>.<response protocol="3.0" server="pr
od"><daystart elapsed_seconds="83896"/><app appid="{00337E
A4-7B9A-44A6-B45B-B1722CD4343E}" status="ok"><event status="ok"/
></app></response>...0..
GET /chunks/goog-malware-shavar/-zFjpKxKhsxytgDQNzMvJgyR8pvmFqwL1vXPvZg1oFo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/-zFjpKxKhsxytgDQNzMvJgyR8pvmFqwL1vXPvZg1oFo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/tFrZWBGYzrmSIkQD08neZlV3aJoQfKyKFZgZSg7ts88=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/tFrZWBGYzrmSIkQD08neZlV3aJoQfKyKFZgZSg7ts88=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/xEztrZ_otV4HLVyDpTFlDQBGcxzWLzBBBm4NsdzFEwc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/xEztrZ_otV4HLVyDpTFlDQBGcxzWLzBBBm4NsdzFEwc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/y89AXj6vwBtPw01Gvvljk0iJ7w5X_ddoWa5ftRYPgU8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/y89AXj6vwBtPw01Gvvljk0iJ7w5X_ddoWa5ftRYPgU8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/O9JgGROBQ5x0P5QtZJaM8u0jmTgbS8oXBKn-Ktuo18k=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/O9JgGROBQ5x0P5QtZJaM8u0jmTgbS8oXBKn-Ktuo18k=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/B9oFeiEQxNCzVOPSXAabZqrJjttO7a0CzH6NcQHUIYI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/B9oFeiEQxNCzVOPSXAabZqrJjttO7a0CzH6NcQHUIYI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/AML77lIHrfObviL_zBFRuLttbdLev1tq5-ORUTccdyA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/AML77lIHrfObviL_zBFRuLttbdLev1tq5-ORUTccdyA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/I4cHXUB5lw3x_oo_3SLBgGOqm-L0Ppel0n5wNSMEYdk=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/I4cHXUB5lw3x_oo_3SLBgGOqm-L0Ppel0n5wNSMEYdk=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/oweDFIsK4aD4_rARvw_DFsYTnCHgAwkIyO-Cr1Sggq8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/oweDFIsK4aD4_rARvw_DFsYTnCHgAwkIyO-Cr1Sggq8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/1gJ-QLXRErQ4NiC1c9bYxQAG6x1mHAWYoJKg9Hiahlo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/1gJ-QLXRErQ4NiC1c9bYxQAG6x1mHAWYoJKg9Hiahlo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/5S79mJ6464OwK7yKBT2PYdKWEZ4aQHolIEUHr4Tzyf4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/5S79mJ6464OwK7yKBT2PYdKWEZ4aQHolIEUHr4Tzyf4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/0R1tCv_0z65MW3lwpOOkUz0Cpddp4rD5-PMCI8oOhRM=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 3248
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 22:00:34 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40197:4:3233.Q@of....#[email protected]_....&..k_...I....q...I........#.......
...t.....'.(.......U..."K......."K.............T~G.....^.....|........
|....DX....4..DX..hg.......hgd.......&d....|......[."..j.k.....M.?.1..
RW......\7....FKH.....E".j....Do....G........G..2h.......2h..........]
....Z........Z...|..P....$|..PgXji....BgXjiY...........9..vE....<..
vEb.WZ.....b.WZ........(............d.....2-.....].2-..n......'.n..{..
.....[{.....]........]..9.S......9.S.R........R...Y........Y..i.......
.>.28...^......._o.T....`E.o....a.<O. .t...... .t.........z.....
0......_j......]..d...._...a.F~.....].F~..tw4......tw4.........'c.*e..
{.....e..{_..W....._..WSg7.....uSg7...m'....]...7......EN...........^6
...9.......&9...%.......;%.....z........z.{..K......-.T.....).0.......
V....\........07,.v........v..T..:.....T..:y../.... y../...m........mA
..c.....A..cYc......LYc...............~6......f~6..G$i".....G$i"0.r...
...0.r.........&.....v. ......v. ...5........5........%....j.>[....
qj.>[............................Q........Q..VX.....Y.VX..!.n....J.
....|........|...h;_....gz|.]...lq..&...].......v.,.....my..l...m.....
..w.;.v...].)q.E........E...........C......O........O..h........h.....
.............D........D`.......)`...7 .,.....7 .,........_......H.....
A..H..O........O...NU.....#.NU..Hil......Hil.U......].U..x........x...
o.r*.....o.r*........"..............c;....JT......Jm......J.\.....JQ..
....J...a?..s....>n.] yAHb....G.oGZ...C.......Gj......G..x....F....
...C.o'..Ee.....4.Ee.cd......"cd....6....._J........w....._jI.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/6QP0kMWCUrsl3TMa6i0RJicPwULRgr-75UnuqkTrowg=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 12636
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 20:20:48 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40196:4:12620.j*n.....\j*n...F........F.o.PC....Oo.PC..8c.......8c..
...........T~G.....]..;.r.x.....'r.x........./...h...................x
GG...../Pv2....E........E........;.....:k.....7.:k...._........_?.0...
..y?.0.qs.T.....qs.T............VUH{>.....UH{>.#.A......#.A.N8..
...q.N8.i........i...{.G/.....{.G/Y........A<<.......mU.........
......./....:.../.a5.......a5..J......0.J..T.......qT...RT.......RT...
.).....c..)..Q".......Q".2;Ig....`)..J..._.;.o...`..l...._.N.u...`F_}.
..._c..N...^..}h........J.!....h.....L..h...............R........R....
......6....h..=....}h..=..,........,...m'....aM......^w..S...]`..m...{
.S.....]?......aa.K]...T........T.pjo......B...... \r.......d.........
......1........1............... .11..... .11..l........l.pA.E.....pA.E
........$.......)........).dD3......dD3G.<`....]G.<`9o&r.....9o&
r..............l........l..y.;......y.;.)....... )....*g.....;.*g.k...
.....k.....RW....C... VU.......VU...`......,.`...h........h.....{.....
...{.f......].2..a.&q.....a.&q...Z....'...Z.h;_...._.......qB..Y...a..
.....o.......lB1(..............)........).....C........C..............
Y........2F.......9.....{.CWY%|.......%|...W........W... .#...... .#..
......'............\............_.: ..n.......hR.....C........C.c.&...
...c.&g..V.....g..V..c.....$..c...v........v.".(......".(...e........e
./......../....|......U...o.XT.....J.XT.5:.Q.....5:.QC.......cC....q^.
......q^...f.....3..f...|J.......|J........J.{{....JO...?..s....=2Y.6.
....................$....y........y.....6......9xH..E......].E..m.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/1qFV-RFKQ9Yksu28tM2AZeyfzp7v91bWYWwMI7_MNic=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 15069
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 17:00:50 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40194:4:15053..C)w......C)wD{L5....qD{L5.3.!....F.3.!B. w....JB. w..
........KLp......AXA8f.....cA8f."bO......"bO..........8....f......jr..
.C%s......C%s....i....'...i..9........9...U.....W..U...."........"(k..
.....(k...}h.....7.}h..8.R......8.R'a.......'a...%........%.....f.....
[email protected][email protected].^......b.^.2;Ig....a.....T.r......T.r.9.......f....
..]...)bS......fbS....n........n.fO......$fO...y/.......y/..j/y......j
/y.c........c....m'...........2........2.?..h.....?..h.b.-......b.-...
.....\..................:........:....v........v.|..!.....|..!".A.....
.".A..5*.......5*..y........y..`..R....$`..R.A......!.A...............
..0........0...L)....C..L)7.(......7.(..e.4......e.4S..p....ZS..p.....
........4df.....y4df.................}....q...}...<....r...<-..]
....b-..]..............B.|......B.|7S......p7S..)........)......h....'
...hO..Q.....O..Q...,........,........M>.ML...M`..u.|7.....U.|7....
..... ....<{ ......<{ ...y(.......y(7......./7................1.
2.....a...8.t.K.....E..E.x.w......x.w..O........O..#R.......#R.WC.....
..WC..........J....bs.......bs..e.......47......4...0Z........Z.....O.
.......O.~.S .....~.S .T1C....r.T1C.._.....B.._.U..%.....U..%...%....!
...%..6E.......6E.............'........'...........J.#.gyAHb.......FY&
lt;........<..._..p....6.ZxP...6.F.f...6.......6y$.....6..(....6...
[..6.....].[[email protected]......^.<.n..._.......]0..:...
^nwb...._.a.j...][......^.W.....`q..%...]N&o....^.......^.V....._.p.P.
..`..)...._.h9...._.>%....^..a...._x.,....]n.ob...^<.C....]{<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/OypAprm_9JNXzDZt_V9HoRneNyy7siQEwJ3hHQjmCHY=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 126655
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 16:00:59 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40193:4:126638."3......p"3.....r........r.M3.....q.M3..:......:.:...
!x.....JKH.7...J.......J.o~k...J..n....J..f....JDY.....J.......J......
.JE`Q....J.'S....J.X#8...JU......JN.....B.....<..B..Y.|....f.Y.|.1%
J......1%J.|......T{N....zK....p..zK.4.$....6.4.$.........._.9....i1&l
t;..............a........a....I......8.I..........9.....\......q.\...l
[email protected]...... .l..*.s;....y*.s;.......
.;.....T.Y......T.Y.f......c.f..$.......x$....$aM......$aMJ[s......J[s
.-u......&-u....S[..........S.V....6.S.V"..V....m.&.*...mC.. ...m(.!..
..m.F"....mR......m*......m=..j2;Ig....`..F....].......]J......`..uT..
.^d.f....a}......]."....._.7t....`|......`.......`).c_...`..H....]..)=
...`6......`b......`D.'....^......._.v.<...`.......^.K%....]KN.....
]......._...,...`..^....`......._..kp...^j..J..._X..^...`n......]GZT&g
t;...`..%...._.X/...._..{~...^!.'....`..NF...^..Q....].C;y...`.B.N...^
.......`I......a...L...^K..a...^.......^......._G..8...a.<.h...]Z..
...._.D.....^.......a-..\..._.".....^r..l...^..Wm...`.=.6...a.......`Y
......`.i.....]..O....]6h.'...`...Z...`.EU....^O.2....].......`.MIg...
].1.....]A..:...`.. ...._.S.B...^g..}..._SH.....a.......`;......_.QX..
..]...R...]...H...__.G~...^..Y{...a. .....^<......`lV.u..._'..=...^
.......`>L.....^..w^...^...w...a8.A....^.Un....`>.SD...a:.C....]
...n...]J4}...._.h.....^.2.....]..o...._.b.=...^...>..._G_)....^J..
....aJ..]...`..}....^.7.u...a.C.O...`.i&...._.\N...._..W....a..S....]D
......]=M.....a...T...ao#g....]P..b...`.,.%...^X..<...a.......]<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/yJ1ZF2okVJs_Cd8LPf5zbMQMveBa1SReufVugI1TKTY=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 7620
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 14:10:41 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40192:4:7605.^<B.....q^<B.},......j},..pc-Q....9pc-Qim......pi
m.................nS....y..nSM.......;M....-......".-...m.p....C......
.CN.9.".......:"...O.u`.....O.u`.Ml.......Ml...Aq....F!U0....GKa.....F
.......F..{....D.......Cu......G.Mz....C.5.}...G.......G..c....GI.!...
.EQ.q....D.......C..%....C.LD=...E..;....H../....F5......G.d.....C=.0.
...C..(o...DL.K....C..]0...Gb6k....G.......CA.S....E.......D..X....E{%
[email protected]...{...E2......E..F....C.......E.L-....G=<.T.
..G2.-X...H@7.%...CQ.k#...F.I.....F..!....H]......E.......E.K.....H.z7
....E..ZA...G>.t....G.......C.......E1..Y...Gl~W-...H...o...G......
.Cwl0....E.......D.3E....F(.b....D.;.B...FbX.[...Dj..A...C.>3....F.
.Kg...E.......C..N_...Dv.z....G..W....G.......FI..6...C.......D.......
F..N....F.2d....EZ'"z...D[.g....D.......G.......F.RF....D.......F..Yj.
..E ......DHt.#...EV.p....H.4.!...D...J...DI..e...D&......DpV.....Cd..
....FN.1....G.PD....G...)...E.......E..R....G.cx....GD......Gz. ....C?
.b....F.#_....C.......G.......G.0No...E_......E.[@....F.......F.......
C.......C...o...E.......C.......G...r...EE......G.8.t...F.UE....F..f..
..G..X........0...G;Z ....C%..n...D...G...G..1....G.......F...]...EQZ.
....G%5.1...D.F.....E9.5,...D/......E..$....HJ.v....FZ.8(...G.......D.
k.....F.......C../....G.......G$......C;......F...A...D...6...F.......
Gk......D../R...G.<<#...C.......H[.(A...D%v.....D|.%....G..MC...
C...`...D`......E.}.b...E.......F.CE8...C.."(...G.f)'...D-W|....G...9.
..CTc.....Dk}i....E}.nn...G.......FRn.b...E9.\....D.=.....D..2....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/-vBQWF0p7_3PTuvUELHd7TmHz5DAfYsfy0VG-d6aB3Y=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 114606
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 13:21:01 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40191:4:114589......................9............9.......:.......<
;.~.k:X.......:X..........N..l....M*......OL3.....LK..X...L.p.....L..'
....Mg......N.b&....M=G/M...M'i.....M<.s....NR......M.......M...D..
.M"......M..(i...M..rf...O.hN....N.......O.......Od .g...Mp.m....M....
...Nms.D...L.......L.^.....O...D...M..|j...Mne.....L}j.....O...U...M..
D....O.......M.......L...S...M8N.F...N|[6....O.......N..KR...N..,....N
.......L..Fo...L.b!....N.......Mx......O..w....OK.|^...No[.Y...LJ.L]..
.L'......L.!av...L.ip....O..3....LA......N.X=....M-..%...M.......O....
...O.;9y...O..g{...M.D.....M.M.....M.......L..O....N..Mz...N..#....N..
.B...N.e.....O.......N...b...L..^W...O.......L.......N%#.....L3..k...L
.!f....M$......L.ee....N.`? ...O.U2....N.......L...<...L...\...N...
'...N.<.^...N.A.....NA......L.......N.6,....Nm......N.C.....N...Q..
.O...%...N$*.....N`......M,5d....L.>K(...Nb n....O..w....M..}....L.
......N.......L;.s....L*.M....M..,....N0..I...J3..l...N.......L.h.....
O.......N.......L.J.....M%......O.fR4...N%.VX...M..cO...N):.....N.....
..N.......J.......Lf......MC.i-...O.a.....O...>...LR;.L...LV..#...L
..."...NJ..h...L.......N..=....N...`...L(......O.Z[R...O./O2...L.h....
.N...[...M.......Lv..]...M.\x....L...P...L..:....L..V....O.......M.H.$
...M.X?....Ob......L...0...N/h.....M.......Of..D...N._r....M.......M.a
.D...M...o...M.y.....O.H.....NV......M1..i...M..ex...L.$'....MOC.L...O
vo[....N...W...M.v."...O0......M.1.....N.7.....L.R^....MFV.....M..(...
.M.[.Y...M.......Mvx?....OM..<...N-j.....M,a-~...O...y...L.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/NneCNSI4ljllFsoAbEr4y8E1cx5_ihkhoIBbRdfJ6J0=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 70774
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 12:11:04 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40190:4:70758.EK......qEK...Ly.......Ly......................_......
[email protected]@g.?...b...D ./....CY.`....C}l.r...D
[email protected]$P.....D.N._...C.......C.^l<
;...D.......C:..a...C...2...D%......D._.7...C.)N....C.e.6...D.r.....Dk
^VW...C.......C.>$&...Db\.L...C.Y.....D.Oy....C(..j...CM.[....D7..^
...D.._a...DG.^5...C..4....E.......D.L.....D.!.....D.[>....D>..6
...D0 .....D.......Dc......D.......C{......D.<.....DP.`....C.......
D.5.....D..l....D...g...D.Q.A...C...D...C.......D.0T>...C.......D|!
<t...Cr......C.d.....DjC.....D..ne...D\I:t...D..-....C .4....CF ...
..D]..}...D... ...D*b.....D..X....C..-....Cu......C..q....E.......C...
C...C|..d...C.......C.=b....C.M.....C..&....D.%.....D.1"X...C.q.'...D.
..J...CA.0M...DA..n...C.h.D...D.y.....D}......D.......C.U.....C...x...
D.:d....D0......D...Q...C..L?...C..e....D..`m...C?g9-...C9......D7!.6.
..D..w}T~G.....]s......^...@...^y8.....^c..l...^.(.....]w>Ql...]..H
I...]ja.....].....!x.....Mi......M.<.w...M.n.....L...Z...NA......Lc
......L.c K...L...R...MZQ.....L..I....L=..^...M.......M..g....M?......
MBV.....Mw..H...M... ...N...;...L'k.....N._.%...Lz.]....M.|<p...L.%
.L...M'|.....LM~.O...L.L.....M............ntf.....q'........d."l.8....
..l.8..............K.F......K.F.....6...E._.....C0......Dy......C`Q.*.
..Di......D !:....C..Y....D.^.....D9' ....C.Ul....D..%&...C.......C%..
e...E.".....DQ..D...C7.x*...C_......D...S...D.../...D... ...C uK0...E.
>.G...D].,....C.......CjOa....C.......D.^.....E.......C...1...C<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/1gJ-QLXRErQ4NiC1c9bYxQAG6x1mHAWYoJKg9Hiahlo=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 45159
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 10:21:04 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40189:4:45143.........MH......L.......M..4....M.......N=......N`B...
..Mq..D...NB4.#...M..&L...O.<x....N..|....M.......L..(B...M$......O
.([email protected]_......O#t.y...O.LQ....NJ.bP...N......
.L...E...M..yN...L>......M...>...L4F]....N.......N..t....ML.....
.L.......N..'....L...R...M5..u...L,A8,...N2......MY..T...M"\.....O..c.
...M.&N....Lg|_8...O;.uB...N.......M..>....O...{...L.y.....L.......
M..3....O.......L.......Mg......O.0.....N5......M.y.....L#..V...Lp....
..O.."?...Mu.7....M(..q...M2......LP.|....N.......N.5.-...L.......O.4.
r...O..k....L.dv....M../0...N..Sp...L;......L.:.....N.......OK.mG...Om
@.g...Nf..V...L.7.....O.~%L...O./ ....N]......O.......N.-.p...O.?%'...
M...=...O.".....MZ......N"u.;...N.xw....O.......O =.7...L.g.....L..R..
..O\......L.......M.......N#R.V...M9V.u...L. .....M<]R....L.f.....M
...w...Or.8~...L.9.....M...2...N&.."[email protected].?c?...MS.....
.N.......O.......N.%.?...O.fCj...L..U....O._.....O.#.....M.5.....M0.fw
...M..6....O.......M...<...M..n....M...W...M.I.M...N.a.....L..C....
L.......Mn&-....M.fL....M..!%...Nc..:...Nt.G....M'......L..Kd...O...w.
..O"......L.......LpT.....O2......MX^.....M..[W...N.=.c...N...=...N..k
....O.......MI......N..p....M..2....M.......L.......O...0...M3`.:...NN
......O..J....L..H....N.bu....L..d....NY.8....N .ww...MI.!....M...l...
O.2[(...M.u.....NB..v...M8......N.wI....N.......O.."....MG[o....N.x(..
..M.. ....N.Df....N...k...N ......Nc......M.......N...n...Me......N.v.
[email protected].'.....L...N...O.. <...Ml..R...N..e....My1.....N..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/Lbqo50DoB6E0rsYdfnv8-3rJNk-O52A9UO9OtxxGEw8=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 44666
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40188:4:44650.O.}......O.}..k8f......k8f.0......i.0..........&....T~
G.....qT~G.?..s....<.<}.-.......{-...k.......vk....aS$......aS$.
.n[....g..n[Z.u.....1Z.u...RWT...G?W(m...C6(.....C...R...Gm..H...E`_$.
...C]..7...F..L....C..<Y...D..:....D.......F'vE....D!..X...D1......
D./.9...D.......F.4EQ...F.Xc....EfW.....F.1.....C.;.....D.\7....GME...
..C..p>...FW......D%n.....C.......Cs......D.......F...l...CA..!...C
.......C.CF....D..;n...C,,.....D..[....G/z.o...E ......F..L....F...f..
.E..?\...E&.x'...GZ.L....Edw.k...D..9[...E..}....E..t....F.Z.....F9.D]
...C..2{...G..n;...E.......E$.>....D.F\....C.g.....F.......E...9...
DF.`....F.f.....C...C...E.w.....F.C.....E...$...E)<.n...Eh..&...F.7
.....C.KN....F#m#/...Gb......F..YV...FH......CF.6....F.n.....C.......F
.G7....C.A.....Cd{dv...G,l.....Dz.>....F.. 8...Cg..O...D57z....D..`
....G.......G..^.~..`....9~..`0.P.....C0.P.`B......Ca.r....E$@.\...C-.
.....E?..,...C.F.....C6..C...D..h....Ck4[[...Dx..?...D*g.5...E..u....D
Dz.....D.......Cn.T....D.^.....F>|.3...D,_.f...E..I....C.......F.3K
....D.......D:..8...E.Q.....F.g|I...D.6k....D0......C.......D..[....F.
..|...E.E.....Cg......C.......C.......EI..H...F.r.9...E.0i....F.G.....
FY......DG..I...D*}p....C.......C.......EH......C.t.....C{N.....F0\...
..F..0....F.......D..U....C.x.....E.-.....C.......C.f3....C..<B...D
p......Eb..\...E<..!...FH.u,...D.A.....C.......F;.P....F.{.G...F...
....F7.Cf...E...}...F.D. ...C..c....D.%.....D ./....E.......F..>...
.F..m....D.|D|...C.Xy....C...{...C.......D.}.....F.V.....E.......D<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/D_1Zrj0aSqF6XUXiWJ9r6ZYUEaVZYpvCWaBBaTVDy0o=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 23522
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:20:56 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40187:4:23506..!.n....g.!.nyAHb....E.......F.......GU.j..C..k...?<
;..c...@.......=...#...@;7.8...<V.,S...=D.^....@d......=MY.....=...
....=.......<k..K...?..~....>[email protected]_...<
!..!...?.......?.z.n...<...h...<Eq.....=.[[email protected].....&
gt;"[email protected]<....<.......>.......<C8e....@..,....=.......
?.......<..(....>3.91...?B}.....?..o....>..S....=.Q.....<.
bq/...>.!.U...>41q&...<. m....?;......?.)\6...?...e...<$.%
....<{J.F...>...{...?...A...=.81....=.h\^...=.}T....=xs.n...>
37."...?.......=.......=.......>.RU1...>.......=%......>5aF..
..>./.*...?n.!c...>Q.\9...<.eN....<.0]....>~......?<
&.....=./.....>.......<s.WE...?j......<.t.....<W.U0...<
g).....>...'...</..1...<.y4....?.......?.?C....?.C.....=.&...
..?..B....?.iRH...>z.8....<...,...>..O"...?6}O....=..B5...<
;n......>(.1....?j.i....=.p3N...<4......?...*...<~......?*...
...>X.(....>>......=.......=.<.....> .r....=B.\....=..s
E...?~O.A...?.......>f...........q....?.......C.......Cw.S....D|...
...D.../...C.T.9...D.......C.......C@%9*[email protected]).7....CE;
i....D/2.G...Cv_.....C.nU8...C.[.R...C(m.k...C.GB....D...f...C..)....D
QDy{...C.......D.0(U...D.......Dl8.O...CY..9...C.......D.7.s...D......
.C.......D.......C{._....E.......D..XB...D.-.1...D.CG....C(.<....D.
......D.......CKI%....D...6...D..s....C![[email protected].......
C.J.{...C.(.....CF..q...C..6>...C6ol....C...E...D.......D..L...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/vxmVNy37oonjrrSDZBzDLPpqngc8zEScGiGMBTyDFcc=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 2201
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:00:37 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40186:4:2186....I....h...I.LG.......LG....q........q.........Y..'...
s..b.....S.."...J....k...JU..B.....U..BwI......DwI...f......].A.aM....
....M...S.4V.....S.4Vo%6......o%6..Y.C......Y.Cu\.`....=u\.`(.}Z....s(
.}Zj..#.....j..#..a........a.........H.....=.R......=.R.V.O......V.O..
.D........D.p$d.... .p$dO?.......O?...*.T....".*.T.h........h...".....
.x."...)Rv......)RvF t1....DF t1..............[........[...| .....c.|
.Z,.......Z,..Wb.9...."Wb.97.......q7....pjo.............A0*.....c}...
.....i..............o.......M.......n*I............3..n....i..Iu.DO...
.au.DOb:.A.....b:.A.\.4....^.\.4yMD.....`yMD.R.$......R.$.9..Z....99..
Z9........9...""].....1""]..............8..I.....8..I..KM.......KMK..,
.....K..,.u*.......u*....T........T..............F......r.F.."..b....9
"..b.@.*....=.@.*........0<.........5W....1................4.......
.4....#w.......#w.58.......58...............................D........D
..............}........}..g.g!.....g.g!'........'...Q......._Q.... ...
..... ....r........r.lUb......lUb...(r.......(r9VD......9VD.%U2M.....%
U2M..~........~..K........K.....:........:........7.....,.b......,.bxx
>......xx>.A.A\....5A.A\b..a.....b..a8.......$8...iU.......iU...
.C........C.........w.......{........{..HC.......HCXI......%XI........
..U......i........i...........................c._......c._.$..c....m$.
.c.k.7....<.k.7.]0.....D.%...`].......`]..*.n......*.n.^G0......^G0
........f.......=........=........Q.......q........q..Rm.......Rm.M.7.
.....M.7!..U.....!..UG.......-G....Vp$......Vp$n..k....4n..k/.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/Zc1p-chDcLtgTXbOPHgnX7g_F5Vddk2CGPFY7CZXFkA=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 906
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 06:20:56 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40185:4:892.G........G....f)r......f)r.z.)......z.)........6.......(
........(.3........3..........u............9....=t.x.....=t.x...`....C
...`........>.A.[...@.."i.............W.w.....KW.w...#........#....
.....p......G........G../R......./R.\s......$\s..$.......P$.....RW....
...RW%..\.....%..\8.......58...........<.......S........S........[.
...........<.................`B......T`B..X.......uX...?.......w?..
.^2......v^2....Q .......Q .|........|...QH8......QH8N.......]N...Gpq.
.....Gpq....1....q...1...`........`p..1.....p..1O."......O."...&.....q
..&.-.H......-.H..@......>[email protected]"..V....mc.
..4m.\.....4m.\"VFM....p"VFM..............?I.......?I.I..d....II..d.|.
F......&|...b........b....q........q..............dz.......dz.........
.....1.F......1.F...&........&....w........w..-3....q..-3...4........4
........<....^j......(^j.....}........}........z.......C....r...C..
...............
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/Y-vgliRy7vwOHI7QAOD7H4oqSf-TJiaCBLsl-TOu6W4=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 1042
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 05:20:58 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40184:4:1027.........u....?..s....q?..s................D....4...D..y
5.......y5W.H.....&W.H.$.......4$......;....-...;./e4....4./e4z}iv....
,z}iv..`F.......`F...w..../...w...{........{h........h......w....5...w
|(D.....&|(D.../......../....4........4.!v.....4.!v.........8.........
........~7.......~7...r.p......r.p.,,.....'.,,.........~.....o.D......
o.D..E........E.c........c...$.......,.T........../....v.yX.....v.yX..
....../.... ..`..... ..`5g......45g....O.....&..O.`........`....Y.o...
...Y.o.............|'.......|'..g.D.....pg.D.Ts.8.....Ts.8.).3....7L..
b2Y......:2Y....y4.......y4..D.....w..D..?~7....;.?~7.0&5....6.0&5...F
....e...F~.S......~.S...r........r.m<.K.....m<.K.)......x. ..G~.
...../G~.................~........~..............D........D...........
q......d.....p..d.T..O.....T..O.v.x....T.v.x..A........A.w. ......w. .
XC|4.....XC|[email protected].|....:2R.|6w...
....6w..{..K..../.N..s.......;s....P......,.P....[........[.... ......
6....=........=G.9h....4G.9h..ip.......ip...r........r...1........1
font>....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/IBkAcJkDe-UMa5JcZSHqewm1J1FPxuue9BBrv2HkV2M=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 2221
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 03:30:29 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40183:4:[email protected]./......Y./...(........(...
.....s..Rb...A.j0.............ggd?...@.......@^......qQ..&.....BR....@
..Q....... w.....N>....m.g...l.V....h.l.V...M........M.............
........S................>.....l.r..Fg.......Fg...^....j...^.%.....
...%...j......5.j..)Rl*.....)Rl*..2........2.'.Rv.....'.Rv............
...._........_..t.....!..t....5....q...5...`....'...`........a.... ...
..... ....;........;....s........s....p........pgf......Ggf..........:
......'........'..c........c...../......../%..?....<%..?}..d.....}.
.dx..H.....x..H................D........D.............~4.......~4.....
............< .......< XC......6XC..g..`.... g..`^........^...MX
.m....CMX.m........0......v.....)..v.S.......0S....51.......51........
......5..!.....5..!..0........0...#.....x..#[email protected]@
..AAu......AAuj.P.....Pj.P.[.~......[.~................'........'..1W4
......1W4.....................u......X........X.zF"......zF"..7<...
..J.7<.........8.....u.......y.......}.1..............i{......ji{..
<.:......<.:.........".......n.... ...n..............&........&.
. b....../ b..,.I4.....,.I4S..:....sS..:..|!.......|!.)./......)./..o&
.......o&.i.f......i.fH........H................9o.......9o...Pth.....
.Pth.;c.......;c..|.F......V_L{..$.....{..$..R........R.v........v...*
..).....*..)..L.....{..L.!>......:!>..{..).....{..)..@;....,..@;
.@i=....x.@i=..U.....,..U.&.......4..6...B........B..............a....
....a.....y........y.5..l.....5..l]..B....)]..B3T.[....G3T.[W"u...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/KlYWl0YjuqklZ6Kr-iE6JwkoD1lGRDSYV3y1xtUJ6vE=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 1560
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 02:10:34 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40182:4:1545.UG.|....mUG.|[email protected]...
......~.A......~.AyOSd.....yOSdY...........Ll........l...wo).....Cwo).
...............N6.......N6>.G......>.G..aY.......aY.Q......."Q..
.9U.......9U..d.K.....Xd.K.........!.................u..7....Yu..7..RA
.......RA...]....r...].w.F....1.w.F.q.3....%.q.3.s.n....0.s.n.Z.......
.Z..........0.......P........P|........|...5Ryw.....5Ryw.im.....0.im..
.1........1...............b.C......b.C..bY.......bY...................
........ .l...... .l..u........u...c0.......c0.K.%......K.%0.9......0.
9.K.O6...."K.O6.u.........b.e........e...zY.......zY.....q....,...q.._
........_.M........M..._.5......_.5...e5....S..e5...n...."...nh..$....
.h..$=.......M=....G......j.G..x:.......x:....0>.......).!w9......!
w9....J........J..3........3.K.mS....yK.mS..`........`.... .....;..3..
...e..n.v......n.v.;.bX.....;.bX.z.)......z.)Z..~.....Z..~.U........U.
.a..0.....a..0._........_...)........).....[....#...[S........S....j..
....|.j..W&.o.....W&.o...[........[S.k.....&u........'................
.\;.......\;kA>.....ZkA>...*........*.........-...."#.C....1"#.C
.97.......97......................4......A.....8..A..bp.......bp......
........./......../....h........h.................T........T..........
... ./s....4 ./sn.......rwYZy>.pq....L>.pq................R....'
...R.;......C.;..|..h....,|..h4h.(..../4h.(&........&....$.9....".$.9A
Kp......AKp....F........F........9....x.!...../x.!.~......./~...m..!..
..*m..!..'........'.........&......hG.......hGAGiO.....AGiO.......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/QrQXYdikSjRrXy_HcAZXyWr6KLoxu5WFidPMEx_OalQ=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
.l........l..4H.......4H.#..p.....#..po.{......o.{.........%.....`....
....`...8.%......8.%u.h......u.h..<.V....p.<.V~. ......~. .#[e..
...>#[e...Y........Y...<"....&..<"..TE.......TET..F....8T..F&
lt;x......><x....}........}..>;m......>;m.B......B.B..%..
.....%.. r-7......r-7.#.b.....,#.b....8........8.8......#.8.....o.....
...oe'......ne'..._........_...KH/......KH/CYFS....&CYFS...H....}...Hc
.}8....qc.}8{..K......':.UV.......UV....|.....?..|.~.......}~.........
........=J.....6.=J....Y........YKpQ.....lKpQ..7o.........Z........4..
..:2/ .....:2/ ...............[!.......[!........-....#_0W.....#_0WB..
......B....0........0..!RX.....?!RX.=........=...h.>......h.>...
[email protected]...=......................
.....{v ....'.{v !.M.....G!.M..%Z,......%Z,.............&.........O ..
..o........oMq......<Mq..]#.......]#..'.<:.....'.<:2Y......82
Y...0T=....y.0T=E.<......E.<...MR.......MR..nS.......nS........]
....y..7.....4X`..Hqb......Hqb...X........X.G......'.G..D........D....
.M!.......M!;.=G.....;.=G..............*9.....&.*9..$........$..H.2-..
..5H.2-...k....h...k.?~7....5.?~7...&........&5f.......5f..S.k........
......4.......2...........=.....).3.....5..\.g........g..B=.w.....B=.w
...........................z.b....3.z.b........Y....4gZ......4gZ..UW..
.....UW..A........A....lI.......lI...6........6A.......!A...{.3v.....{
.3v.v........v..R.xl....%R.xl.".N....-."[email protected]@w1.n
c.......V................/......../....).....6..)...............#.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/qMClo-a6ikkoEk0PRMBOLlihKTwko6nmtbIePa4G6cE=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 2489
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 03:21:01 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54947:4:2474.>~...>~.......m.QZ.5.......c.... g.ki..hvA..hvA..
^....^...........|.F./n...:g......<6I....M....M...N.I..N.I.`~.5.`~.
5}..7.}..7..DX...DXD..2.D..2.x\...x\.k 5..k 5............(S...(S.5b...
5b.j.k..9iK........"....".f......,...7....7.....................u....u
q;r..q;r.$@i$.$@i$..R....R."....".....................9..R.9..R4`D&.4`
D&. =... =..V....V...v.o..v.o.}d...}d..P.\..P.\..:N...:N..............
.......-....-...@....@..................\....\......S....B..ea...ea.~~
...~~.2.K..2.K..m....m...7....7...L....L....s....s..J9...J9.~..a.~..a.
........../..../.-....-...{..K.m@R.|.b..|.b....................&....&.
.y....y....8....8..q....q...QV...QV.....B....BB*l..B*l..M....M.....r..
..r7.(...Kf.|..1.xn..O..d......]QP...T....T...........'D~..'D~.G..:.G.
.:Rx. .Rx. hh^..hh^.Q....Q..............................7....7......K.
.W.-...........3.^$.g.^$.g.9....9..........rH.q..H.q.............^....
^}....}......:....:.UH...UH.6.H..6.H.B....B...=-...=-..7I...7I........
...(o...(o...6....6...B....B...u....u..b&....4!...5/...5/>.n..>.
n.K..c.K..c.........Y........V..`..He....}. .pO..t......%....%&2.J.&2.
J..u....u.>n...>n.....X....Xbs.].bs.].j.4..j.4r....r...2R.|.2R.|
6n.7.6n.7..{}...{}.........Q8z..Q8z.......4I..d.r.4V.....?/..aDuI./p.=
...k.....f.......2..s..mtu..f.. ...........(.....................1.3..
1.3..e....e..0.{..0.{.M3G..M3G..s....s.......q.....5j...........6....J
.8.N.....m."5...f.7....7...0....XU/q....q...p..J.p..JC^s%.C^s%...A....
Af[!..f[!....7....7.a....a...........^....^...n'._.n'._.-]...-]...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/Ze8uEZAqHBtd2fK7UD2v7hiXbNOJV9Huo6Wkh5s7vRw=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 533
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 01:30:37 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54946:4:519.O....O......#....#{1f2.{1f2.Vxa..Vxa6;=..6;=...E....E.".
...".....~....~...Qw...Qw....................$....$..?u6..?u6.Z6...Z6.
...>....>.).$..).$5* ..5* ..f....s.....b.....t."._......$.h=.."5
..."5..[%...[%<3.a.<3.aL....L....JO4..JO4M.0x.M.0x.........W....
W............H|.8.H|.8...[....[.(.U..(.Ub.M..b.M..#....#....,G...,G..*
9...*9..z[...z[...v....v..I....I.|....|......3....3...v....v..4....4.'
.D .'.D :.u..:.u....;....;].H~.].H~...!....!..@....@....`....`...0....
0...S....ST.s}.T.s}..c}...c}...4....4..k....k....e....e....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/oweDFIsK4aD4_rARvw_DFsYTnCHgAwkIyO-Cr1Sggq8=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 685
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 01:10:45 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54945:4:671...j....j.;..8.;..8.X....X.......!T. .........{.?.......%
.q.q..[.*.;..LUV......A....A.........&H.z..H.z.W.i!.W.i!..........0...
.`..'....'.....nW...nW7.(..........yl...yl..@"TK.@"TK.x.6..x.6.=<..
.=<.b..=.b..=Y.....I.4.6...#.B.B,.. ..9.u..~..2F...U.4`^...`^.....z
.dAZ......8....................... ........X.........3E.R.3E.RY.....E.
..gR./gk}......x.........O.zJ.....>,...PD...PD.Pa...Pa..........:.N
D.:.ND..................&.......z.U...i....i..W....W...._...._...@....
@..Q....Q.....]....].ht%/.ht%/a$.s.a$.s..Z?...Z?,..@.,[email protected]%A.
.l%A...B...g.O.0..XC|4.o].U...q...'....'.o....o.............-3...Z...i
....i.{..K..N....t.S.k....;.5Zi..5Zi....*....*.J.{..J.{.........>....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/e05WcOZMZtbisUzbwMUQfS06o1PHFsMK1SygyXrIjls=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 1084
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 00:10:41 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54944:4:1069................L.....J..:}Of.....s....../../; -....F...
.....i.....".,X?q....*....*...........R....R...f...?..%.'1...'1.......
...Y.....v..9.!>'$I..'[email protected]@a....a...Ifc..I
fc..v....v...T.O..T.O.M....M...0z...0z...4]...4].z)...z).X..S.X..S.z..
..z..u..#.u..#..w-...w-7.(......lq1OO>T..;.B..D.A...)..K.O.. ...U#:
$......v....v...Z....Z...........SC..,z.8..AY.|.*V...*V...9.....S....s
....sSs...Ss....;\...;\.j....j..^....^..........e_......Jr.F....V.0...
p1.W...j'............9v.....#k`..K:[email protected]..$:A......
...........28...28.S....S....6..Wc.ub..0....\.....fW&.N....N.O....O...
0...b,...`.....................|.F.hF.Tv).....K.kI..rs...rs..Y....C $.
....^....q..]..}.]..}...I....I... ..s.....[.nB...nB.P..9.P..9*)|..*)|.
.2c3..2c3.6.O..6.OKd...Kd...........l....l...&.......f. ...-...G2...|.
G...E.@*ZS.k..T.... M[..h....h....j....j9....9...'K.e.'K.e...L....L<
;.Q..<.Q..........y.x9.y.x9...l....lj.k...[...&....&...)<,..)<
;,Y.o3.Y.o3..=....=....z....BXy..n..X...........@[email protected]{..(..
B....hEXC|4.... .,.j..,.j.F>...F>.!h...!h..[h...[h......
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/0_r7h7C_8wmcDtCoyZDTlAyHpqloSAKBngEZmJkLijc=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 1293
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 22:40:22 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54943:4:1278....(....(..R....R.Q.!..Q.!.....)..j..gW|V.&...\..B.9G..
.c........|J.W.|.1#.ty\;...(..#.a.....9i\.9e..Y}..m.$=............E..C
B...O.1.*8.h:..M'.X..'.............[......ap....n(.22....../.q"..v$..u
.~....~......<....<jiM..jiM..f.........._...._.........F~k..F~k.
Y.........~Lh..~Lhr....r.....C....C...Z....Z....<....<..........
.Z....Z...r....r.v..g.v..g..Z....Z.".]..".]....]....].uu^..uu^m..}.m..
}............P....P............b....b..........Y/...Y/.7.(..^.....[.'.
G.3J$.L?.r...._..J.x`..........i....i............W....W.............c.
...c...-....-...0/U..0/U.Y.Z..Y.ZA....A..............................v
....v.....m....m.%.%i.%.%i_s..._s..[....[....'....'..Z>...Z>....
r....r........................K..sC.:..C.:............G....G...6..m...
]_.A.]_.A..........8....8...z....z..Y....Z. ...uB9.E.wN.n.wN.nL....L..
.... ...W.0vi_.0vi_.).3.|eg.B..,.B..,\#...\#.............Rl...RliH...i
H.............................:..n.:..n.]....]..S.k..3...m...b5H.E.9t(
.1D....6.*.JT..Z.jW..8.K....*a._.VBG^.#L..V9......'..jb.K.$..)...if.=.
.5sN..5sN..r.2..r.2.......................4DY..[.U..[.UF....F...@....@
....0.0..0.0{....{...l.a).l.a)...z....{J.5.?....?...}.7..}.7... M.;..f
.........mA{..mA{..........9.z!.9.z!.DT...DT..]....].."...."....u.X..Q
@..E.F..E.F.v.x.Xz.H..B..H......=...q....qc.i..c.i.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/F1IyfhgOm8mRwbTEWMWMuzVHUuC8Hgp5YQrngFJrcHk=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 1171
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 21:30:30 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54942:4:1156...........?A...?A.............B....B.f....h.F...vS.4V.S
.4Vq.U<.q.U<..................wNMN.wNMN$..U.$..U..3a...3a?U.u.?U
.u..c....c..E....E.."..V....A..f....f.CI.B.CI.B".,%.".,%...E....Eo.ZB.
o.ZB.sc...sc..........4.]C.4.]C...6....62{.E.....t....t.....H....H.:g.
..:g..p5r..p5r...x ...x S....S...N8...N8...0`d..0`d.LQ_..LQ_Y.8..Y.8..
E.3..E.3...$....$............?....?...........#3...#3.................
.. >N.. >N{....{....y....y..$ .k.$ [email protected]@@....@...]....]...
..................l.k..l.k.0....0..............Z....Z....z....z..05...
05............C....CH..V.H..V...t....tZ....Z...6..U.6..U..........p.i.
.p.i...\....\.o.7..o.7.C.`..C.`.}....}..4....4...&"...&".....p....pouM
..ouM.m'P..m'P..........c$...c$...'....'..D!...D!.....:....:..........
K0I..K0Ia....a....6$...6$...................9..y.9..y...V....:.|....|.
..Iw[..Iw[.........v....7.,...@[email protected].>....>....q9...q9
Sn...Sn..w..~.w..~-R|..-R|..}./..}./..F....F..s[...s[..c....c.........
...........x4I..x4I../'.../'.?=J...!p.....................w....w.7.T..
7.T..o.9..o.9.F.y..F.yE%...E%...-....-..=3.L.=3.L$.x..$.x.0.a..0.a..*F
x..*Fx..........^....^...g]...g].J$.|.J$.|..F....F....)....).........<
/font>....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/I4cHXUB5lw3x_oo_3SLBgGOqm-L0Ppel0n5wNSMEYdk=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 2819
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 21:10:29 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54941:4:2804.<|Uc.<|Uc')...')..-..>.-..>9..u.9..u....;i.
....J........A..-1.....P.,......"6...X.-G...%N.sN.<....(...h^...9.x
...Y.\.A.%......Y....M..gN....,..k........#...C..0..F.5....7.j.(.l....
...J.g....'6.D`.(.*$N...0...5B.Q...;}...)S ...N].e|fi.1.n...>..F.2.
{..A}tJ....r..9.k0..5e.o~.*..4...r....r...................:....:......
......%.g..%.g.;=...;=....1....1............v....v...>....>'....
'...._.z.._.z.$....$...f................;....;...u:...u:..............
.......d}...d}Q....Q...sMNN.sMNN...k....kx....x...'..:.'..:.........=.
y(.=.y(..@[email protected]<..IL<..7.l..7.l...........N
C...NC..I..E.....G....G..........i....i.....8h...8h.,....,.._..4._..4.
v....v....................v....v....9....9...........>Ia=.>Ia=..
.S....w...K....K..9....9..........\.0..\.0..@[email protected]..........
.{....{.."(X.."(X.|1r..|1r...{....{....<....<...........A....A.f
t.8.ft.8...(....(...e....e.P.J..P.J>f|N.>f|N...>....>'3.m.
'3.mZ....Z...[Y.<.[Y.<..=....=............T....T..{.6..{.6......
....E....E..............R....R..4....4.Bb.9.Bb.97.(.......ej..{FR..4.|
..n.W.e.......A...WW.>bnphX..k....k....g....g.zp...zp...&vL..&vLq..
^.q..^K[...K[..nrk*.nrk*.......D.fT.k.&....&........r.k....J}SY.J}SY..
........9.....5....u....u...$....$..`....`.}>...}>...........G.B
..G.B....1....1............`....`|....|...{..%.{..%.L....L....%....%..
.`....`.EB...EB..r .0.r .0..........,X...,X.4.g..4.g.K.O6.K.O6........
..........%....%....0.|..0.|...........t....t.1....1...I....I...K7<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/bPzVXNtCxclsBHuqQnq_VFLS814vJ9YrJr0_ECYF23A=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 1464
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 19:00:47 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54940:4:1449.....S.^[email protected]..'.`..(......Zr......QG..C{tx0.aI...e...
p.t.#....s..<...T..m....`1{\.o..0...h.5kc../._...b...Ru/"...&..N...
1X...N5G.q...."a..q.mnv...b\.Q{..0..E....\.n... ,....O=......:t o.J...
^[}V#B{jA...Z4P-K./y(_.QX1!.w..v10.9I6.;`%J..h....m92..x.}....*.....xZ
xf`..8..b4 ......|G..!.......d....,.....}.}.K.nI...G...x.;... ..|.p...
JP............i....%Hf...... x.....c,.........~.R.,C.R.,C...7....7.mZr
..mZr.f..........5....5.:Zh..:ZhY....... {t.\.{t.\...H....H8.6<.8.6
<<..O.<..O.CV...CV............81...81..5o...5oT....T......W..
..Wg..Q.g..Q.........A.h|.A.h|..........0...................e....e....
.....2.Xt.2.Xt&..H.....h....h...7.(..8..<|....>........c;.X(...X
(..d....d... )... )....-....-..F....F..!.n.k.....f.:2t..:2t.F%.".F%.".
.RW.. ............ip...ip....8....8.9...tX.. ./.. ./.l].s.l].sym...ym.
..?~7..?~7.{xt..{xt...................-S...-S..Hil..Hil.-n...-n..BN...
BN............5^...5^.......D|.WX...-....-............6..!.X..G.a.....
e..-.5...........=.<.w..<.w..........r..k.r..k...&....&Y.....).
....'[....f....yZ0.d.*......(....(... ..LT..,...r{...r{.6..y.6..y&....
I...;....g..W..I$...a.Hl.a.Hl8.M#.8.M#?.?..?.?.M....M............,@.K.
,@.K.h.Q..h.Q./^p../^p}|6..}|6.s..[.s..[7!...7!..x..t.x..tP....P....-%
...-%....v....vs....s...S.k...u....x8'3X..'3X................Y.....\..
..\..)|...)|Y.h..Y.h. .... ......z.....[....`l...........4.j.k..D....f
{8..f{8.t....t.....;......!....d....d...B...E.L....XC|4.g....d........
....Gcl..Gcl..y....y.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/upbUSLkFFgKYbxZEi1SDt8e2LlKATdvoZ-bwaW7Zj_Y=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 2617
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 17:21:00 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54939:4:2602.f..;.f..;J.FV.J.FV.v91..v91..............r2...d........
...,#./E..........E....E............w..5.w..5...........W^...W^.b-...b
-.E..r.E..r.C.E..C.E.H"...H".I.|..I.|...{"...{"j.k....2.N.Xw.N.Xw.f...
.....T........IS..........Be...Be.:....:.............='_..='_^.Yb.^.Yb
...M....MD....D...k....k...e..E.e..E.W....W.....u....u._...._..y....y.
....I..m&6..p$d..p$d/.y9./.y9.N._..N._.1b-..1b-[....[....=....=..,N.#.
,N.#S~:..S~:...c....c.$....$.........$.*..h....h...^....^.f..A.f..A.WL
5..WL5/..../.....[....[.jo6..Jw..*]l..*]l............~....~. .k..BC...
E.0.n.X..n.X..._...._.G.p..G.p...E....E9h2(.9h2(.M....M....~....~.].I.
.].I.W....W....T....T...u{...u{....$....$$?...$?.....:....:..w....w.B.
.}.B..}.z....z.... .... .#.. .#.. 9....9...V.z..V.z..k,...k,.h.V_..|..
.<1j..<1js2...s2...qLA..qLA....................=....=.s....s....
K....K..B..S.B..S.Q.m..Q.m.Z?9..Z?9.O....O....>....>...........@
qr..@qr)....)......3....3%.c..%.c.<{...<{.....^....^...4....4..y
(...y(.'....'.....h....hk.J..k.J.b&...<v....^.r.....:*.DZvb.t.w...E
.k.......8.]W.{0y.W#..E..f.....T.%.D_MH.D_MH.....U.{...........H....H.
....^....^..K....K...u....u.2.P..2.P.............0....0..}....}../R...
..Fi....i....,....,..a....a.....-y...-y...m....m............D....D%:%Y
.%:%Y.}l#..}l#.i....i..#..".#.."......T/....V*P...*P....Hm...Hm...B...
.BG....G...U}j..U}j..N.g..N.g.]o...]o.<......h..7Q}..7Q}.....b.@a.:
....:....6.......U....U..g....g..............K....K....X....Xq..<.q
..<..a'...a'C....C....^....^....................S.n..S.n.&....&<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/xxhx3h0IzWuRG-tiUmGAPmqcSkzL7CgGn2_WLc4XndI=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 906
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 15:50:41 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54938:4:892...Kq...Kq..........5P...5P......|..U.v.V....oxUs3.s.."n.
'..s.'..s:h...:h........%.;G..4.G..4......My.j..v.j..v..l....l.5.Z..5.
Z...........V^*..V^*Y.....T.g6......>....f.yr....J..u.......X.. V..
'"....X.|c.cw...cw...H....H............|t...|t.........".``.".``6.z..6
.z.2B.~.2B.~..6....6..].9..][email protected][email protected]:.-LpM.
.LpM."yW.."yW.V..p.V..p..P....P.u..Y.u..Y.@[email protected]......?..v.H..n..
.At.....Q....q..w.q..w|....|....Hil..Hil.[....[..2R.|.2R.|.{."..{."...
..;Y...=G,..k.luz"&.uz"&...............n$..5z.Y....4....4............7
o..6.1...Hk...HkY......W&...o....o.5"...5"..dO&..dO&&....v..a.,....,..
......B5.7....7.............0.....B..ul...ul.S.k...6.3O....O....:.W..:
.W,....,...sK.l.sK.l0:]..0:]..@....@..\zf..\zf...... 5$....z....Q.....
.............j.k....PU..D ...D 8.E..8.E...aZ...aZjs3..js3..2....2.....
........................J6.A.J6.Al....l....;....;...eO....S...Ca...Ca<
/font>....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/GgQ4WSYwIL2jgsYgnfOjR0qqfePaXmb-DX3XOtsW9Zc=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 591
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 15:10:34 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54937:4:577..z.).5HKj=p.........c..K....f."....g... _..7a..AY...~...
.......KDG|f..;..:...A.....L&;.Z....I"..kP..j.....U{w..........`.K.u.&
lt;q.Tn{w.].-l.......:Kn.r.....J."MV..{10.......r.lc.J...J.[.iz...5...
G......v..Q....s..VK..8..i.<P..2..}[email protected].....]=...E7v
@.L....n}...].......5.J..0.d=:..s.....h....M..YS.:..4...Z.z.6..iO.Z...
..._...Y..........5.e.P..w.n1...:....V..t`*..h....i...^..[..MG....M#..
.}m.z(....<l..y.1{-..8.j=.%....pmu.T..?.A......]@\HfYT.#e..d...n.Ym
.....a.w.z.._.....n2/.H_..[....hd...%.K;.w..U. .....5xw )..n."...=k...
.<^....p@*.Q.......;6r...c.M}.....6...c.....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/Ns_Bo4UvBU6hqyUFEDzll7JPYJ-SQwlpuXzX7KRxY_Y=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 2322
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 15:10:30 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54936:4:2307...........R....R...........SM.%#?.sx...<]9._....:.L.
.......}...[....z.).....u.d.....jECQ........F..Y........ m.).S.%q..|.{
.;...'.YE....!PJ.C....p&Z.......Q.E2..V.W...g..HR...R.j7.[...[...C....
.".T...L.FF(.6......sV....I.D..)Xl..h.p.....]?..3..g.....F0C..(...9{--
G?....ID...j..d....d.[..y.ej..$.a....A....h7....H.g....g.....<.....
9...o-T...6rL.P}k...a..ps1...;..?C.u.j=.s.C... -!.d$.J.X..I...........
.....i...S.p.{S....9..:..N..ho7#....I.5Z...p].t..5. *..X.M.. ..X.L....
..W.F..O...?.>H..nN..Z.=..O{...h.. ).%T....]...f.X..Q.>..b......
...)..D....A...L..RXT...f#I...ub.U...=(....{...t`m....VQ.w.'I..kp...Q
.......b x.m,p.\.)..W.qQ............>..t]....U.........8'.y.p......
....x..g.T....c;RR......EB....S.L. .K..(....l8..<.F _.q..yI.;..`s*^
).]...(g.;.l...Q.v..]3H..|c.`...L....pe.....J..S.hu.g.6.!.:.....u..;..
.X.(<.]W...*u.(.........M.p.C.R...2..].(_P.}..0.Z3.?.V[...`.v....n5
b....=......O..8....l..)@}.lr.^.b..xP.?....:....w.N.*...p"...JI.dq..s.
...........P.. ......F..B._.-.L.v#[email protected]!y..6L.{....x]z..K/.19.
g.]!.P9....u...]*..>ex.E..... .{.....>...i.["...a.q.....~~.].Z..
p.e.) ....@...*.F9.*.F9........./..F./..F..................Y..../...#&
lt;...#<..$....$...,....,...:....:...P.WD.P.WDc....c...(7...(7.....
........=....=..Q....Q..5.S..5.S.A])8.A])8..s....s..........t.h..t.h.f
....f.............(....(..l....l...HL[..HL[.;JU..;JU.U".4.U".4..j....j
.n}W..n}W..r....r..7....7...7.(..-..{v... .(.eT.y..L.=,.....$...S.....
.......B....B&....&...]....].............|.F......_..0....0....C..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/r26WN31Wqw5U0loQzRbt_kZT_vWxHj8ekoP9Sdr3ZIU=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 2724
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 13:30:24 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54935:4:2709.S..[.S..[..R8...R8.e? ..e? ............E....E}.=..}.=.G
..Z.G..ZSd...Sd.....~....~~....~........ms...........w.~o.w.~o...%....
%............O....O.f...)..0....E.b2.E.b2>63 .>63 y....y...W..p.
W..p..."...."..........S-A..S-A..Q....Q..'....'....[....[..#<K..#&l
t;K..[/...[/.a.Z..a.Z.s.E..s.E.j....j...n...X..Lj..gsbC../:P../:P..yZ.
..yZ.P.Q..P.Q.........4.}..4.}..Ok...Ok....A....A..L....L..'.u..'.u.Lj
...Lj.p..>.p..>.Y....Y............\.v..\.v.........ID...ID....iU
...iU.n~...n~..F....F..|.B..|.B..J.c..J.c..........*....*..~G.,.~G.,..
.......o..?.o..?.1....1..u\.#.u\.#.........#/...#/.....p....p.]7...]7.
...H....H.\....\.............._...._..,....,..^1~..^1~..c....c........
..A"...A"..ytDx.ytDxj.h..j.h.x..<.x..<...2....2..r....r..LW<.
.LW<.........R..).R..).)%...)%..9.s..9.s`Gu..`Gu..........""...""..
"..n."..nt[.F.t[.F$.&..$.&.Up...Up.............\....\..D....D....t|...
t|O....O....j....j....r....r.o.|..o.|..xm...xm...........S.|..S.|6....
6...:.j..:.j.}....}.....dc...dc.3....3..x..(....|....|s...|s...:."..:.
"...l....l..f....f......................[....[........................
...V).-.V).-.!....!.....3....3..........s"]..s"]b&.....v..;....J.o..zQ
?..*B..a..0.u.....E....v..7d.t.1.d.Ab.:R`n..R`n....1....1.9....9.....[
....[z w..z w...F]...F]..........s.5..s.5.E....E...P.M..P.M..>Z...&
gt;Zy9VA.y9VA.4Fa..4Fa7f3..7f3....F....F./..../....BH...BH-....-...x..
..x............7..t.7..t.G....G..\.a9.\.a9..qZ...qZ .ls. .ls.2.[..2.[.
.........o.g..o.g.!.u..!.up....p...1Pr..1Pr............s....s....~<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/QE5wpfxYC4_ZkRiYpgWBMaPIipoEvJ2MAg3pKTv6kqE=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 641
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 13:10:32 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54934:4:627.s....s................... }E!.Z......k...A....A.'..l.'..
l..2....2.a(.!.a(.!.....$X..d.. .....csp..csp7.(.............<....&
lt;j.k......$..Y........,.......$"...$"...f.........................l.
...l....4.$..4.$...........U....U.zeK..zeK..9.;..9.;............ .H.|y
...A\{....=..t....Q ...Q Q.<..Q.<.[....[.....%/...%/T.j..T.j.{..
..{....Yy...Yy..dIY..dIYi-aV.i-aV...%....%w..<.w..<.a....a..x.X0
.x.X0<....<...{.p..{.p....~....~.M....M..D....D............<~
...<~..KI...KI...|.F.X.t.9.W7.9.W7$B...$B...a6u..a6uw..O.w..O.9....
[email protected]|4.W.d.Uy.L.Uy.L..........."....".w4.:.w4.:O.4..O.4..D....D......
.....X*...X*..S.k..7....1V%..1V%6-.r.6-.r....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/DFBYtvq866rJuHxVyLHxF65hHot39cLoMpvzYSy1k7o=.chunk HTTP/1.1
Host: cache-kiev02.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Content-Type: application/octet-stream
Content-Length: 200
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 09:50:20 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54931:4:186..f[...f[....g....g.6......5...I....I..B..y...I..3.I..3.C
....C....6....J.w4.:........E.e}.%...9r...0...n.ob...G....Gv....R...o.
&..o.&......j.?...a..4:....0....0...........RW.c....nX...nX.HTTP/1.1 2
00 OK..Server: nginx/1.6.2..Date: Fri, 01 May 2015 04:21:34 GMT..Conte
nt-Type: application/octet-stream..Content-Length: 200..Connection: ke
ep-alive..Last-Modified: Thu, 30 Apr 2015 09:50:20 GMT..Expires: Thu,
31 Dec 2037 23:55:55 GMT..Cache-Control: max-age=315360000..Strict-Tra
nsport-Security: max-age=3600; includeSubDomains..Accept-Ranges: bytes
..a:54931:4:186..f[...f[....g....g.6......5...I....I..B..y...I..3.I..3
.C....C....6....J.w4.:........E.e}.%...9r...0...n.ob...G....Gv....R...
o.&..o.&......j.?...a..4:....0....0...........RW.c....nX...nX...
GET /chunks/goog-phish-shavar/PNPgF0Jh61aGCyqcVnEpeT5gL8KFscgS6OjPTI44wis=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/PNPgF0Jh61aGCyqcVnEpeT5gL8KFscgS6OjPTI44wis=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/DaxhlnrV0XFnHcnQXoIcYI3Ok7env3ziAM9YJA0w0-Y=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/DaxhlnrV0XFnHcnQXoIcYI3Ok7env3ziAM9YJA0w0-Y=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/HTljzKj4oCu9PHBzGXK_dMaJUzy_2N0eWMp9W7Zt6QI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/HTljzKj4oCu9PHBzGXK_dMaJUzy_2N0eWMp9W7Zt6QI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/m9zSmPnZl43F61hsLKfueuH6VwYE7gGXeYYSB-pypy4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/m9zSmPnZl43F61hsLKfueuH6VwYE7gGXeYYSB-pypy4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/ALWeV724V9w89dwuc3ClyOUZxXY9wArCzxfS4TYmikU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ALWeV724V9w89dwuc3ClyOUZxXY9wArCzxfS4TYmikU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/-vBQWF0p7_3PTuvUELHd7TmHz5DAfYsfy0VG-d6aB3Y=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/-vBQWF0p7_3PTuvUELHd7TmHz5DAfYsfy0VG-d6aB3Y=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/jirNZVS0n4RradSHkZnbeYzGa2hV_bkuj5A7qemLfn8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/jirNZVS0n4RradSHkZnbeYzGa2hV_bkuj5A7qemLfn8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/LkU_PzHi470rWlFlDx6vPOMdSCxN46QTXhBcM_R_KXc=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 26
Connection: keep-alive
Last-Modified: Wed, 22 Apr 2015 16:10:20 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11305:4:13.Z.he....DZ.he....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/ihvaXT0zxWqt0I1IIj7mFRJdHKF0OMXfAKRwiTwrFnk=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 52
Connection: keep-alive
Last-Modified: Wed, 22 Apr 2015 01:10:30 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11304:4:39...J....................M...#.:.............
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/y89AXj6vwBtPw01Gvvljk0iJ7w5X_ddoWa5ftRYPgU8=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 6604
Connection: keep-alive
Last-Modified: Tue, 21 Apr 2015 00:50:24 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11302:4:6589.Qz........b..LW.........#.....l{.r*.a........U....F....
......N........y=..D..........,.} .........x\..........{X.........|U..
.........j.Q..............F.$..........&3.N........#j..k......x.a.%.!.
.....[.C......\.......3p.........U...3..d.....B|{Q..?1.........e......
..>....L..........Tl.........dY....#......l.....D.......d$..$......
..l....7.....V.]h,1........V..U...........h>.K......=Xa.......a....
....?..F.......8....'......ykR.m...........6;>........=O.S.\....../
.......L..........{[email protected].....
.....I..........$...%3...........$y.9.....i.j.]. .........a">......
.F...I..,.....>z..C].4............1......,..iw........j.E..........
C...........}.2y...%......"Z..9%......T.../.........d...c..........f.;
.......670X...........P.......!.....#........a................w.....2.
(......hhM..mC........i...........{...........MZ........r.r.L.........
............nD........]s....<........h.K.k............p......,0...&
gt;.B..............j.........1..i^.......J.s........s.................
........E....~y.........$...m.....V.m./..M...../..M.~........~..[.....
..........%.....g........E..A.M9.....zZ@.>........So...&..........Y
......A'[email protected].....|.".9.t......,*g....@......>7
.q2w..........$..)......%Y...|\......od|.B........K............0xU.n..
........[..]T.......b:..A.......~>..Dg......FO.V......~...,g......~
.z...u.......)..6A.......J.tH[^A.......Y].........u.8Y........ZL9.....
.ZL9..=.......T=......]............b.....R.............{......._..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Jftr8wgkwo56H9yX6nJePhy2DKlA48l3kn4aJ2EZ6DY=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 34
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 07:10:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11300:4:21....3......;......\.......
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/xEztrZ_otV4HLVyDpTFlDQBGcxzWLzBBBm4NsdzFEwc=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 716
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 00:50:27 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11299:4:702....S.....e.......N.............o.....1......a. ....?....
X.Z.......r...J.............j..........>.B.....,.......s...........
....._y................7.......M.S.D.U......0...........%.G..#.:......
.i..!........I,...........M,O.6.C......#W...d......kJ.....H......*.v..
..s.............?....Y........V.......U..m...............4.........vF.
......(...f.......T....`.....g.N..\.......,.j...`?......./...1........
t...h......u).?.&-<.....k..F.........B........e$l.....4.......h...M
..........Z....T.....................[}........y.......c.U.......(sxC.
.DL...................')...........d...............8.......S......-...
...............0....._.z....G.)............4..JG........C..-[........j
..........x.^.............
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/iux_0kYqwLpBad2nO9MehhPZp_IurAi8AdwiLiyyVyY=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 8555
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 00:50:27 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11298:4:8540..........)........0%.....!<.q....w...............Zo.
FP..........8...........TA.LW.......!........2.|....-..Sl2........OV.=
.MB......<B...........z.]...._.}&[........E21..........O!.^..1.....
."H...^g........&..1.\........OT.."[email protected].
.%.!........@.".........Y..=.........V..........y1....Gz..... Xi.-..A.
....k7...........g.\.-m.......Ys.%..?1....... y............w(.k......b
...O.W......O.W.J..I.....3.J.....oB...........Rt ....?................
...4......9=.........L....{............_......D......1 .$w........h=..
........V.............m....N............................e(D.=D.......W
.......a,c.......................h.... X.^u}H.........S.........c..DE.
#?.....................\........?".e........5.....ZG.!.:........D:..P.
......~Bq......&.....Q.......?.6k......W;....H............iN_...;.....
.E.....L......C/........4LR..P.........2.!H......O.<.z........1....
..]............6E.%..xx.....bP".8<........v.....C.......Zr.........
.#.N.`p......['......8.a[..........1...............2........8.sU."r...
...."r.$y.9...............{..r..........-...............B">.......%
.w....'.....*1..$..m.....v.FD...l).....~.........y....)0.........e....
J..J......|........".....&..............j.......-.B........Z....:.....
.g|[email protected].......%..............}............w.c..
.....M[.......g\.............. ....h..'8.....q.........Z.......$......
.......K.......w.........[.....,.........)....K.FY............m.M.....
..Ot....d.]..s l.....b .....=......O....._..... ....i..........3..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/h_xpPnaTd4FhVPIkCA2nensqXe_s9gRnukwHWL_1IIM=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 26
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 00:02:12 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11297:4:13.'.Ix.....'.Ix....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/NOmm6qIJGzLneEHWSVjp5adubXmIgV9QvN8DqpIxpMg=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 4686
Connection: keep-alive
Last-Modified: Sun, 19 Apr 2015 00:50:31 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11296:4:[email protected]......=......J..............1.........
...Jb..........8[u...f............a.......a............O~...a......$..
...f.....b..1..aY.....t.I...E.......#.*..w......mC[-...A.....;.2...7..
..................rC..o........uZ#.KA7.......=4....a............\....g
O.......r...........o..............@......_Q!...........oL.)..........
J..:1........~...e........e...X...................f|x.................
.....Wk.............4s..L.......9...................CMU....u........@.
...u....6A......=.f..:........#.............4R....o..y..........s.~.=.
......T..O.....Ni......;.............F.....u!.............uH....).....
..90 ..i..........`...-..........g.7.....$....\........y.X...s.......{
).. b.......9a..........v.............;...IE.....}....Z.......q..w...!
......Y...^........^...%.........=...?1.....e.^;. ;n......)...........
.M.E.L.......p..b.U........;R...........B...B........5!.....:s........
...3c1......9.....'.............b..^.....P...e2......;<j.....8mOw..
..........D.........A....... .g]...D.......R4...........X.....4ZNC....
...`..^.......Mt..........a............G=.%..$........l.. .......ZV...
.... P...4...........2.R.....h=.....2.......AC......................J.
..\...........F9......-m.\.f*......<..2.........._...4........VI...
.M......'.t..................E...m.......qcm.....b..4......e.....>.
.i....>.........8...,"[email protected].......
......7........c..5i.....[..E.~.......TW.h.Ay.......u...u.z.....W.u...
.......d..P.#.:...............................17.......N..........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/PNPgF0Jh61aGCyqcVnEpeT5gL8KFscgS6OjPTI44wis=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 8475
Connection: keep-alive
Last-Modified: Sun, 19 Apr 2015 00:50:29 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11295:4:8460..mPS......i..P........%.B......o.K......Z........v.....
....D.%b....D...LW.......j'......LW..{x...........8........?...=.MB...
...F......oq/&.........M...?".e.....O..Tx ...........................v
.........>9z.......<..b.........I.e`.v......x\8.;{.5......\.g.%.
!......jx.....6.H:..T........4m7.L<[email protected].#........m
.wE.Y.......2...3..d.......]..%........%..(.k......C.w}........'.(....
...c].-.b......b./.)h.......T.>T.........?.1L............w.........
!"....N.......4t&&b7....... d.X........h;........L.#G.1.....>....=D
......5.4i....c.$c].]b.....m...mnb.........L.).......u[.[(,........Md.
.#.......B.|...nB.....`f.c!.:.........#..........P......az..a.r.......
...............h{'/I.....9U.Rji8{.....Hc.W=v........z..'.........(.aS{
._.....K.(8G.........V.W..........?.........1.....q..,`........,..q...
.....L5.....u......|. C..........M.Ba.......'.#............*.....M...a
.........A............O.YH3.......H3..T..G.....d..P...H......aC.....
...qe.l.4`..............#~>.'.........J..G............?.:o......#..
o^J......... &$.......&$..$..m.......6.....$......|........|..y......C
.n.~........P..2..................%...2_.........Ix.Zu.......?...0)...
..{t..S..?......f...............T.#j.......4..........=SB.....d..H....
..d.......~T.......{....nO^.....e.z.......y...... y.....}.^........[..
..~..........C.......&....cBa........8....<}.k....{jv.....R./......
.]......g........9......Ul.............*P........dl......r.....(..g...
...{......s..{j&o.....F... 9.C.......V.x..@.....$..[.....W:D......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/FHvKorYRa9bSJlD4xPUO7BZe3gbwe7hXGscMWGeHqIw=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 295
Connection: keep-alive
Last-Modified: Sat, 18 Apr 2015 02:00:12 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11294:4:281.L.7......%3...............<SER......<.............
.Y..$.-........-...H.......7`hw..=<........UFa?..............W..8..
...t.n.....c.[.....g........f..............v.O......?.....8..W........
........R..B......n...........1p..:;z.......,...............4.Z ......
............}.........J.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/wZBd-e3nlAYWe0lPx6hvMHNc-sDwWwuhlIin-owxthM=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 7050
Connection: keep-alive
Last-Modified: Sat, 18 Apr 2015 00:50:28 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11293:4:7035..U......................S...../"B......,E....N.........
.1.]......tv......b.............m....._..!.R........R.....7.....u....=
.......w.......na.............<.............0.....}X...?1.....x.H..
.....0;.......[.........J1(..L.......E..x.........pR....7&.....y......
g.....*..,.....f.y....H.(.......E...........L......6^v...Ho.........."
.......I.....C......A.b'...l.....P................v.(.mN......... ..~.
.....<.E...........'.........u.YPZ...........N.......wR.._?........
....xx.......O...`?........L.........Sa...X.f.....)....a.y.....u>..
... .....!.....td.....4..W..*........*............................r...
.......-.F.......UY# ..fM......O ../W......@...................._.P...
..jx.8.....y.................a....Ir;....l^.....^.......'.......k.....
............;...._bf`.............O.G....Y.........ud.....D.......*...
....*LJ.............0.'.......&....s..........h......r.............zs.
............}t.Q.....e<.....}.L.P....U.%D......E......".........R..
...........m:..............-........O.....E..i.....'.,....e..*....8.?.
.....K6;[email protected]...............=......i.Ib....vDKS......
d......U;.....Ry......>..a......b....g.S.........,............)....
...$.\M.....H.3.....a.....u.`.y.....J.n...............).....b.?......u
`....c.mG....8s.........q...g..Fe.....q.e....I.,!.....r:.....s.......M
&|G.... ..F...h.:.\............E.v.....M.......H..........$....c_4l...
..........Zi........A....h......u9X.'....B..2.............%.q.........
...jiZE....\.\.......c............................>............<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/p8jCP90AhLl5ufYMynxaluNFR688R-dqD2Twp15_Jiw=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 10796
Connection: keep-alive
Last-Modified: Sat, 18 Apr 2015 00:50:28 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11292:4:10780.Qz........|........H.P........6.......)O.......~.C....
$..Q......1i.........k .U.............).k=.MB....... .8L.L.....Qa..?".
e.....'............D........Y......C;.y6............).GM.........{....
.......K[."......O.tQF.$.......s..;{.5......z...%.!.....].l.......XO..
...........[bK....,...E.x".....2m(}Fa?......s.s.......m#[email protected]..
...p.......^,.-....t..MyI......."....".5.......2.-..A.....1.1....._.p.
n........q...-m.......Ys.%........%........Rt.=(.k......3.j......R....
.?.....l/...........Bj4................F6.E~.........u.5......~W..M6[.
.........U........>.. &b7..................X.........N.C.}.}.......
..nwn......3T.D._I........8$Z/...........[F........#n.(,.......k.1...P
......E........_......dC.k...............J....(...'.).........i....`7$
..6{.......,.X].Av..............x..S.\.......l7C....F..Q.......b.....8
.v....i.).......9......'.S.....'......rG......K.. ....s._.......R ....
..t.....-.e.....H9._......*R....s.........l.......&........I....)E....
..2{e.....9"}............`......d.K.z.......8n6.z.!......].>cS{._..
....8v .........S.J...|....................~......<.I..i43......p.t
q........!.jZ...u......KVS........C........~i..P........4..W.....=.^2.
.......8.sUZ..H......'..a........<...?*Tv............".........d...
.....|..v'.........7}........I........s.........(x....v.....=s..~.....
...=...A.W*.....A.W*..X......O.?.C.&I..........x....................V.
O.....1..~....c^......]........j.......].........~.......b....&.......
"........k.4....B..!.......4....|..G.....qH.......p......F........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/bV86Zyzwrz-XuBUsX9if0otATsDvqxKW9-y0KqjYYzA=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 2385
Connection: keep-alive
Last-Modified: Fri, 17 Apr 2015 01:30:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11291:4:2370...&......qa....................n#..Mu7.......r.=.MB....
..............N....-, .....3,RW..nO.....dY.[S........S....a.J......l..
.T........i.z....h..ZwF8......H............R...x..A.....?W.l.o[8......
.G...%........%..=.........#.m~S...........=........)O..s":.........q&
gt;`...... ...R..k.....,_]......9..j.?=.........x..|.....<.....#...
.......8..W......}............IwM.rw.........I.....-............q..e..
p.......7..q".............X.....dy[.9........t8:r.E.............../.6.
$T.......J..;'.(.......qY.|./m.....b..jE2.J......O.....g..... ...V.u..
....5rG...........n)..P........P...h........#......,/...a.......lm..'.
4..........D'.......V.v..9.........1y......... .l....l........11F.....
..v..."..a.........k.c.......0.f..'[email protected]....
..P.V.........O=..<t......2.....L......-.............Z....,......}.
.<_..9.................. ..R]|1.........]..........}.3S.\....... ~.
....r.e.....Y............O.!......pJ..E..........l,`.......:......u...
..c....`.7......`.7..47.......N...UK.......k..f.............s.......;(
..W...........e|.......-................]X1...H.......|/.........&K..e
...........Qd.|..........4.Z .......L2....[....s.......\....X./.....p.
..-8.{.......Q..............._........y|........................B?..g.
t........b..,T.......,T..zZ.......k. Y&U.....DC.....l............g.o'.
............H.........v.............|BiC.....5.{...... 2...u.e........
........Q........-....NO.7......i.............d....Q./......u4.g......
.. ^...2.e......d%..X........X...SA8......[...........;.......;.d.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/GsrVhUq6AbrMVrXw4Ec6ftazfcF7150-LStN0PdRwKA=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 26
Connection: keep-alive
Last-Modified: Thu, 16 Apr 2015 16:00:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11290:4:13..J........J......
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Z-BZzgdR6niuNm6Dbw-4jp7KnREXbvzrB0Xn2C-u9d0=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 1089
Connection: keep-alive
Last-Modified: Thu, 16 Apr 2015 00:41:16 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11289:4:1074...Ca.....B............f..*.T.x.............~.N..H.\....
..t.q.x]......<..........\.....q.&...1...........L.........h...e...
.....c.........4M.R.................&........I......xS.Z.....X......`.
.t.......x.........>.B......*NJ....B..j..............d......5......
.#.r.............].c......^...........$..._.......m.C3.s........>K.
............~...G............F........O....M..P..............1.f.....(
.'....b........b..X......j#.3.V.........N....d..........E............t
Ja.......b....g......BN<..............R#.......j.$.i...............
.....JG......t.p...1......G^B...D.......,!....b........R...#........z.
...3............}.......Q..*....(.......{m...........5..o.M.......K..`
............c.........T..........Z....h........Xu........r....Q.z.....
...6.....l.#....q.........)........$.Bx......%.2................K<.
......g..8.......n..x.-3.........h..d.......$i.....3HHS.....4.>....
...'....Fr6M....?.......u.9......v.................S....".B.......|...
..1T.7......=......}.C.............p|........e.......!......[.........
.......*........*..1..............X......FZ...........\3.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/S0qM3gmmlTfjfU09iNPuDLKQ-EcgLa4CykvNbVwOWz0=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 8851
Connection: keep-alive
Last-Modified: Thu, 16 Apr 2015 00:41:16 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11288:4:8836.P................[T.$...N.......=R.........M..)E..0....
..;..G.r......;\.KH;#H.........?".e.....vUjW..............*`.D.......J
.n...........R.f.....si..........dKLy...O.....BL.mZ.........._:F.$....
..P..n&3.N........AeG.;.....8...Fa?...............c.[0..n.......t.YT..
.....o!/.@./.....q...?...p._.X..?1.......~......n<.(.k........F...u
N......$.l................c.....c-.*...Y......).e...?......Hxy........
.VG...c........a..u.5......u.5.o/.......'....d.I.....}..:......|.....*
..A.[......^.[..W.D......v.F.&b7.......yU.....M..3.....l.$..../..!....
......r....R......x....vvK........7/2.......]._.....H.A#....?{J.....y|
d3..3L.....{dD{k.c......ZT....P......dC.k.... j.y..N.........L'.).....
....e.......1....W]..Y..o..............s..R..P........e..A......r.M..i
f..........].6.......e......................O.........y...JH(......JH(
................|.........a,`.......|>..}..`........#.f.......J....
`p........]......kBu.a.........j.Ba........$.............w......<.(
1........<{...>[email protected]&..........O........-I~.gm........f-
.xl.......xl...1h.........2.r......._.!.'.........b.=.....&......n.f."
>.......w./.....`......la...hA=.Y......1$.......P....y U......n.H..
.t.4 c....R................................v.....}_&C........9....3.|$
.....V.l.............o.......l......#[email protected]......
.......).....g..GT.......1.....>hH...g......... k~.....".G......7..
..m.H&......`.......Rm.....c..S......R.....A}.G.....V......dq]........
.....2^.C....MI.......8.......Q.........?......................KD.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/ALWeV724V9w89dwuc3ClyOUZxXY9wArCzxfS4TYmikU=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 1254
Connection: keep-alive
Last-Modified: Wed, 15 Apr 2015 01:20:50 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11287:4:1239..f........G&.......R.dL;......dL;.....i..R'..M.....'d.W
.........D.?............!...7V......1.u}{0........1.'.4......(...Fa?..
.......I....._.R....v>q.A.Y......`"..iv.......,.E....#.......8.u...
.....^..../W......&...X4.;.....#jl...rF.....F...\..........D...*......
.6..d^.9......W../P........v....xU......x7`...7........{.O.%......O.%.
..&.......j................<......!..47..O......Cv#.........Y......
.t.(.........7X.#......7...T.......p..........^..V...............S....
'........."U..........m{H........H......Z........L'.]......q4v1g.L....
..g.L..G.......-....#K........B..!dq......(G.....}r!..a.........\.x.Zu
.....nX[Z-..$........u..z......Px.....p...........~A.....h.U........O.
.../3{......;L.....I.....F......lc.....[.........nv.......nv..S.\.....
.g...&1.........(.?-.......?-............]j........9......)K....m.V5..
..P. Gc._......c._....l.......I..............y|..^.......8(...5~......
2..............{......w...^.h.....qR.o..B.........6p.?......H..ncc3^..
...cc3^. @.......j....r^[email protected]........
.............5....m........e...j......L..Z$G........H^..5...........D.
......{...I......................|107..U.......#W..L......R..y..d.....
..;56..E......X....R.<.....\.(4.........Y.b..xr..........fz.\......
,......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/7bOJgy8Hm2aYptpm9nr6UfbSLV0FRWxA8aiAgMmpc3w=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
...=e{.....A.`......../.^9T.....2...J..Z......5}...............K.x....
..K.x.G........B..hP.......hP....w........w....[........[....g..y.3...
....8b....Su......J..Yxfu........|'.4......nxM.......mm....J.......lD.
.............}/........'.......L.............3.rh....Y3.....n.....Zl9.
.........I....ML.......ML..W%........fp,e..............K.....#...Le%..
.....W.....R............Z.....*....I.n.....oa....%1.....G............n
FM,.........9..w....{..,....Cm_....=.....u..#bm.l......(Q..}..........
.ja........|....P......].# cN.$......X}..\........n....j~.....<c...
..3..........<t...........Y............F.#.....,..............I....
................n..-3.......q................h.........h....p......P..
.......4....|.B`..;..............."6.S.\.........)....(.........hY....
...8....yy..............RN......%........Na!.....R.......B.......N.P..
....a...........O.O....y-.S.".1.......|g...........d6..........v..`.t.
......n...O.!......\s3.........h_^.w.?........Y.`.........U.L.P9......
6......g.....gL...Z7.......7s.../......t}.AH~.........i...j.......wt..
mCc......rr.*L........~.>"x............,........91HL.........Lh?;..
l.....wf.*7..U............J......k...............2..........s.hsq.....
...s...&.........;-8.{.....B..............-............v.v.........Z.R
........."........X.X.9y......p.......Q...9.........c.............J0..
...y.<..Af........$c.........U....^......J..g...l5.....Wmc...g.}Z..
..h..kn.....h.0....>Yo6....!..F.......[..................... ......
[email protected].!.g....X..........'......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/RbA3tgllhVw4uoreA9t0dnot91l0x4S0xbKnKLSSklM=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 2219
Connection: keep-alive
Last-Modified: Mon, 13 Apr 2015 01:40:45 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11285:4:2204............s.Am.=...../[|.=.MB...................uN....
..C4.7..U.....`..0..xU.............%..7....uG'........*.T.............
.....K%s.W.....%s.W.6..............f.....o..(.......f"........Q=-.H~..
.......\..R........Brd....Cl..vh..........@m~S......N_..6k.......ZZyXj
.?=.....J...e........>...Wr...............?..\..... %vTG........,A7
...[..........5C............M........Ke.f.R..............O./.......T..
D...........8B.........<..|......k.&L........./.g.'.4......z.......
.?2.....sDY...J........... :y.....'.Y...X........,j.~.3...........,...
.........*........R.....>.K_.......O......O5..^............d......2
....}..........0..`.........Zn&.'......t.....*...../...........c%.....
..c%..|.h........Y,.<t.......j0,.........z.V.....o.%...=......o.W..
.........5.A.......^.......n....`J(K.........ER{D..................)@.
....&Oz.........._..WS.\......;R....2......X.Wc...................s...
..-j......Pu.=.d........B.U.e.,.....(;...(2*......p..p.?......ii.0..-.
......de......X......D................;......4..;.l.K.........\.......
.hFD\..........mE....Y........#4..=.........b#.........x.U............
.i........i............fm..}.9......yNyeI......................x..7.H.
......a&......... ..Zc.........}Im=>^........X....l.......e......}.
........;.....0c;....R.^........D............yuwT.SA8...........2.....
.)[email protected]./.........d..w./......w./...~A.........
#[email protected]..?.....R..?2..,.....~
..\.........f........3..X.........H..|. T....{|. T..K..........n3.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/CiVhTt28sFS93rXevnsokT4ntD6_q3CDbxSad31QNu0=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 620
Connection: keep-alive
Last-Modified: Sun, 12 Apr 2015 01:20:56 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11284:4:606.".9e......@~R..........Q..'.4.....................I.#...
.....;..?G..:.....z.............L?....q........q..*.........#.d.n.....
`. ...xU.......E/......qEc{.u.......h.M.........T..../[email protected]...
......... ........S....e...........w......(..a..`......g......2.....W.
..vh........^..*W.......U.mY..~A.....q.............9d..gb.......J.p'.)
......4.cIaTi........."...l......w..Mv#b.......-V..^......>_b.a..,.
.....c..'.........N...2_.........Y.t.............c8........Gt.Gr.....(
0..j.........1.l.........k..o.@.............d......U...............Q.\
.@.....]..Q.<*.......j/..1.......4w.q...j.....yA....VL......y.Wnt>....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/8XiZtdDw1DowEM1tM0Tx3-7Fu0YDRjcZv3cZUNkgNEI=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 7070
Connection: keep-alive
Last-Modified: Sat, 11 Apr 2015 00:50:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11283:4:[email protected]....%.B......
.....................;!.....]x.S.....................st........1....S.
.(....eAM......=x..............u.;......1r....")..Z..N.....z...=.MB...
...........F....xU......D$-.....t|.......<......-..................
.5................E.,.....5.......b.P.............r.........?.........
....''........x............@|H......<.......X{K....T..H....j.N.....
........PY.O....)}.W....`O......Q...b.........I.ej..k......x.a.%.!....
..jx...T........4m.=........;..........Fa?.......t.n....8..W..........
......#........m.wE...s.......{).%.........=..|g........{{@9.......SG.
...,"......u..'.(.......c].-.b......b./...K...................A......x
.....(....8B.........<N.Af.....N.Af..$........l.&b7....... d..=D...
...5.4i....c.$c.ML.......ML..X..........q..D............^..........q..
'.....q..'.#.......B.|..JW.........0.z.V.........]|1.........]-.......
...3..X............d........B.U.e.,.....(;.....u........c.....|. w./..
....w./....N.........Ba.......'.#.U............e........c.FMT..G.....d
..PC........qe.lG......................Bc............oLo^J......... &$
.......&$..$..m.......6.c{.u......XJ....|........|[email protected]................
{..........eB...y......C.n...z........ `..........%...:..............}
......~A.....cp......o-.... ........36..r^.....a.....W........d.T.#j..
.....4..........nO^.....cBa.......d.......y.....d..H.....;t.....=SB...
..:.R.....(..g....{jv...... y......g.........&....<}.k....~........
s.......Ul.....e.z......d5g......~T....m.V5....R./.... .....e.x.x.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/quCU-R968hkl0cyruELC_MV3YrizvN33lCu_XyBmd4E=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 4732
Connection: keep-alive
Last-Modified: Fri, 10 Apr 2015 02:20:56 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11282:4:4717............s......,E...6.........D...........6.P.......
.)O..6.....................Q.5.j.I...........#...........aTi........."
..............1.]......b..Wr........ %v....?..\....O3qhu........^....n
r......z4.m..P#........x...M........sM........z.a......I....xU.......q
E...z................z........... .suV........lE.........%....I.b.....
.'>.............5.........k..7x.&......h.wf.........hn{3.......b...
..i...............r;.....N.A.....d. ......R.s.............k!.....K.C..
......5....l8Pc.....(%|....||.......................K.......m.........
.....E.r ....4................)T%.....}.......{......<....V*......Q
e..[."......O.tQ..............(^.......7<...b.......r.?.......2d...
.....h......f......VzU............F..q.......n.Z.E........E...........
..pS^..2......&......,.......7......."..f(H.r.......n...w......-:.&.[.
...... .."..;......".HMFa?........m#[email protected];6k........c..
..R......B..............=........G......Q......$k%.....?............H.
.3.L...... ............].............b....r^.........J:l..............
r.@_.5C.........l...8.....U...1........Z..............X......;.;.rw...
....GxF>.........\..9.........a.I.........k..ok........!.c....$....
.Q.......|....@........... `!.............b\V..a..f.....a..f.........
.g]M6[............y......;.....c1............x.....P.....\...........i
.............q...............m........H.......1(..w......0.fM.........
[email protected]}..'.4.......i.d...._$
......j~.'.......V....s.........8$......1............._...........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/htfrrZFnqTgSC2mR0kmzYfL1_FCaDvtToyAQP0dl3VM=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 8645
Connection: keep-alive
Last-Modified: Thu, 09 Apr 2015 11:20:50 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11281:4:8630.P.........~.C.....O.!..........TA...................=x.
....S..(.......1.....st.............eAM.............]x.S......I......;
!...............(.....")........1r.....u.;.1.].....!.~G...........h...
.}.b.$=.MB..........D........Y..........}...... ........S..2.$.......6
\...v.....=s...............)....... )...F.$..........\K......}\K...%.!
......[[email protected].....^,.-...}.\.jyI.......".....Gz....} Xi..
........M...-m...........@./.....}a=.m...I.....J.Ki..?1........[1.....
...].{.....1...(.k......t.8i....3.j......R....uN...........&O......P\.
..........4...f.R........T..,......}..<U.......}>.. ..q......)[T
[email protected].=........}.9.P.".......I.....C.....}A.b'...R.....!...k
.c.......d..I........7>.. g9......)]..........r.H.B.........P.x!...
s..........u.&.....<j......M.j.R..P..........-."....}..'z...}R..)n.
.......Z....O.O....}.O.O..7............|.........y.i43......p.t..R....
.}\..=w./............/W........C@.........`.\........\........hFD\*o,.
.......X..f.......0.&.=.-........k.G..d.....~.r..7Ho......7Ho.=.......
t...J........[.w..[c.....}....$y.9.....i.j..r..........B...}.. .*..u..
.................zg...2.....}..2.....$....9.g.....T..H....m..U....=7..
....@|H.............D........j 4.......&..... .)....)}.W....5.......wl
Z.....-.D......#.G....j.N.....6x.G.....E.,.....5...............X{K....
ACc..............<.......''.....`O........|......?O..............%.
O.....>o......r.................x....7..............1........Y.....
tm....q........q...l4...}U.%D...r.......gQ.r....rv........S.]...}F<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/ZuAPRjyGYJlkTcv1FEc5TDP_4G-_uF22_OMHVkTckZw=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 6050
Connection: keep-alive
Last-Modified: Wed, 08 Apr 2015 05:30:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11280:4:6035.P........[T.$G.r......;\.KH;#H...........xU.......<.
..........si......R.f........{dKLyFa?.......c.[.".5.......n-.......C-.
.A....{.._7..D.......,!.(.k........F....c.....c-.*,/a.......%.T...x...
..(.....q........1(.............m..W.D......v.F.&b7......M..3.........
.r...vvK........7k.c......ZT....9........M...N.........L.JW.........03
.......{r.%4Y..o..............s..S.\.....{.. .......&....{9"}....."k..
....2{e....{s._......'.S...9.....0..&...........e.....D...JH(......JH(
................|.....{...a,`.......|>..........{-1.L}..`....{...#.
f.......J.....w......(..axl.......xl............X...r......{RIj....{_.
!.'.......{.b.=...{.&.....{n.f.........{Ir;....5......{.}...l0....y U.
.......e....o......g.QF....b%-Ef.....n.,...}..:.............s.._.....n
.H...{..[....q.v.G..... k~.....&2t...xA}.G....#.......&".....{U.~.....
J.1.....!........Q......;.......u/.'.....A.H......fV...{3.V....{..jb..
..........p< ......8.....{.".G.......1....3.|$...^2^.C...{.........
QCv....dq].....c..S.....<. .....x}o....C.1....{.......{...-.....Z.[
.......B.......P...........r.6..E..\......j..............g...%......E.
...1......G^B..Bx......%.2..:.........0..........x].......q.&....<.
.........\..~A.....o-........f..................s..I....1..~.....[`...
.{.A.......]6(.......=.u.&.....g..............................XPeb.^..
..{.P6v.|.............L.........hU.......{s!..........{HC.....&.......
.K.w.#........h........{t.%....{DR...a.J....{...\...H......d..T.......
..>.j....*..Oa4........i%J...R......7?.{s......{.....&......{n.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/jEtUT_cL0M27Wn976ODIjlalYuMX3QGH-mjk2rUKFQA=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 4315
Connection: keep-alive
Last-Modified: Wed, 08 Apr 2015 03:00:07 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11279:4:4300.=R.......'q.^......LWP.........j..2........O<..4.F..
...}v.............).k.}4V.....p..A.........g.\...D...................N
....{..........#............X...].....J.T~..&........7.-Q;............
......}...5_C.......LZyQ..........O.Y.xj......b'..._........}.........
.....:4!.......Ds.z..........dM.........n&.'.....uh@O\-,O.....=6. ....
..[...!........!...P......p......e.......b.c..E....}.T.I.q........T...
..{^............. .Qj.?=....../.Rm~S.....}RW..=O........S...._........
.^[email protected]........$.o........
...S...............Q......{..S lgX..........CE.........p.@./.......r.W
..-........gr...T..........rw.......6......ul~..............{........O
2#.F........F...o.......... ...........rk.>.........l"...........1.
......D..*x.........b(.........R$:[email protected].. @....... @..[.X.....
.............G=.%..;......h..Z.*i....../`.M............Z.......w."....
...2.............S^.{'.4......t.......a.......9..?...}.(VJ...}..S....}
.k..............q|;j....U......}.Aj....}.......}..gM.....Y8....... ...
..[O.............{.*.N...n.....T.._. :y.....~............c..D:..m.....
..P..7......}.7..;........'wLez.........$b.I........oI.@..........~...
......9.............4 ti........w...}......}..%..........9...........'
e.ja.........k...P......._..'.).........e....a..............kF...A....
....A.F.#..........."..........N..h....}r.O..h.........'..........@.,.
...D....}..R41P|[email protected].\.....}F..Q....,.(y....P}.b........}.O....
7.......7..Y.j.........4kS2......#.p...............Ds......;u.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/wcDPbWwJTE2PtmVwcgnQhhl6hkrs-T-aO8g8Itcyd-U=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 75
Connection: keep-alive
Last-Modified: Sat, 25 Apr 2015 04:00:41 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11948:4:62..7...}x....f.. 0....h}.,..`.k.Z..k.Z.f...${. .?....1.X...
.<'7#....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/0D3N_cx0Jm-0zlRfzxtI1c1JCExEEO-3DUtScKCpOHs=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 235
Connection: keep-alive
Last-Modified: Wed, 22 Apr 2015 02:10:15 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11947:4:221.I....I....K.d..$[@...9.]A....................-....-....=
<....U..@[email protected]?...g............m#8..W.c.[..f.W
..8.v.O.t.nv>q...........?......pZ.Z.GQ.....<......rk.1p..<SE
R..3...............4.Z ......}.....J.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Btt71EDwI8tUxpLjIa52nMtiSPr0jPATp90kyoijHJ0=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 4052
Connection: keep-alive
Last-Modified: Wed, 22 Apr 2015 01:10:29 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11946:4:4037.Vmo"....1LW...l{.r..#.*.a....U.MSJ].$u9.\......{X.....|
U..`.gW.6"..&3.N....#j..k..x.aw.T...p*..M.i..M.i3..d.B|{[email protected].....#
..l..'.(...<~.`......Gh.:g...:g...k.....WS.Th...?....?...7.V.]h.s..
...s.../.,1....V..U.......h.......}....';>....=O.n......I.`.t....?.
z. ..R......y.U...q.a.......J.....&...Qv...p..a.....\.%3.........!...5
...F...UY# I..,.>z.....1..,..&$...&$.....l5......I&.....w...h...=5.
....9......-Y...8..v..T...\....sj..v...C...BC.Q%.....r:... ..v:;..(..A
o*..H.v.....J....e....=.8.GqQ...}..6/....k.J.nA...ro..!..Fe<..\.\..
...'...8.~,.K........i.'.JX.*..M&|G...)[email protected]_F.M[......-.a........1..
."...o.../...:..d.....}.2y.Bx..B....:...%@... .....2...r^.a......H....
.Bdb.]...Y{.......qD.......?.........,.....P..`.{..G........mC....i...
{........~.i..n.r.L...........p..D....]s..b.....0.7:f.~....r..........
.p..,0....s...x......8..'.N^#..A......,.~y.....$...m.V.m..CQ7..|.j....
...5.i..&[...........%.g...>....So...&.....A'F..oP..]...Y.6.C....p@
..h.|."...j&..[C.(`l...qPm..^..|..T..^.q2w........|\..od|U.E...`.l*ft.
.!.kC.n......[......8[u..v.. a....A...~>.W. 0....*....j..8.[....7m.
.x.yN .>...b........,g..~.z...u...)..6A...J.t..9/..............u.8Y
ZL9..ZL9..K.9.....T.........{.}.._y...R..t.a.i......y....{..._.q.C..&l
t;!_:.........w.z..._.59...........$.1.RU|.....$X.....%....Z...e..p..-
......0.5E1.._...b4j..i.j..i...n....0.....I............B....t./....)..
[hx..s..Q.O.17.......5(..,x.9...,..h%.... O.s.|./m.S.;..=.O..5B.......
....v..m5...F..x.B..']..1<.W(..fp.#(..*....u;........}.........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/-anZCDFwCsiDfCOfxIKUAJrW0FZfXw4lV2mDR_XwEwU=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 5169
Connection: keep-alive
Last-Modified: Tue, 21 Apr 2015 00:50:23 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11945:4:5154.l.Z...nM!P.....;Gk..8..........M..)LW....2.|-..S!...l2.
...OV.=.MB..<B......_.}&.z.][....E21......O!.^.T...z...!.....Q. FA.
D..x.....pXC.`.gW.....r.....Z...".....Y..X.Z...r..".5...(}.ywF....U.r.
L...i.............7(.k..b...N=e......J..I.oB.......Rt ....?..........9
=.....L.4..{......D..1 ......V..._..9.....hP...hP....N............0/.j
....=D...... X.^.W.....h.....a,cmnb.....L...j.....u}H.....SE.#?.....fR
...xw..........s.....iN_..................M7./..t.sO.6..L..C/....4L2.!
H..O.<.........8<....v....`?.../....C...Zr......#.Nq....L5....47
..-?.......i........1...........2....8.sU..........r......-...'.*1..$.
.m.v.FD...l2)0...[[..w....=6..g\.....e.....Z.|.......a..}.G.v9:..,....
...............c..G...)...d.]..%.k.. 2|.~5:....Y.......O.G..r@..'....$
...[......w9K.FYjiZE...(..Q....r..Otz.U..&..R.....k...j...|.........Y.
...s l.b ....M.........%.T5.z(.....w...:........%. .!...i....24.b.;...
....<..c...S..x......}...........:cd.V..R.Mmg.....}$....'[.&.l.....
........|..G.;t...1:9.O..(/..W........ ..QUj....>.C........C:.R.{j&
o.f..?........7.......c...S...wu....~.h....,....J.......Ao%M.b]F.5/...
3'...?^...m....meb.^.:%."..tW.~.*R.^I5..i-.w.jx....l/W................
..S..Nm....8......#.:..`:..a.J....m%.....}..'....<...q; ..q; -....
.h.d..3.....QG...hq.L./h....mj.(B .(.U...^..h.MS.g.t....b..YV.@'.(#3A.
..y..].....{..O.......s......o..jLB7....j.j.L..,8......!.qE...o....g..
L.uJ!..?h./z..g..~...L....L.............u.kg...........H[^A...FB......
..s)`{...u&.S..*]/B....-=./..)...5.W0.5.W0j.?=../.R. .#...|..bI...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/O9g5OJm4JRG7U6M0FrlMP6KS2sLifUb-a-mH5mfdXIc=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 44
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 19:00:28 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11944:4:31............ln...ln.?...X...........
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Tj7ZLCSSjPdV1SzabZFpEPSGnNkXuSnbXXrEG9YWUsc=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 21
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 16:20:51 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11943:4:9...y..........
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/wEXpqs63b7RAaV1YPIGl6QqBL-E4S-69bDQwGU7vRBk=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 26
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 13:10:16 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11942:4:13.^....w,J.^.......
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Sl6kTbztAG7gh4K9-UWT83pEpeufQD16QOSbGOMH940=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 1404
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 00:50:27 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11941:4:1389....I.J....=.........1....f..........D..........f.b..1I&
lt;'V....3?".e.O..T..p..L.........O.Y..El...~.......}0T...X...........
=.0......L..H[^A..Y.6so.....eD1x.J.'.e..8F ]&:..D.R0G......16...R.Z.Hl
9q?X.l..V7.2..||sg.Q...V.....2v.x=........u.'....}....`.#.(.>....j.
.?1.e.^;.....!...Y.j.....4.....!".............N...4t&BC..'.4. .,..6...
..wZ.....~l....n.V.e....I?...-o@..![E....di.!.~BBj.....6.,j.....p..3/.
..W.u..(VJ?.....X.k.jE.)..n;.z..9T................D'......G#G.1.>..
.......}.4.*1..]U.^'..p... ..mN......l..O...*;.#...B.|.Zh......Hb.....
.............W....;7._..9...al}...;....A.v....;*....q,.w*.........$(un
....t.#.[GC..F..r'.....(.a.\[email protected]=....u..|. }..`.4g7U..L........P.....
...s................N.*..S$....H..a..........9y..Y.$.`e.NT.c........
.v.v.0..........>....>.........|....|.$>..g...k.8~..\..y..p..
`.Z...O.<.....z.... `.0....R9.`.5c......e.f........7..IT.....#.6{.8
3(.._V>..k...u.[...p..2_.....I.....\..8f......%.N.....On.,....|...:
5e.....b..D...PF.^.1...%..*LQ.#.h..C...O..L..#r..u.&.@...=v......?.z..
.Kh....e....3.\......h....k9W..D9.o.#..*.v.u........6.#.,..&...B....Ux
...........y.*........k....>.B..zl...t...2..[3.....i.....DR..[.....
...0....t...d..y.W.... ...i..P%....V.t\t..u..8.a.^.......Z..1L.X......
S........S.........Q_...6...)...u[.[.......j."..y.P%...f.....Fx...v.K.
h.*L.......=......BM..d..._Q.0...Vk@.!..!.0.......... L...N..wFj7.-d.S
.o.[..i|.%...2..}......n...........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/-Pz-fPXqNiCqMKFOyFGBikrEmpIlZiMQ-guIaOYFwRo=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5567
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 00:50:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11940:4:5552..bI..h.)!ml...mPS..i.....a...a......D.%bLW...j'..LW..M.
.:..M={x.......*.a...7....;...........)......J...T.$........oYp)`.v..x
\8.U..../....%.!..jx...T....4m7.L<[email protected].^,.-...s...{).Y...2...3
..d...]..%.....=.(.k......E.s.........?.'u...)s.)h...T.>T.....?.1L.
....A.....N....9....V..$....l.X....h;....L..2.R.h=...=D..c.$c5.4i].]b.
m....L.H.`H./.X...>z.....q\........U....l...q..'.q..'.m...p.....nB.
`f.c!.:.....#.....~...TW.h;>...;%.*........hji8{.Hc.W......E^.S{._.
.8v K.(8G.....V.W.e.,.ZhM....C...C......#.... ........1...\...Ba...'.#
.?.X...~z<a.....A....3.....M.....3.).H3...H3...[c...v..C....qe.l.By
...@7.'.....J...7}.">...F..........oLo^J..... $..m.$.....6....l/...
.o..W>..an...........0W.].....S........k...ebc.mG....NO.7k..~...y..
.?.E}c..M.V.Y....'Rz.gm>&...kn......c....i...R..........k.F...yuwT.
R5.."P...1$.S..|BiC.h.0B..2O......;..E......l.T..........C....2..)...~
....P..2.......E..:..........$.y...c......f.. ....36..r^.D..o...X}v...
..1....!..B...T..<..=SB....F..].R......\..)K..{.&.R!.n.GR./...y.(#A
.t&;....{}.^[email protected]...~...B..zb.......*P....~T<}
.k@.!{ [email protected]:D.....0Jo.E.(.c..G........~._88...K.....0.vI...
n...z.......q.Q.:f.~.......p.....VF.........J.....'J.......e...ZA....}
Tv...Tv..;....M..T. ...d.Z..gg...-........._..K...o.......T......x.>
;.....D0q.&...f.n.0..8...-n...]......3......Du7..1..,../...h..KLok...?
.......=...|!...^...a.T.....)"...%...j......t.......f...:....#...9.D..
.T..i...!.4..L....W.W7r.0..=...6A..=.f...]T...b:...A.;.2...C..5...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/qDC0G_w_wSrAQ-0l04BWQgPpcKgZMDT6ciA2msBNIzY=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 2920
Connection: keep-alive
Last-Modified: Sun, 19 Apr 2015 00:50:24 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11939:4:2905....L...J^....Qz....|....H.........Er(.-.i.M.P....)O..6.
..$..Q..........).kk .U9q?X...>.:5e.....}..A/.1..w...[.a.z ..w..-:.
&,.q.I<'V..U.`.4.S........(.5..... }...b..3{....F...aR._...fR......
....i.8&..suV....lE.`Z:...P..:}..]Q...-......;..A..gRP.V*..Qe.........
pr<..c..q.}".....T........g1.......l.Y.j......b........so....|L.;{.
5..z...U........b......x..2.<G.....WG....|..,.....pR.....<.\....
2W......B.M:.X ......... .... &b7....\ax.o...t.j..aR..:f..Q...K8..-..A
._.p.1.1.......F.E]...n....q...?".e.'.........?1.x.H....[..0;,..../..G
.....J1(....i.\.........[}....".v(..Z$G....H^.M...&}.k.6{...,.X-m...Ys
.%#.<....[.a..f.a..f.........Bj4....F`....}G.vV.u......M6[........a
.... ..zY......e..p.I...Y..o.....[.X..U ......g...4&...B\...v).."J0...
5...|Pj..i...n.'.4.E\.uI>.....e.._....t.....j~.'.q.....8..2.......n
...;../. .A...n.#...._.....8$.n.&..LrBHn.%.|r.......TS5..[..B.........
.\*.3............S.}5....&.M.O)_$...x~.~CbS...B.........k.$s.$.zK.....
.....a....W.}.4.-._P^.' .......~...1... .S.`(}..v.D..........3.rh...V!
;..3f...>..7.a...&<D'...>........>n.R0.7>.....0.7>..
... .l....l.....b..a..h...$V...A.x...=..H...].....C...62Y..d&.z|.$..?.
..'..p.oO..1..s.~.b2...?..f........"...R.<...........`e!Zh.....@...
.......b.............9J.6u..0_..9.|.'r...[.....5(.....^.....Z...!.....
....,G.H;.$...^....^S.\....*R..t.i.).rG..z.!..].>cn.....c 8.1...c..
......e2..I..6.'!..qz`.dk$..dk$.<.r.U.....xx...O....3..;.......$...
O....72........f...w..jZ.-..m.`..s..&658.>.....!.I..s9.h....x..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/5QoMmAuV8US3Ysur3PVelYvOwlVagaglfaAafQ9_Yig=.chunk HTTP/1.1
Host: cache-kiev08.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5727
Connection: keep-alive
Last-Modified: Sun, 19 Apr 2015 00:50:30 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11938:4:5712..bI.....h......,E....N......;.(.2...4 ti....w*.a....4.B
. .=.MB... ...n...>..8L.L.Qa..|\H...'d..D...C;.y..S..2OI......_..!.
[email protected]..............<..".5...2..1
.]..b...tv..L...E..x(.k..3.j..R....7&.y......?.l/...17.......^..U....&
gt;.. ...R...Q.X.....N.C.}.}......X....zR"......aBw_..%Z/.......(,...k
.1...9....M.......H.B..N...wR.._?......].Av.....:9`..]y1y{Hf..\4Vf....
...`..d.K......O..N....i/O.G...../1...|...........<.I..~....`?....L
..FQ.Q.. .....Sa...X.f.)...qr.". 2..... .!...2....8.sUa....<.......
.....)EN...b[,..!....tw.....0....[c.......r......-.By..|..Ax.&..h.wf..
fM..O ../W..............a_.P.Ir;..y......jx.8~....=..........l;.*....e
..!.gs.....c...d..L.P..&..*LJ...hC...M......A.y|..=...O...-.........9.
5.{..u`c_4l.".x9[.R.2.9.k............E......"..U...zs....Q&.'...j.e...
..b.?E..i.`.yi.IbP.......I.,!t.Q......^.....)..O.s...Ry..........A=.Y_
bf`H........H.3..........$ti.S=X..........B....3%u"...u".../..../...].
........{....@2.:....h...|.j..........M$.x...............o'..]5...c^..
[email protected]..~.d5g...~v.1_J......$.ow Q....l...e
......J6......j.`..<..../......g...7.$...K.k..(NVA..T....Hd:f.~....
bF.............$............].....A........s..)...l~.Z.gg...:U. s..."X
.5E.x".2m(}.o...m......(.=~........;nl...%..R..mT.....<EJ>..G.*x
.gv...: .P|U....x.......3[7q.v../h...Yn*.....c...6k....v...c..q2w..OS.
.{....L....4.....K[[email protected],..k`...Z$..i...w.......o\{.n"&.. ....k
.Z..v.I.,`......#.......bM...,.q...7.. [email protected][{B...<<< skipped >>>
GET /chunks/goog-phish-shavar/rHqFII0PWn-x5sL4llxzm8PrL_k6RDogkhqBV80h3JU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/rHqFII0PWn-x5sL4llxzm8PrL_k6RDogkhqBV80h3JU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /gn/468/farm-frenzy_71x71.jpg HTTP/1.1
User-Agent: Game installer
Host: mpcstatic.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:04 GMT
Content-Type: image/jpeg
Content-Length: 5358
Last-Modified: Fri, 27 Jul 2012 11:07:29 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:04 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes......Exif..II*.................Ducky.......P.....)hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
1 64.140949, 2010/12/07-10:57:01 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM
:InstanceID="xmp.iid:4A7C5657D7BC11E19EE8EB24BD6AD373" xmpMM:DocumentI
D="xmp.did:4A7C5658D7BC11E19EE8EB24BD6AD373"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:4A7C5655D7BC11E19EE8EB24BD6AD373" stRef:doc
umentID="xmp.did:4A7C5656D7BC11E19EE8EB24BD6AD373"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....Adobe.d.........................................................
......................................................................
..................G.G.................................................
........................................!...1A"..Qaq......2BRr#b......
......................!..1AQa...."..q...2.....BR.3r.S.$4............?.
.|.&.2...'.e1fj....2...EJ....T%[email protected].;v...v".......?....A...6
P.?......*..'...J.w$.a...{.......:.Z.W$..H.d..'.h..!...~.*m.....K...2.
..&.%...j#o;....Y..h_...W.>Uh.'8(>....W-.....\.K.,.Cc.%q.?......
'......`...m-....1X6....._l.9...Z../....@.)IQ%.._.R6...$c.;...z...<<< skipped >>>
GET /chunks/goog-phish-shavar/wzLxTSmOmorwmke1Edhp54wX_9dvNs5yPeP8oenPaK4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wzLxTSmOmorwmke1Edhp54wX_9dvNs5yPeP8oenPaK4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/KUfgkRS_-x-xLthI9bemI07LuTOBbdjQXJVT1Gcc8Fs=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/KUfgkRS_-x-xLthI9bemI07LuTOBbdjQXJVT1Gcc8Fs=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/-Pz-fPXqNiCqMKFOyFGBikrEmpIlZiMQ-guIaOYFwRo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/-Pz-fPXqNiCqMKFOyFGBikrEmpIlZiMQ-guIaOYFwRo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/sJEvZc18T-F36DdkfLn5DgD2i3J2L2_5jaZ89QVBmvg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/sJEvZc18T-F36DdkfLn5DgD2i3J2L2_5jaZ89QVBmvg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/7JE0yHlqxwcT2P3015xdKB--Hrdwr7-1wPzo1rfzEPM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/7JE0yHlqxwcT2P3015xdKB--Hrdwr7-1wPzo1rfzEPM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/2Co669pBX8sWhrvtK2V8n-iyxDvdICtpqxZfO4qFwdA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/2Co669pBX8sWhrvtK2V8n-iyxDvdICtpqxZfO4qFwdA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/UIig0slspRhngV1ffZg2oait9i-ELqUx4qMoBUagOvs=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/UIig0slspRhngV1ffZg2oait9i-ELqUx4qMoBUagOvs=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/UD0bsq7CgMFsj1L2lGlt_qMLDOVILsZp0MO2uGBvQDw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/UD0bsq7CgMFsj1L2lGlt_qMLDOVILsZp0MO2uGBvQDw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/bPzVXNtCxclsBHuqQnq_VFLS814vJ9YrJr0_ECYF23A=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/bPzVXNtCxclsBHuqQnq_VFLS814vJ9YrJr0_ECYF23A=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/vOZ7hV0kxCKHMixiB5_zjy6_Yc9TGBNyvnbfCylFdHo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/vOZ7hV0kxCKHMixiB5_zjy6_Yc9TGBNyvnbfCylFdHo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /gn/468/farm-frenzy_71x71.jpg HTTP/1.1
User-Agent: Game installer
Host: mpcstatic.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:04 GMT
Content-Type: image/jpeg
Content-Length: 5358
Last-Modified: Fri, 27 Jul 2012 11:07:29 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:04 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes......Exif..II*.................Ducky.......P.....)hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
1 64.140949, 2010/12/07-10:57:01 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM
:InstanceID="xmp.iid:4A7C5657D7BC11E19EE8EB24BD6AD373" xmpMM:DocumentI
D="xmp.did:4A7C5658D7BC11E19EE8EB24BD6AD373"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:4A7C5655D7BC11E19EE8EB24BD6AD373" stRef:doc
umentID="xmp.did:4A7C5656D7BC11E19EE8EB24BD6AD373"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....Adobe.d.........................................................
......................................................................
..................G.G.................................................
........................................!...1A"..Qaq......2BRr#b......
......................!..1AQa...."..q...2.....BR.3r.S.$4............?.
.|.&.2...'.e1fj....2...EJ....T%[email protected].;v...v".......?....A...6
P.?......*..'...J.w$.a...{.......:.Z.W$..H.d..'.h..!...~.*m.....K...2.
..&.%...j#o;....Y..h_...W.>Uh.'8(>....W-.....\.K.,.Cc.%q.?......
'......`...m-....1X6....._l.9...Z../....@.)IQ%.._...<<< skipped >>>
GET /chunks/goog-malware-shavar/tdaKepnAEP8GIBFsntEZotPvlWuEMLmm1oKs6ppIzjI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/tdaKepnAEP8GIBFsntEZotPvlWuEMLmm1oKs6ppIzjI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/34hObcShEQV4s6ck7ExkGQwcoXdmdgRIKIqoNG8qAkc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/34hObcShEQV4s6ck7ExkGQwcoXdmdgRIKIqoNG8qAkc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /PlayFreeBrowser/setup.exe HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/octet-stream
Content-Length: 1663784
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-196328"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytesMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......f/.B"N.."N..
"N....L.!N..9.J..N..9.~.!O..M8..!N...9h. N...9j.#N.."N..pO...9m.?N..9.
..wO..9.N.#N.."NC.#N..9.I.#N..Rich"N..........PE..L.....UR............
.....h........................@.................................@.....
@..................................N.......0...............J..(....0..
............................. .......*[email protected]..@.....
...............text....g.......h.................. ..`.rdata..........
.....l..............@[email protected][email protected]..
....... [email protected].......|..............
@[email protected][email protected]..........................
......................................................................
......................................................................
......................................................................
.............................................A...u....N........S.V....
t.V........P.....j.j.j.j.j..3.........U...E..V......N.t.V.w........^].
................j.j.j.j.j.......U...E..U.....E.QRP........].....U..QV.
[email protected]..^..].......U..QVW..j..M...t...G...t....
s.H.G..w........M.#...t.._..^..]........R...........U..QW.9..t;j..M...
t...G...t....s.H.G.V.w......M.....t..#.t.....j.....^_..]......U..V..V.
...R...y......E..t.V.>........^].........A..H..Q..D....R.P....R...y
..Y.....x..r..........A$.8.t..I4....3...................x..r......<<< skipped >>>
GET /PlayFreeBrowser/chrome.packed.7z HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:06 GMT
Content-Type: application/x-7z-compressed
Content-Length: 34442382
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-20d8c8e"
Expires: Fri, 01 May 2015 04:55:06 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytes7z..'...3;..................z.........8%D.z.x../.Bg;....N.zN.......9 .
......M....4..hM.......X...S.-....O ..`..85.........F....$........m.cW
.F<$7i*..... $q..0D.-8.wm.=..`}.Fv..b......I....-...<...%RzE.5G3
PS...@!....z...c&s.....X..4.I...>.6..R_..~...Ov.t.Uw..I......r.U.kJ
h..z.S...1g.Y......2..aa..7..O..'M..wH.B'.P..}EM......y|...bc.a....^..
..."...Oaq......#o...2.U...nSK%.'m.f!!.....'..`...@...$..9.wL...!...K.
..g....sV.7../L...V...G..........k.<)..D.......H..-.9........(Q...5
?j...g...'..0g...E.3 .....k..z..<...m.......f.. .,~.k.......Q..7).`
......&..x.#*.a1D4...,...w.....=.....g#3z.{j.#-.........$....<0...W
.wE... ...t.....C........"BNB5h:.J..Iz.....I...#....6..s......R...7.N.
.I.l......7.2.=W..VO.. .....Zw...M...........no.q9..1.q% q.%...G.).g.Y
V.....Y^!g....|x..R...q.\H.;....~......x@,..*.&.......<h.X.4..~.&
gt;.z...T....:Fz.7.Y.^k.....e...........0.$.J$..rhX....E.<....5l.H.
%..O.D...w...4K8.....o^..P.~N....0.Z.'i.......K$..~.(x.C....>....y.
<...I!2.AB.....p.l....m...|.!1a..T..F..C.....~....:..&.....Q\_..J.a
p.. 2i..n.........'...g..'[email protected][..#.U....$..o.F.1B.&
gt;.k8.4r...a.aa .,.)i%.g.V. %...=.f6...sK.,B'...._.......z.x.7..).n~.
z....:j...J$'.j...L..^.c\.{.K...q.|n.$...F. .H.Q.~o..HT..I...[........
o..o..'Y-.S..6.IO.c.5Q.D.~...[2.L&[UM...U...1..I*H...f...>..C.G..V.
..b.[..C..KOB....X:u...q.....<.......=..eEt..D....D..T..../^.D.g.&U
9.........)%..k.p..V...,[email protected]_.A......... ....dT
.kK.&O..G..y....&N5...P........(..Tu..a......M0..dx.9.9....mV.*x..<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTEemCaVgs8Tuh2B9fGVE0pKKNyzgQUTF+nNhcF4oZhIkk5jLmo40rgOBoCEC6utoKGY/7ZdVX4/iTzOxo= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1552
content-transfer-encoding: binary
Cache-Control: max-age=503476, public, no-transform, must-revalidate
Last-Modified: Thu, 30 Apr 2015 00:10:33 GMT
Expires: Thu, 7 May 2015 00:10:33 GMT
Date: Fri, 01 May 2015 04:23:08 GMT
Connection: keep-alive0..........0..... [email protected]
0001033Z0s0q0I0... .........z`.V.<N.v...TM)(.r...L_.6....a"I9....J.
8........c..uU..$.;.....20150430001033Z....20150507001033Z0...*.H.....
........e...E;....([email protected].....,.jPVAh..z...4..eL. ....2.G9.i}..
H..!.}..........<.w..0W......a...S.K)AR.h..N...V}.5:,..xE......n..j
n.:wg.h{....D.:-...~.7....L?..W...<.Vm..5.6o.g...3..=...f.R.W(.t.`.
. &.4:..d....K..K..A./.e.d..W..K=a..l......f...........0.......50..10.
.-0..........y.P}~.EY....T]. 0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1<0:..U...3Class 3 Public Primary Certification Auth
ority - G21:08..U...1(c) 1998 VeriSign, Inc. - For authorized use only
1.0...U....VeriSign Trust Network0...141202000000Z..151216235959Z0..1.
0...U....US1.0...U....Symantec Corporation1.0...U....Symantec Trust Ne
twork1?0=..U...6Symantec Class 3 PCA - G2 OCSP Responder Certificate 3
0.."0...*.H.............0..........6..]......w';.r........I..c..4....
.........TyW......hd_.....!C.k......SE<?o.H.. .me.c..9N.&....e.^-..
a.....i\:..*."..u...|....".Nf3.~.L...QW...p.....-]UV8U...J&.<./.G..
...I...4.T....#I*.i.E0\..~q$.I.......X?G....f.t......v.l.U.Ld.I...B...
..=...Sf...H.s.........0..0...U....0.0l..U. .e0c0a..`.H...E....0R0&..
.........hXXp://VVV.symauth.com/cps0(.. .......0...hXXp://VVV.symauth.
com/rpa0...U.%..0... .......0...U........0... .....0......0!..U....0..
.0.1.0...U....TGV-B-2740...*.H............1.`...i.....H.C.i.9~.i..Z.r.
*$..(./.ag9.....J.Q.~.`.$?b..C....<.h.........d&....3.kV.....f.<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRODEXefhs/UZFum2o8YfzOFwceMwQUkz5j3yJ0BOBkhDHd2yOfDq+2TZMCEA89qsgV9niZmSI6gIO0S/U= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=546569, public, no-transform, must-revalidate
Last-Modified: Thu, 30 Apr 2015 12:10:12 GMT
Expires: Thu, 7 May 2015 12:10:12 GMT
Date: Fri, 01 May 2015 04:23:08 GMT
Connection: keep-alive0..........0..... .....0......0...0......%bn.$..5.......?'4....2015043
0121012Z0s0q0I0... ........N.E.~.?Q.n.j<a.....3...>c."t..d.1..#.
...M....=....x..":...K.....20150430121012Z....20150507121012Z0...*.H..
............B.l..8........Gs/........"..........G...{?.^....R..'...)..
........J...0.R.l..)........W.N........D...D.K.....C....y.<....Y.S.
...#93..B.}....6....%..3Sf... ...j..S=.,@....N.......[..%.yI_...1.....
.)....N{[email protected]{.D~.j~...{....0...0.
..0..........7.R.~|..r."....#0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of us
e at hXXps://VVV.verisign.com/rpa (c)091.0,..U...%VeriSign Class 3 Cod
e Signing 2009 CA0...150401000000Z..150630235959Z0..1.0...U....US1.0..
.U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSi
gn Class 3 Code Signing 2009 OCSP Responder0.."0...*.H.............0..
........z..|..>.....5.Z ...2.C MWIH.5......M.\.... ...eW..`.B=..`:.
.R. ...Z.k.Y.....p@.(3.c....a.;..[E....J:'...`...B....M..&......{. (..
......%......^[v[....m....*.T.o&4..3.....3.........G...e)...'?.K..2s..
8=?..z.:..T..-.8R..8wv7*U.K..c...<s...]{.........6.?_...........0..
.0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://www
.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS
incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0.
..U........0... .....0......0"..U....0...0.1.0...U....TGV-B-34920...*.
H.............,..-......q3a........z....t;B.z.h...]...#}.6.,..YU..<<< skipped >>>
GET /browser/updatechecker/?uid=PFBrowser&contract=C132BADE-00A8-4386-BB5A-D30720EBAB87&date=1430427600&version=3.0.0.4&build=gs_en&action=install&mode=installer HTTP/1.1
User-Agent: PFB Update
Host: update.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.4.1
Date: Fri, 01 May 2015 04:18:14 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.151..1..0..HTTP/1.1 200 OK..Server: nginx/1.4.1..Date: Fri, 01 May 2015
04:18:14 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Con
nection: keep-alive..X-Powered-By: PHP/5.4.15..1..1..0..
GET /chunks/goog-malware-shavar/r26WN31Wqw5U0loQzRbt_kZT_vWxHj8ekoP9Sdr3ZIU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/r26WN31Wqw5U0loQzRbt_kZT_vWxHj8ekoP9Sdr3ZIU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/Fejg5XK1yuNw_YRGnEjzcXe9IfHSn_fxKCR37v7LbfA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Fejg5XK1yuNw_YRGnEjzcXe9IfHSn_fxKCR37v7LbfA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /pki/crl/products/WinPCA.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Sat, 07 Mar 2015 06:01:44 GMT
Accept-Ranges: bytes
ETag: "dde36a309c58d01:0"
Server: Microsoft-IIS/8.0
VTag: 43879645100000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 561
Cache-Control: max-age=900
Date: Fri, 01 May 2015 04:22:10 GMT
Connection: keep-alive0..-0......0...*.H........0..1.0...U....US1.0...U....Washington1.0...U
....Redmond1.0...U....Microsoft Corporation1 0)..U..."Microsoft Window
s Verification PCA..150306223202Z..150605105201Z._0]0...U.#..0.......p
............<.J0... .....7.......0...U......40... .....7......15060
4224201Z0...*.H.............4......n[.t........'....Dx.P3R.!3.|D.6vL..
"k..9'....L..k......e.4......._..N..TJ......N.fP...H.....8...TJA...fGA
.e...^"{../...H?..E.Y.U....h..0/.......d...6..K..V?QM...{..h.....{.3..
.v.....\~.7n..5..'..k.Ia.YL..LP.b....._7.V..%......z*$q..Y..f.b..L8<
;~..v.w....
GET /pki/crl/products/MicrosoftTimeStampPCA.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Thu, 05 Mar 2015 06:01:35 GMT
Accept-Ranges: bytes
ETag: "cf2633d6957d01:0"
Server: Microsoft-IIS/8.0
VTag: 43853244400000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 550
Cache-Control: max-age=900
Date: Fri, 01 May 2015 04:22:10 GMT
Connection: keep-alive0.."0......0...*.H........0w1.0...U....US1.0...U....Washington1.0...U.
...Redmond1.0...U....Microsoft Corporation1!0...U....Microsoft Time-St
amp PCA..150304221607Z..150603103607Z._0]0...U.#..0...#[email protected].. .
.5..0... .....7.......0...U......20... .....7......150602222607Z0...*.
H.............Y..}y`....T.Z..`B<..I.N..O... E:....7......a..)......
...._|W5laoqi(..>t~.."...&`.._.7J...:..{bO_Kyi...R...!...B.s..I.c&j
...(I\.S{._;@B...[i.e.[."...R` \...........M^k.=q[.V...9y..G.1o#k3<
.W.......H.$>}...U...2qyd2|b.fB.....r....H.P...;....Q...b......5%.P
.#..
GET /chunks/goog-phish-shavar/4QA7fZWgrqxa94GQcWGjO3rvLLV-E4WktLOUf4lHHrs=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/4QA7fZWgrqxa94GQcWGjO3rvLLV-E4WktLOUf4lHHrs=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/5uO6Pab7G-Fdp1GqUSSzm2fYjQ24MkfLFcHw2lPcG48=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/5uO6Pab7G-Fdp1GqUSSzm2fYjQ24MkfLFcHw2lPcG48=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/mQG2X2AwB1UBKbcXP7oraGgK9_Js1nl7N2vjMKo_7Uo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/mQG2X2AwB1UBKbcXP7oraGgK9_Js1nl7N2vjMKo_7Uo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/vxmVNy37oonjrrSDZBzDLPpqngc8zEScGiGMBTyDFcc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/vxmVNy37oonjrrSDZBzDLPpqngc8zEScGiGMBTyDFcc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /en/main0.css HTTP/1.1
Host: home.playfree.org
Connection: keep-alive
Accept: text/css,*/*;q=0.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: utm_source_channel_id=gs_en
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: text/css
Content-Length: 16675
Last-Modified: Thu, 16 Jan 2014 07:34:43 GMT
Connection: keep-alive
Accept-Ranges: bytes* {padding:0;margin:0;}..* :focus { outline: 0; }..body {font-family:A
rial, sans-serif;font-size:13px;}..a {color:blue;}..img {border: 0px;
}..#mainContainer{position:relative;width:100%;}..#bdyLand #srchCat {p
osition:relative;float:left;}...dvdr {width:1px;position:relative;bord
er-right:1px solid blue;margin-right:10px;margin-left:10px;height:10px
;top:2px;}..div#homeLnk span.dvdr {.border: 0px !important;.margin-rig
ht: 6px;.margin-left: 6px;font-size:13px;}..#homeLnk {font-size:13px;p
osition:relative;float:right !important;text-align:right !important;wi
dth:215px;}..#srchCat span {cursor:pointer;cursor:hand;color:#FFFFFF;t
ext-decoration:none;display:inline-block;font-weight:bold; padding: 5p
x;}..#srchCat span.chsn {color:#FFFFFF !important;cursor:default !impo
rtant;text-decoration:none !important;font-weight:bold;background-colo
r:#0886D7 !important; padding: 5px;}..#bdyLand #btmStn {text-align:cen
ter;position:relative;margin:70px auto 0px;width:605px;height:20px;pad
ding-left:100px;}..#btmStn div{position:relative;float:left;}..#bdyLan
d #tpSctn {height:26px;position:relative;font-size:13px;background-col
or: #415362;}....#bdyLand #midSctn {position:relative;width:700px;marg
in:130px auto 0px;height:25px;}..#bdyLand #midSctn,.land_SE_logos{/*po
sition:absolute;*/}..#bdyLand #srchCrt{width:550px;height:23px;line-he
ight:22px;font:17px arial,sans-serif;padding:5px;top:1px;left:0px;}..#
bdyLand .srchCrt_1 {height:25px !important;border:1px solid #abadb3 !
important;padding-left:5px !important;padding-right:5px !important<<< skipped >>>
GET /en/i/games_bg.png HTTP/1.1
Host: home.playfree.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: utm_source_channel_id=gs_en
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: image/png
Content-Length: 4707
Last-Modified: Thu, 16 Jan 2014 07:34:43 GMT
Connection: keep-alive
Accept-Ranges: bytes.PNG........IHDR...D...'.....^..e....pHYs................OiCCPPhotosho
p ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE.........
..Q,......!.........{.k........>...........H3Q5...B..........@..$p.
...d!s.#...~<< ".....x.....M..0.....B.\[email protected]..@F....
&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH..
...........0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(.I.
[email protected]..._-...."[email protected]~..,/...;.
.m..%..h^[email protected].~<<E.........J.B[a.W}.g._.W.l.~<..
....$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..&
gt;.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..?..
..D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/[email protected]..=p..
a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2...
.G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,..c.
."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.X
H,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!.[.
[email protected].(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i..t.
....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....J.&
..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.._.
.. .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....).).
.4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....Dw.
n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC][email protected]....
..<..F.F..i.\.$.m.m..&.&!&KM.M..RM..).;L;L........5.=1.2.......<<< skipped >>>
HEAD /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Length: 41792592
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0HTTP/1.1 200 OK..Accept-Ranges: bytes..Content-Length: 41792592..Conte
nt-Type: application/x-msdos-program..Etag: "5358c"..Server: downloads
..Vary: *..X-Content-Type-Options: nosniff..X-Frame-Options: SAMEORIGI
N..X-Xss-Protection: 1; mode=block..Date: Tue, 28 Apr 2015 18:08:16 GM
T..Alternate-Protocol: 80:quic,p=1..Last-Modified: Tue, 28 Apr 2015 17
:23:00 GMT..Connection: keep-alive..Alternate-Protocol: 80:quic,p=0..<
/font>....
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=0-9536
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 9537
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 0-9536/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$........ K..A%..A%.
.A%..Nx..A%..A$..A%...K..A%...Y..A%..A%..A%...]..A%.Rich.A%.........PE
..L.....>U.................&...N}......,.......@....@..............
.............}.......}.....................................p0..P....P.
..L}..........x}.P<................................................
...........................................text...2%.......&..........
........ ..`.data........@[email protected]}..P...N
}..*..............@..@................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...................................................1...1...1...1......
.1...1...1...2...2...2..:2..P2..f2..r2..~2...2...2...2...2...2...2...3
...3..&3..B3..N3..d3..z3...3...3...3...3...3...3...3...4...4..$4..44..
J4..Z4..n4...4...4...4...4...4...4...4.......5........................
>U........0...............{.8.A.6.9.D.3.4.5.-.D.5.6.4.-.4.6.3.c.-.A
.F.F.1.-.A.6.9.D.9.E.5.3.0.F.9.6.}.....{.8.B.A.9.8.6.D.A.-.5.1.0.0.-.4
.0.5.E.-.A.A.3.5.-.8.6.F.3.4.A.0.2.A.C.B.F.}.....{.4.D.C.8.B.4.C.A.-..
.{..|!...P.E....pP.......YYt.NKKOy.....2._^[].U..S.]...VWt8.u...t1<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=9537-21587
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 12051
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 9537-21587/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=03...3...3...3...4...4..$4..44..J4..Z4..n4...4...4...4...4...4...4...4.
......5........RegQueryValueExW....RegSetValueExW....RegCloseKey...Reg
OpenKeyExW.ADVAPI32.dll..\.LocalFree...lstrcmpiW...GetCommandLineW...H
eapAlloc...GetProcessHeap....HeapFree....WideCharToMultiByte.u.MultiBy
teToWideChar...ReadFile....WriteFile.4.CloseHandle...SetFilePointer..V
.CreateFileW...SetFileAttributesW....SetFileTime.Z.LocalFileTimeToFile
Time...DosDateTimeToFileTime...GetProcAddress..T.LoadLibraryExW....Exp
andEnvironmentStringsW...lstrlenW..Z.GetExitCodeProcess....WaitForSing
leObject.i.CreateProcessW....RemoveDirectoryW....DeleteFileW.N.CreateD
irectoryW....GetTickCount....FindClose...FindNextFileW...FindFirstFile
W..~.GetModuleFileNameW..p.MoveFileExW.q.GetLastError....EnumResourceN
amesW....GetTempPathW....FindFirstFileExW..5.SetProcessWorkingSetSize.
.B.GetCurrentProcess...ExitProcess...GetModuleHandleW....FindResourceW
.U.SizeofResource..e.LockResource..W.LoadResource..KERNEL32.dll....Com
mandLineToArgvW..SHELL32.dll..........................................
......................................................................
......................................................................
[email protected]........
......................................................................
.....................................k...........................0....
...................H.......................`......................iy..
...c.a........p.R.|...qm..v........(TC..V.'.m.Ko....w...i.5z|...".<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=21588-38306
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 16719
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 21588-38306/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0y.lC..7......M...Hn.......c...aA.....{...4.../.k.z...@,.$.a.R..u.0...#
..u`a.$z...~7.....R.B..C.....9..Rr...7....._.Q>..b.(..%..o].*.....(
1.c.[:.6.V.wS..H54......:.S....S.`...........o]l._......3...V..w.....z
&.p..)^..]R..W.2.| ]....y\$e.y....yQs4hN..V......Q.Vt. p$y.F....pvH?.k
;.....J..4.f.....$f..O.u.8..To...2.......X......vi.=d.o>....#d....*
psV..Q....n.WP...A...yP......A|...I....B....%7....?...[._......9N...F.
(...M...<3Y%&Qyj.....",.D.`.......h[.H..(....NG.(IY9...ey.o.J.....y
.,....1tH?.......^......&..}rD.\......:*..._..&......v].N/.\.qx.f.s...
.F....Y.k.*.e1.....)x-ib.% e....-.E.3NY;.q.Z.M^.C.......;@B....|.c.A.;
}W.~....$.......a.^.r.!....K...9....:C,]...W....E.y..\......0.\.(q.d..
[email protected]..=..w=.|.a....uC[-I.u.w...........Wg..k....
.....js.lVG!$(.E.......F:............`...]!5A..N..#&G~JPZl.:Q.O......2
U4*7=...0.d'..4..!..q0^....D./.7G,...jJ3..`[email protected].?..F...\.E
?M.#..W=.u.Yr. .....ag..k..d....W...x.3.A..%.a.H.. .LT@.:.G...s.Sh....
!.....V.K/...1t1.zp..A.*\W~y3..O8...d.......w...........Z.......?c.L..
.x.,.......F....U.W....zj#.rH......=Cn..Q....^T....Z.`-jK..Ft......P..
.2.Z....e.]...(.n...j....O8J...v,.>...J.`..K..1....n=F..!..|..Q7...
. !`..V=I.(.{m.~b `o....F.........!6....A.o....^U.....z.5...G.E. BK4`.
..D..^9N...q.^..lFz.|...|..M.W.b7.WU(A...C<.hc....{A..............T
.!.W..;.,..b..-.6.8h$1...;....v..o...Yy..qov .3......?.u..8S.Y...?....
......D...f..Q .O..z..#w...,..."6.|..r.np....0.. .53....f......[...M.U
.......I.&Q...Na.....M .....~..1.aZ....^xR7.;....Ch;.H..l,...&..h.<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=38307-58590
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 20284
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 38307-58590/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0....W....CM...r....V..R..vk...-...e...5y....\L.3.a...Qz.m....e...m..2.
...)i...7.e.'.o...m.y._aO..;?..n........D.u.......q.!......t=.|..s...d
.c.....#.~-..T...s..3......y..v.x.BZ.c{.s.:.....[.8sx.Mw*2.K....0]...E
YA..CK{.|...~*f.[.,Q\.......bO....-.E.......^........L...pp.e..;B.....
[.aa.(.(..x...Y..h..n.d.GH...t?..vTV,h.81...AJ..".Gp!.r.o..;...k(...I.
..=.$.|<.........0Hv.Z...:V.T.M...<.....:.."2m....&~x(..{[email protected]
.)."[email protected]....(:../.Y.\WA$^..^.?./=...G...^...|w.G...'W....&...@s...
.l.../..Lgm.G...N/|....&. ..A......c?.....K._6%.tS..j.X_.(.w.&..H#.-..
......m .9 .c.s..E.....R#8.ngr0\4.>.,.R.C:.0a../p..?....>Y......
9zW.....I....SV0.Z.C......h.k..U......-....*v.....j .I...j.c..(..~...N
......,....L"....se...n....|.'....!l'..!.`..w**..Ry........ ..M2dX.O.e
w........w-..^4.[.9... .....>..U.....5.....*.s.n>.L.B...NOu...lK
&..d?.....%.i...k...E.9.P#.hoLc".(nm#.9.#..6.:P..F.V8...qZ...L..D-.R..
......:.:.e..U4V.ZS.8(..R...Ac}.{hp.....R...Q.^O.y.[.``..SW..*d.......
....#U&..M......h.5.8*.L....Q...S.WA:.....*?...q7Y.X.X..8.............
..A.).M...*...,0.........m.2..e.......<....).G..........`./51.C .v.
...t...-3.Z.\.*qk......B..9.w..<.?m.e....^;..66\.8.).!..l..#j.C4!.i
.d;......dEz..$.......R.'.`.........s...`:...k.O"7uz?.F....d...m......
. ..(....^...p.,O.y...f.5|{.B..&.Bm..$.......#uB.8@?I...-.Wt...&...i..
.e.../...H..T..S.3.Bc..#.x...b.O..Mtd.)..*..o."..Z..Sq...=,..D.G..Or%.
....Y(8..........=^.....o.....S.s..U*v.5.*..v/..26.}..M..^..&z...X..:{
.W.R...wk.<..u..^n:.bWe..../.p..1.nT.......j.cJ.G..2.....O..O..<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=58591-86907
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 28317
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 58591-86907/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0.e..{.........z....U.....R.-.&>t...HH........7....3.j.....l...vU.a.
hm.h.E.5.i2....h.L...........R/nq.]....`s /........a.7..L.T......=XYB[
.u../...u...~..o_;.a.S..u,.]&A:.4.F......lE\IQ..~K..i.Y.v3\...>BD0.
.l.8....\>...=..:^....8y.pTuP.2B..i....i.....e;......pR3......T.WWF
..:|....#...&.$.....^.O.O..'.../{.e..M!E.0?.." <.i3..D...nE7...../l
...%........Jg\........a...K..X.x....7.(&.C...h.!...![......1WWn..Cf..
*..B...... ..T.?0.......|..<...Gb.(^/.z....WP.%[email protected]..&
lt;Kur.<.l....,4..^.../... ..,.Y....RN..Lt.N.V..m[.....bD..M.MxUI..
...lP.....i[..^..>#.t...'...z\.o...Vd...tK.f..[..&h$U..N.W..y......
w...H^.y>.....j.i..]}............^..W7TUyQ(..iV.P.*....p.W.{...jW:j
bg...."..?.v:oY5...6.Glt.m....e........._.....'...>".Ztv.k..uc.X1..
..R .......Q...\...f ^e|o...Z.1..*...Q....^..e.o..}.....m.m....tO..r?.
......=>#rrV...0W.....8N.!`...q....|."....-.g.!......'..,%...?Z....
......<...S.[....i......"..<...9K.[B....,L. ...F....A..?.o%..<
;.1..........QD..Ro}.kx...3o.zG.K.o..W..#*.QT.....v01..0V......g...k.}
W...3........5....$"y.Y<...'_.b.5og4*p..5[..Zh....C.9j..Mp)...8....
D...J.jCBl.$.3.....J/B...)P4........'#...=..t..W|1A..`s..oU......,....
Jg.n.|..32.....$..tU...D.....G..%g.l.k.......Z..GMTc..I$....F.UB....r.
..H..K..sn... ..1.........Z/Z.....z.2T.....|.5.M ..i2n.....B..}...3X..
........HW.c.<..][email protected]. ...-...g.>.>.....F...7o....
....X.L..H....&..0o..G...Q..?.75..m..y.\...!I.....Y(."...U..i .|K%.t.U
l..`.f.[K......l.R.M..U...c^...]..ik..&.......-&...- .]..~..MCo]'.<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=86908-129659
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 42752
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 86908-129659/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0.k....Z..........%.....^.6.j]..S.....a...o/..Y.......[.d...._.IYC.g8-.
.~7dG......G..............Uf.]o.<.}h../*.P........7...=%.....6....V
[email protected]...>.`.Uf~F$..T..{..1.....-.f-A..n.l.b...Xr.....<B;
.TU.)E.:.y...^..n|.. 7f..}[email protected]>{.V......t.)/........p..
_.aU{qU..... .Ig.p..)`.7.',6.....f.E?.V:gX.k..........8D.T..-Z.....~..
....K..]<,..k..\..*...eDE...._D.2.W.8.Ws.~<.S.s....h..=....6s.E.
.......iw......&x'^..B,....I.,2.......s..].S.....1bMw.....*...lv...z..
.....2...g.[D{.a..r.....l...:......s~...L.@AOSf.]..7<..........."`.
%...xq^..e.!iK1f.}.:.8..i.....=.du..b..4..&.1...>Y.:lb..\.{.w..J...
;.t}..;.ZA...m..yd. ..N..Om..n..^......h.*.D^..)[email protected].(...
.......}.".Zg([email protected].....?.d5 p.=.C.......D.~......g.....N.L....n..
.s.u...:..\..5...L........7..c_9JL}.s8.w}.D/...V.)..]..A..I......{[. .
...m.}.`.K.Z..)7N...A.......\..c.Z.t.2%......Od....3P.S,...-..0*...#..
..&y.^.....HR..VdX,J.....:.....O3.X.K..Z:....;dd...o.[f.G...<o|I...
..L<..i..=j.a..a.A..FH.V:.j...G..^&.pN.3..$..j.>.....|....].3r.U
..p.....*.j.?$.....s.....I.t.n..;..#.|...r[J!...|\.|...zS.I`......r`F.
..].......5.....Y.[7...o.,Y~...%[email protected]......'...bH..l%D^.
..;."..i...N9Ug6.U.....J...Y"...c.Um?..^..!..!}.....$.e......X.w3....Y
[email protected]......&0ee..........J.-...Z.<.O...!.$r...c...Y...p..E..I..
.....U.Ay.BiL..O...=.w...{z[.o...H..}.q....)...L%......c..\.......L6.&
gt;..7j.8...m.. F.Iw..}..p..=.fU.........3R..h.....I.i.CU#%P.v.X.r...a
r5JiZy.....!=..jQ..I;.s!^.........{.[..........e.....)7....@.~....<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=129660-152981
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 23322
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 129660-152981/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0Um.<.\.i.Y."-\ sU...~I...L..1.r.G...!...[...3..L..V....U$..IQ..}...
9....h.9.>.G.E....Nw..F...f....R....hC.%.D...>..&..o./.......b.s
X..]. .....D}.x.8. .].)t.fqo!.4...'(.....s.....'..a!.8.. .............
7....O.7......E9...|).0.....u.......?.5..u...<$....'[email protected]
....Sq.RV..i.. ,...G...\._v.C.........'4d%..#....g..c..n7L:F\:..j.@:.t
.7.Q..NuZ..$......7.K)...c ..<~.`.....{.Q%.N....*......,.\..}...@..
.j.....P)S....q.......:...<}[email protected].......!qh..........q."..
..4I..)..4..kMD...v2...b.d..M %.u.j..[...^m..Gm.%.8....)G..0.....o.*[f
w;.q...\[email protected]../.R.!be.....*q...J..e.....?g...Y.Q!g../p..\.....
...3.ciPODH.......O....,..GY........).l#..YwTJ.... ...;...s.:.LB.."...
..........2.2....?7.[.6 ......@ ..m.^....p.`.q .wt......k.......|80..h
...*.-...f/E..!..^..<..y.8.|..L$...,(....g...V.".[.EIPRNYS1GTrih..w
..W\..............d.f...h;..{........=h....=...H.f..#..sD..KYS.7b)V.3.
....u.4...}..../........D...x................D....;.@..... ..]NX.9...u
}.PWH.SKT..R.e4&.... z%Gi......i..%.a<[email protected]..
e.NX.:G.....u....C.....C.H..Q.....O.n.....s..n..U..3.~<..0...~..\.S
.,W,,._Z...ml..t....1,.!.....qg(i0.}[email protected]..
~.0.c....m..%..\ .d_.....*J.......>*..TZ`T..O..kj....Gt..7.;.$...]'
.!.....yt...E(.r.&}[n.....0.]...:......9l.._uW...E...........M...*....
.D........Yu.Cd*.q...c....P.F......h........H..F....-..D[q<u2.t.t..
O.v~. ........oO;i.-c...[B...$..q5...2w.....G./.T.#.o.........^b.C....
.'..5...2O..o.j.b*E...W.r..X..E... .....k;..W.......].{e.B~j.xW2.!<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=152982-272824
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 119843
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 152982-272824/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0...j......!...9..c...Hh.....C...5Q|.P....H....t..&..=.......B...WG%...
[email protected].../...W......F.0.E>BA.3...%....i.f.. ........
.Gy.a~....4..i...1.s......;t.L..7gJ..pt."......._.......?P.f...M...q..
b..w........ A._..."......~..n..8.]3..D.^..8.{IsWzv.....>.0..?p|k..
........!.D...v.Y.E.I.^..Y...{c..d....KD...k...c.....S#N>....3.../2
F..7..../.d..>m.B...A%.....y.oPT\........}A.4uS....Z..o..1....*J..c
U....B.X..AQ...d...2.N..7...)N5......%..R...s...P .,e.._...s.r...en...
"[email protected]:...0..#.sx..^?N .......B./..\..........
........B.KO....\..s.(z.....:Y....C..w...z....lH.d..U............\...%
..S..sm* ..'X...h x.,S...jO}H.B>.{%b)bf1.......7..(..^o...U.6bw@...
..d.Z...?"..3E....P.9v.......n......{6....*....2.(U......F\..9h$.a&.".
..Tu...3.VU.....o..e.....R.....Lq..).j..2.........~..J......'...].}..$
.lV..Gy.A..*.*Md.X...X.....Tj....9..e......3.y../.U....,cX.....&.9....
Vp0...P...T\~z...>.....H.]...`....7...5....W. E....u!. '%.$......._
Rd.........:....."J.N(A.%...N=h..t.......IkN..|!..x...*.N..F..Aw......
P.V....6G..6/..y...g.}'..G...5&LX'....[[email protected]@.[0.;.^K
.W.d:i.:....Qf.M.<r....:....~L..q5j.3..h*.A.....aV.........j.^.e.r.
....u..V.....>ds.~.f................`.<. ..s..7.>..9.V......6
...S...q..7.0W.s.....L......,.vf....Z=...'.l..`...`...2.*.....|...5.1.
1.2.....H..cVP...-.}R..U..H....r..lsn...x...9;..........4 v.......|&.
....'k.....;.A.V..9 p.~>0Y.A.u...vO...L....Om4U4.... .%.}.)....O...
..|.O..........e,[email protected].<....-$PZ....>:..@.)..,...;..<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=272825-632390
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 359566
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 272825-632390/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0........)........Zw...Ul......vVx......n.......z.A...A....A5. .b.C Z..
...M..........b!"C.e.".<.~.6`P.....q;.XQ3..-..ck.J..y.......T....(q
...>kIiT..A...z.O...2.....f......~8...U..?..F....................V.
H...D.;.encB.O.O^geU...zEguscakH>..c.{W6....<R.!.SBw..._-qo..r..
.. [email protected]$..J....758..()U..n..g3......9(...
.&.$@&.<....X)....yU.".j.cS=...T..........t....G....R7.x.c.....Dj..
.e.R.......G..{... rH'hWw.4.9....RKE..b...... ..L..._v...$....j...r.#z
..{...R..............0.-......o..'...n u.;.........eN...5..}[email protected]..
....W....A.3.!^.....1.\h./y....I2.[4.6Y.. ..{....".R .5.....@".PJ..n.=
. .....).A`z....W...`...~ .w......z..&.......z8a8.7$....2..^...q..'..I
r.F.Bz#.eI.7[5.......EU.Og.......)/......s^$...~...>...4.y..jb.....
......y..b .;.}K....[\.z~G....6....rTg2...z.....V.<.E.yk.W.>....
..".K.^...........%G'^....B...Yf...fJ...H.j.be........0.F...m.;....I.%
'.z/.......: zP..3.(ga.M=.8..h....VPS..n.....,wa.6m....).".....m..u...
....6u(. ........a.......9...%........2..|E....N..s3..<.'..A`..o.B.
..H.e#.........(...g.......g..Nu.....UIqx2',=`........1i........p.I.Sb
...<\.q..%?Nb..D.../{...vy(ye....%.dL..P=.G...!......`.....k......q
-<.Y...-..%.U/... <)...D.w..z#u......A..gJ...W.O.m...........%..
...C_...pu...#...?..l$...i.....M. ..... (..Td.EL...f..l.|.....%.5.|..n
.y..)D..X.qH$^....3..3G.".4.).q..K%.o.w.Mp..I.w>.,@...F......7~.}&l
t;.Z9..ph....~.o......v.. .I.9O........U...VI...8!.U....`%/.r.|TeDz..l
..pe.*....p..6..[.......C.......}@.M.<..C.w..U...O.T.F.../...5.<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=632391-1347781
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 715391
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 632391-1347781/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0...t....#......C.....n.G...:'...t.... .Qg..C.P...*r.X..x..}9..........
U}..&i.4...j.,..E. .BG..._...Z..5.K... ..b......@P..:.N.....7.1.~.....
/..a6.p...tR.dJ.f....%...7..2o10..B.4...X....~...N.C........l...$.....
[email protected]...|....AO.q....rF)J;...K..w.;....>.i.......
.......Pv..~...D....D.fi. [email protected])/...z..~ f...j..y..fh.9
.r..<.....-....L~!\.[R.6z...........N..<?...B...rs.w.\....W...S^
.(....<e..y..2&...*.....F).r..X..iR.I.R..<......fpQ.7.^iv....,m.
_..).X..*...0.o..n....1.c...5h.lTc/IX..Ls.]..R....|......C...)..L.kq..
.n..U^...t..s..].~..x.*_B_;S...d..#[email protected]..\........o...,T.%'.<
;..,.f.,...........v[........S02.zY.......~JJ.O7..!. .2..TwQ..........
q._~..6..^...XK/F...iX.eT.....[.MG.\mA...~.&.e.b..Q,..k...U N.........
.....A.#......Ev....n..D..r..2.K'......KG.DyN.Qy......r..7RS...K.<.
.|......v.Q..FY.,.0..5s....`...\A....4...`.....#.U._.H....P..._.n.. ..
......RD....=.S.qrAC....)..D..9.k..J...r%.U...c~r...."[.....O.......9.
....B[..6......{~)w..{../.~............V0..V..Sf..<.m.9.P. ....pj..
...o.[..U....Z...'..4........v..2_s....n. 6.R.....B`...K.0zEQ$!...s.S.
..E|.....@..~....v.O...o..:..#.uP.].!a)..n....l...O...W.d.T.i..j..P...
..O.u..-k..Zj*)...{.......=m..*F....b...QX3}......f.....r. ..dGe<&l
t;UL._v......:...Wi..^... .dZ..8..(..Y._......K*.......o...g...b.\.U[e
@..z.W...(2."..>PI".Y.......l>.2.AN..lZ9.,.<,.H. Q.QL)U..._..
....`x2.....z u.%...k..c....n.....r1..]....8L.)...rO..U.{......:P.g.K.
9..3.....ce.8..-.R.v..l.....)-......7....k.....h.p..A.^...:./....9<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=1347782-2784169
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 1436388
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 1347782-2784169/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0~..Y.H....ag'.T....Z.`..R}C.;"{`..$.......*.y...l.."?.0..g..&.L....."&
gt;.........tl.]O.P.......WP..Z.>...h..M.e. E.^..ZqP .<)%R......
..i=.."..N/.....yzt.e.....%[email protected].....
b..4.X .&.......O....-.....q...~..)1..o!..Nq..C...F...k.w..oI....b..A.
9[F7.<.j$....v.|B..B.Q..."o.}.E....z..C.4.9.v..)c....-# ..[S.....&l
t;...;.. %kY.<.@.[..x....q..-...7AW..N......Uu\.^..|H.`l........F.X
.......1. &..H.........`..0,...7..w>C..R&........(..k.Z{`.(!....j..
....hn.....H....{l.'x....*.<..../{...gR.....u..a.......7S.-.D...r..
..kU.9...;..vE........3.?....)..H....o...( 8_8........CN.....M.....1.~
.]...1(..d.7.c.....z.......u....'..A...eJ........"S...nTa.y..D..\...(.
..../... S....jk!\Y.....C.2...O...t-.. 0..&...ml....r<J....T&.7...Y
=9.N}g.0K'..T..x.1..4.."..-tk...w6..T#.|N....3...Fa,f.5..6......(.9...
...8.._.?..n.B.o.{..W~......i..Rv.y.S.L.......U@.....].......U.# .X...
v.E.rDyPw....l2...)\1........$.'....\...k...Q....D....o........<..Q
E.....I...H.!..vC.. .....V4...gYR/.YU<.o..o..9x.37I.xp..b...._....]
...Z....(.%...%W..z..W|[i..'..9/:*.NS..=...^..vA.X,.}T}.8.4.NG{u.X.N@s
...~.>....:.eh.?,.^......D........R.....D...i..D.AKO....$...D|x....
"IE...9#..P.<"??...X...7...;.P.. Y%.d;_.>.s8.0.M.3\Th.....}"....
.......z.)...j|.k......z....}.....,.A.._% ..$5.......4..........2..x..
/q...S_......V.Q.....M[.....{.8.6a....._1....Q......_..2Z>[email protected]
>^.zp.4"\.|.q..q.l)..o.eq...=yN.u\...F`....hz...KY._.!.u........_.N
.u6:.F.K[.].je...O.k....q.............@....@...@Z./z\-3"L'....M...<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=2784170-5661761
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 2877592
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 2784170-5661761/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0%.Q.'....BAO9i...'..r.=&)..w.4.m.w.......J.....|...........O~s....Ud]
..tg}uD..Cg.cU....6v.....mn../j...1..)'....h..KX..$.^.w*j....?. ..:>
;.{{.s.Y.. .#...>M...:,...\..K.GW...... .w9.-u..A:........!.3.a..\.
@..9....A [U...,......?........Sy...9.f..5.>.J.....)....l.....d..|`
...0y.;..y..........Y.M.r.j9......j...3..K.F..It.U.K....>....5-F?5.
. .o...x3.C..gv.P......4a_.|.`.....1 C.......f...d.Y....]...^.t6.H..FP
P1..y........;......zP.H..O)Z8<..s.&..ov ..~..'[email protected]
.8$.oG..........]g..F..8.......x...&........$...9DP..:~.j...x/D.../4.Q
\<V..G.....#...X. ......#......C.......u2......5=2.^.%.....Q*..N...
($............k.....O^..z.m'8.2.X........;?.DRt...}.....h..F.....w.bQ.
XC..N..,K.Rq.h....U{.n....n.C..z...5.LC.J...aR...7T.!......F......\...
..W...D.h9.R..?U...1mJIX.VN...n....t..~w._U.\.z........u)..J.......j{.
.b....w....`....6..j...".7..........d.{...9.M.c`k._......W.....8.ept..
...B..B.}op......=J......W..ROGy...6.."].....f..H..GmDe..!&p..(.7..!.Z
..{g...h..n..-.......3u{.)....?./....$~s#...|.C?.).c...:.[.luH..7...P.
..X..G. ..........*9..o..r ..4...E.c....|r.8M...,j....-..u..&.Y.....x.
........v.....g.E...]. .b.....E.......T.....&...JQ}../"..........`Z5.\
.K.....M....c.)..k-.p..,E.....^... E....KN....cV.[1..4.....D...j. h.Cb
....,Q.L..J...........hD.....-6..~.]YL...MI.3...j...1..!.......7......
s..6e.|.../[email protected]..........{w.tR...Z....O.../S...[K.,..;
..,@.<3-PP#A..c ..=.o..O.,..\..=,......D..}D..;)[email protected]...
_. ............ `j.v..e....g,.....[f...yG.q.( ....NH{.)6q.....B.B.<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=5661762-9438801
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 3777040
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 5661762-9438801/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0........Tu..o...ZF.....M..........P..g....E:...../.S.X.....A..pK.CC{..
.3[....m<B.y...s...^......m<.(...q.|}.6.q...,Axc...z'..._...Q..B
...`.d.......h..7...../....`..].....>.TJ:.h%.b.R.._..n=.g..Z.3r..w.
..X..t.K..{.)Ev.z..Yr;..O.TX...........]..'.....iO....[$.. p..[.F..d.z
W....F.......:b..M.... .O........s........D..hyz.@j..(....L.....~G.a..
.. e.....{.Z{}.U.......^.........o.aG...%..1...R.u....CZ....r#v.M...mT
..@.%.&_........[U...|_p..n..O.H..3......W......*.i.....{..:....A.....
.1u.G.lL7MdZr`....'Y_^e..C.~]....;..-!....X..b..... O...46.].V...qa..Y
.........!..Z.8...I..7..|..}&......Rk>i.9...I.D.t..x....r..........
..fQ>]....!......'.................U%<#../.5...C Hk.......Z....o
..1....nC.....-.."/[@.f8..5[^!pP8.....z....hq....>..A..{].M[r.0...z
..._....}L.A.> ;.....n.}kfym.>........,.......g'.YpHv..L......0.
..V..`^...E.....2.ec5..y...E.....&^wdB.L.U..`..C9w.X. [email protected]`
MayYs.!.jX.U.......Z}w!.w.7....l...`.F].:.O.t.....3...5T.......y.... g
0u....M. .Vb....Q.. }l....&A...1l.;..at)r..WJ.m....)....].....v:k.....
EW.nZ.xWHW......t.......:.).h....HkB.jo....e.eoFI.U..V.^...6.of......r
.j/A`.u..S.:$...".8.-s.....H.I...s...%.miPZ.... ... ?P.......^..o..*..
0,9..N.........@......"A......K;....".w...h......\..IT..S....c..c...UU
e^..2.x|....Io..).....]r.\.............{..0)..9........_....U........`
.;"?.v..f..a........ [email protected] .?0.J.CME...
....C/.Vm9..a.......=9....&w.ke......Az!....s.I.~...).~..p..%B..F.qo.f
......;....\.i.......".......].E..e..b#.)V.2..#<g"zre.j}......W<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=9438802-21072245
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 11633444
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 9438802-21072245/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0...QvV.....e. ..:=...7.V,..w.!....j..J.Z[.Y..z$.>.->.UP`e..S[...
....6....Bl.^.~y..F{].9..._...[B....g...P.A,.~,X*...@.:..._...._..).b.
.i]..)l@3O\.m.......|nJ...O..Fd.'.#Vy.I...bN1.b.z..;<...;km&l.czU..
.......Z.c[I..P....b...!.W....b}k}....>0V8.P.'.5...B.1>zP6s.!b..
.AM..K............&:|KR..@5 t2;.......y.v1.E.1......)|.....Z8....S....
....6. o.d......am*NQ......}....."`k.J....8h.e...../...SNc...]....z.C.
a..iS...7..s.N............./T.....k0SoY^RdK.T...J......l"p..AJ .E../..
k....g.b/?.*.~..}..../i:.:rYdZ............/.....;L..W!.-......'a.MV..Q
x#S...$g_.......lS...a..Jut{=.0\.}.;.I.....?.;i.._...]4. .....'.`.32)x
.00.V.....`.cg%.....J...A...*.... n6.yAtA .L.T..[.}-.x.3.Q.\.. .....KD
...!..c}..}<@\.;.....I...."........~.du.{.k!..w./]p*...h.......&...
.......'3E.l........z@Q..?.%[email protected]...]w.FD....W..v..D......
b..9..pJ..<e3.Ie..m..M...~..}.1...9*z...K..y..h.Ar...4.....6Cz...b.
......=.....#[email protected]<....lX%/u\I.U6....M\_,...........
.. ..8.M7...Y/;.i2^C.....w."........@........'(s').&.....ue...Y.8...B.
...:.0...S.y...X.:......\......N....Ni.C....S....Z.JI.m.....9..K... .`
...r.'.!.XV..7..._.$4,Q..g.w...o......7.G....yQ......_...Sj...........
..Z1.......Su.6>...G..PL..O.q...:......U.......0.;Q>V..cY.yx....
....]..[&.9M..\>..wy.B`..t...@\....=.g.{.=..TU.I...J..._...K..i...L
..!..D...&[.....v...Lg.b...s.-x..`.[4....0..`..^bk1..Z.F.B.|..h.O${..;
.....6....91.....l...J..J...J.EE...z4..C..B.K~S.w?..}....h......c`.f~.
.=.w%K}._..........pC.%.."J-..a.......N.~~QH...AD.V2..MGW...).[.W9<<< skipped >>>
GET /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 28 Apr 2015 17:23:00 GMT
Range: bytes=21072246-41792591
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r7---sn-3c27ln7e.gvt1.com
HTTP/1.1 206 Partial Content
Accept-Ranges: bytes
Content-Length: 20720346
Content-Type: application/x-msdos-program
Etag: "5358c"
Server: downloads
Vary: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Date: Tue, 28 Apr 2015 18:08:16 GMT
Alternate-Protocol: 80:quic,p=1
Last-Modified: Tue, 28 Apr 2015 17:23:00 GMT
Content-Range: bytes 21072246-41792591/41792592
Connection: keep-alive
Alternate-Protocol: 80:quic,p=0})h.....$.6.....(.?.v3e..)*.).;...|#C....Z....e...~.!.m!..f....4B..Z.2
..-.^.*G.I...h......%..e.......4*.&x...4..f..........[.I4...N..g......
....l.....e..6......]in.._........P!......~!hK.>..p.7$"'....s....}M
t..en.D..4a..K...I'.:.N...&......L........O...J....u..X6R.j. .F.3...E.
..Rt!.Y#..jZ.F..b.....qgh......$.....[....?.pA...?..oj<..._..x^A.p&
gt;pI..S]..8K.N.....B..:.........4N^....%m.....v........ ...91.k`.K-&l
t;...u...d..0......h......%....c.6O....kb. ..~2...=(...5.|...'.6....^.
yhHj<v.w.h.Rc. ..`..]}.SK[().....(..Z..|Q<."....). aE...h...2.NV
..S2..C...d.w...u......bC1g...=h...H.H...s...5Nr.;...;.i .......`.Z..S
....d*$*.Y...x[....,....=.-s.$.2....tQ.zb...`Z./C.~......_..u.KH..cUr.
.p.Q.......*h^..|............R0..;.m.v.xk..............HO..Z..>..7.
I.5.....-..J.l..-.....L..9.3p..z.y}@......:.}..5d.....#....T!....;.<
;0.....g`jH.Y.......Fw..!...7X.&...q.b|..Pu.)..3..u.x......Z.].a...}..
.~a.6X..j..^`.b`._.(....R.X..i..&.*...\5 .J|..Q...I.:a.v.9.-....2k....
S4.awx.C.>D.c.i......=....?;..../....q...`.?.B..&$..V......|..)..C.
..M......>`.....Lu.:..-.fg..6.$...5.E~.?.p1H.X.....F]....(OI....Y.G
}...y6....Y)..m$.}-...??H..8uL...t4...a..h.=..Nn>Bs:c}6....p..5...E
.....'...\....c%\..Wu.U<m.....s.....b*...!..c".....e*|.....R...Qq..
.. ....^/.....Q...w....i`&.=.!C....s...rDw7...Q...=.!..c.$|.F.cYu..6[.
E.....rw..^..aV..W. KUJ..:...... ...J9....`=o.yDe.....SK.5}....V~8D...
...J.!......N{...<..j..S-.`b....5..Yd..D.R/.K.....Y....I|P...6....I
.Tc..O..Q..ZW.>.{.O..8.(.....(...BrhR-\{...}e.p6}..!$1lp5..j.G.<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEGO+CyDUoFQBjrKVo87pCRc= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=544652, public, no-transform, must-revalidate
Last-Modified: Thu, 30 Apr 2015 11:40:21 GMT
Expires: Thu, 7 May 2015 11:40:21 GMT
Date: Fri, 01 May 2015 04:22:49 GMT
Connection: keep-alive0..........0..... .....0......0...0......N$p...v....1.;..vn....2015043
0114021Z0s0q0I0... ...................F....0.yV......{&.K......&......
.c.. ..T.............20150430114021Z....20150507114021Z0...*.H........
.....>6K&Pfq...g.MF....Kp..>.-.3............Cpa.X...\...........
2..W.c=k6m>.z....SB.$[s..|#...;vO.6......'$.k.0...H.4.`...M....Iq..
.&...1....i..!..'.A4.l.H..... ...".p.r%'.r........,...Sa.b.0cx.Oh.7..Q
.......Uu.(^...q.9......bh...Q.".y..MO..1 ....s......\....P.....0...0.
..0............F...I]A([email protected]...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of us
e at hXXps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Cod
e Signing 2010 CA0...150225000000Z..150526235959Z0..1.0...U....US1.0..
.U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1VeriSi
gn Class 3 Code Signing 2010 OCSP Responder0.."0...*.H.............0..
.......q<...A...#......A...u..Lz.............o..D.vQ%..s.......f...
.e../jI.d.W.....|K;.j5...#.B%.]..~S.... .|;S.&.....N..`...5.....!D.p..
..M/.. ..;j...q..`6...2.Ck..BnLHvCZn%....,.w.Ooi..z'...\.Yx......b..L.
..5.o..o..{..}.........%e.....N..._i........*Bc....:yQg.........0...0.
..U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.ve
risign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS in
corp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U
........0... .....0......0"..U....0...0.1.0...U....TGV-B-31830...*.H..
............-..^.........f.P`...s.....8.....V.......... .... B.(@-<<< skipped >>>
GET /gn/468/farm-frenzy_71x71.jpg HTTP/1.1
User-Agent: Game installer
Host: mpcstatic.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:04 GMT
Content-Type: image/jpeg
Content-Length: 5358
Last-Modified: Fri, 27 Jul 2012 11:07:29 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:04 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes......Exif..II*.................Ducky.......P.....)hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
1 64.140949, 2010/12/07-10:57:01 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM
:InstanceID="xmp.iid:4A7C5657D7BC11E19EE8EB24BD6AD373" xmpMM:DocumentI
D="xmp.did:4A7C5658D7BC11E19EE8EB24BD6AD373"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:4A7C5655D7BC11E19EE8EB24BD6AD373" stRef:doc
umentID="xmp.did:4A7C5656D7BC11E19EE8EB24BD6AD373"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....Adobe.d.........................................................
......................................................................
..................G.G.................................................
........................................!...1A"..Qaq......2BRr#b......
......................!..1AQa...."..q...2.....BR.3r.S.$4............?.
.|.&.2...'.e1fj....2...EJ....T%[email protected].;v...v".......?....A...6
P.?......*..'...J.w$.a...{.......:.Z.W$..H.d..'.h..!...~.*m.....K...2.
..&.%...j#o;....Y..h_...W.>Uh.'8(>....W-.....\.K.,.Cc.%q.?......
'......`...m-....1X6....._l.9...Z../....@.)IQ%.._...<<< skipped >>>
GET /chunks/goog-malware-shavar/Y7Bbdz8_yw6v_bqO-aA6L91DCfbRovNLkVFMxneEoig=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Y7Bbdz8_yw6v_bqO-aA6L91DCfbRovNLkVFMxneEoig=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /gn/111x83/1819_111x83.jpg HTTP/1.1
Host: mpcstatic.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: image/jpeg
Content-Length: 10165
Last-Modified: Fri, 31 Jan 2014 17:29:33 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:23 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes......Exif..II*.................Ducky.......P..... hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmp
MM:InstanceID="xmp.iid:0C5F2A12697911E388FEC239E1BD522A" xmpMM:Documen
tID="xmp.did:0C5F2A13697911E388FEC239E1BD522A"> <xmpMM:DerivedFr
om stRef:instanceID="xmp.iid:0C5F2A10697911E388FEC239E1BD522A" stRef:d
ocumentID="xmp.did:0C5F2A11697911E388FEC239E1BD522A"/> </rdf:Des
cription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?
>...&Adobe.d...........................'...........................
......................................................................
............................................S.o.......................
....................................................................!.
.1.".2. 0AC&........................!1A..Qaq"2..#....BR3$....rs.Eu0.b.
.S4.....................!A. 1Q.a..0.q..."@....2r#....................!
1AQaq.......... 0.................1.....x....w....... 1......n....z.-.
........=..5..#.9.0..]...Z!....$.....G'. ....[..I...b.......,[.....m^.
.....z9oYL...SC\.....9:....;..5....Md(...{.4....68>...E...s.r..<<< skipped >>>
GET /chunks/goog-malware-shavar/FFVlibTAzjsLur4NAXQOZA6peE6IVXVI3LCXkKUctgU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/FFVlibTAzjsLur4NAXQOZA6peE6IVXVI3LCXkKUctgU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/vDwva6A67JGbzpy7VPkWvdbtMgYd7qMQ8rFwR2vbEUA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/vDwva6A67JGbzpy7VPkWvdbtMgYd7qMQ8rFwR2vbEUA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/RbA3tgllhVw4uoreA9t0dnot91l0x4S0xbKnKLSSklM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/RbA3tgllhVw4uoreA9t0dnot91l0x4S0xbKnKLSSklM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/HcTDZdOAqbjP60mqsUDke9Xw0HITGpAZnncOOQKDDKQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/HcTDZdOAqbjP60mqsUDke9Xw0HITGpAZnncOOQKDDKQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/DhmkbGq3IqOmH688Cmt9YunECJJ_kvFlB6mcbV-E4sQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/DhmkbGq3IqOmH688Cmt9YunECJJ_kvFlB6mcbV-E4sQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/POqsACfqD9umXojHJh63f3wzdU0jArUnh2RZWVlPo6U=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/POqsACfqD9umXojHJh63f3wzdU0jArUnh2RZWVlPo6U=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/nB0tjQFotnc6cc-qs7MVBADJ66-XV6kfwDsAr-8FW9E=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 5955
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 03:30:30 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11909:4:5940........O~P.....O.!.j...xj..b'........).k..xU.%..7.-....
....~oT........:$%[email protected];p
...u.......2.....g.\....A....A\-,O...[.=6. @./...r.W.L...p..b..0...whO
F....F.........|10.Cg...........Rt .......rk....B..'........1...D..@..
l....7...........N.....`C.".$w....h=.N.Af.N.Af..Ho......*i....../`.MS^
.{w."...2......=D.....h.a,c.W.. X.^mnb..YB.z...j.....u}H.....S.....c..
Dz.....$b......Z..W...\...w...wE.t........N.......ja.....k...P..._..'.
)..a...4.w....e.z.V.o.%....V......"........l#.#Hp..I...M........6E.%..
`?.../....L,`....,.....u....c...<.....jz8>\[email protected]. .......
zh...N..>P.....=.^4..WBa....$...a.....\....L........{Mq.....33.....
x.^.$.......)EN..-N...`p.=.$..(x...[....lN)0...........`....g\..e....k
.Y.c...r...q.0c;...Fz.U....E.....S..d.........Zq....Rz.g.....E}c.2.9-.
B...u`-... ..u......U..%.k.. 2.^k.....vDKS.wiS.v:;.Y....(..&..&$.C.(.H
......p........e....]._K..r@...$.d`..nR\v9:....f.J...Z.[...(;.....x...
....Ot:...B..2o...O.....e....;N..[...._bf`...PP..-........]`U._..z...e
..@y........./.LS....j.s l.b ...3JK.......y..C.n.A.W*.A.W*-..X....q.@|
... ....{........4....H^.:...2_.,.......$.N....~A.cp../3{......;L.h.U.
. F........r^.. . .....f..lc.a..#...s<...X......W...`......1...o..:
c..-{..B...T.....'[email protected]...}>.C.~D..&.R!.....qH.5A
.22.(.X.d......!...g....g..d5gv.1_..P......;t.@[email protected]:.0.e
!....kr6v....qD......x.....a.. .....R...@.!{...C:.R.{j&o.f..?*2.>..
.k7|.......fc..G....lo....o....9...#xZ..........s....s.....8...k..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/S68JNpsZmJZq6F4upq2Bd2Dw4N2MAoSZ_bdHW_x4e2g=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3586
Connection: keep-alive
Last-Modified: Tue, 28 Apr 2015 01:01:08 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11908:4:3571...u...3&....&.Q..^P......J...&.....;.....h_^.}y...i....
.]T...n5.Mu7...r...uN.tsm...&..Y........D.%b/;.!>/.~......gO...r..P
....... ......`C..D.U...K......j.T_.....H.........(.9.&...y..&..j...wt
.uJ!..l8..p'....r<....".9...8&?................fO.....4!.....#;....
.?N...K;[email protected]..#......T....T.$...\PNQ......S...../...T..S...w..".{...
H[^A...FB<.g...:.6so...1x.J./t...X.......V\..^..2..&....`W"..f.....
..`...F....([email protected].`[email protected]....{.(.]..........e
.;...$.\S.Fg..S.lR..k......oz...E..\-,O.Z..3..P......j.?=..T...^....^.
..F.#.,........Z..c..#..w..=.F...UY# ..DI.....(.k..C.w}.....c......=..
.............9.t..Q..O.._.m.&.".....J.59J....e...JG..t.p.......^3...K?
..N.....j.u...%9...I.`;....^....3...8b... ...ZV...JV.....a.".g....Yxfu
....|..M.......]j..!......n..i."Zl9......K.Y..W%....fp..X..j#.3,e.....
..Le%...W..}[email protected]..........(.b..r..AxC*...&...%1.G........
Y...nFM,.......=.u..#k.c...0.fS........Rs8........P..az..(.....P.].# I
an..bC=......S.T.X..?..~[...j~.<c.....3......<t........l.......#
.:......."...,...17...N...A.v..j........}.4C.....m...if......a.r......
.....g...S.\...Na!%.....hY...).LG.(...yy...N.Pg..........8[&.t.B..U.&g
t;..'#.n.......d6...\.7.d......%Q..(.....,....!.....v...3|./m..g2b....
..U...L..`.....U.L...C...C.........P\....fw.Q.l.K...v2t .z..2...Q.....
.._D...)..."x.......6k....Bl...JJKr..(d'..,....91H..DL.3....R6.....,..
....Q(...O..o9...W........./..t}.A7..U..........M......J..k...........
...r.D7@._.>....-.hsq....s....j...Nr.....3.).7.."..b...X./.^...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/BC0-t8qDOZWMvEUrn6JXSuUN6qhlTVaqNx79F0rdNVc=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 21
Connection: keep-alive
Last-Modified: Mon, 27 Apr 2015 13:20:40 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11906:4:9...k....k.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/lF47Sh_HLEdUNiXpguEQ9zZeeyjhHFGZNZVIF3fgnXw=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 21
Connection: keep-alive
Last-Modified: Mon, 27 Apr 2015 13:20:40 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11905:4:9.7....7.......
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/5S79mJ6464OwK7yKBT2PYdKWEZ4aQHolIEUHr4Tzyf4=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 21
Connection: keep-alive
Last-Modified: Mon, 27 Apr 2015 12:30:30 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11904:4:9...k....k.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/VR8x-VIlD9su8cKntNAkoMX85wo3_9pJu8jiDHcZtHE=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3406
Connection: keep-alive
Last-Modified: Mon, 27 Apr 2015 01:50:29 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11903:4:[email protected] ........J...r...ae\g.F.z..
..f.b..1r.G..&!.T...u..|. ...|....|.........=.MB..F............f.....A
.............Xh"II.sU..../^>..J......["b.....v.W...xU...........(..
*.....C.O.[...x..z.k.y..'! .cf..&...f.n....I.J.KiF..~..q0...p.3\.g....
.4!...McR.[."...J .......f|[email protected]...
.....^......;.0..r~.....;....;m~S..N_...%.!..jx...T....4mFa?..........
8..W.t.n6k...ZZyXT.h....<...jZ.P..<....(P.. .... .....-.....>
/.~....X...s...{).. b...9a...@....@.%.....=.O..L..#r..>.B...t..j...
.......w{.....~.,d....... a.v..a.v......X..?eb.^.Q..<T7.M.WV..'.(..
.c]..[.z..k%........?.'u..>.....E..G................D.....A........
....J..Z....>[email protected].....|..k.&L
..$....l.1..s.. ......./.g.........j...n.....j.o.....m.=D..c.$c5.4i]B.
..s....ML...ML..#...B.|.......Na..X......q.....c.S s.#..4Y=...w.P.....
o.K%.B....v~ 4..Ngp.Q....................-......P.V..6.Jq..'.q..'l..O.
I..0.....v.}...n..jw.....W.4^YjIan..H......-.0..hA.SF...U....v..f6..s.
ME.Q...'..9.x...q..t?..#.:.....S........d.$...k..N/.n...C....'.h...7.{
..|...5.aaS.\..O...;............._........(.....:.j.mC...E..p.....(...
@......_..W......E^....f.....I........-.b..b./.X.....Q...4o...s..#.6{.
83(..F...m...2......"*.d....B.UT....62..w..U.9d.56....6S..-..v....w.g.
2_.....I.....#..../h....[....N.......D......4 .E...x...F..*][email protected].
.... .... Ba...'.#..rB..T8.1.i....i........fm..<.v.e.....^.....0...
........j.i..l)EN..).......T..G.d..P.~._..v..p.S....C(.,pd.S......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/KUfgkRS_-x-xLthI9bemI07LuTOBbdjQXJVT1Gcc8Fs=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 21
Connection: keep-alive
Last-Modified: Mon, 27 Apr 2015 01:50:29 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11902:4:9...k....k.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/JfMelIF4lIIljMS8fg5WquzqYqSh-C6DIxDq6ByNvqo=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 5186
Connection: keep-alive
Last-Modified: Sun, 26 Apr 2015 01:10:42 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11901:4:5171.h.W.........h..-.....h..b.$=.MB.oq/&.....M......F......
,'K.W.WPCLj0...l.............*....*w/....V*z,..8..aY...z.\K...\K...%.!
.,.....3p..\[email protected]..\.j..Gz. Xi......U...@./..a=.m..?1...~.x.H
.......0;@9.....h...8$.fxP..\y.....N........F...k....k.....gO.......C=
..U....>.. W.D......&b7..H.........9.P..C..A.b'...l..v.(P....7....7
...m...F.. .N.......".. .[K.............L...x.c#......f............A..
r.M..O....O........O...T....T...O.O..O.O..R..\..=...m............,.$M%
...].&.......*.)EN........8s.j|............[c.......r..... ....=...-..
.2....2....'.*1.....l]...T.Hs..D..>..a.|..Fr..FFc.C....>).K.FYU.
%D...Z..}.....[9.#.../2dsk..@|.'.....<..:.c.....S=jiZEJ..6.S... ...
.;y.w......!...c.(Jb.......c..$....-..\.[[... q..O....R..J....y.q...MK
B*.7$..uz..r..h.0...).....l....&..H.j.y|..=...,....T..0.'e<......zs
.....%.~.._&C.j....l.Qt.Q.>......i..k.gk^..M[....<J..J..1..L.P..
...O....w9..KD@o..*....2s..F...gl`.@._E..8.....1!......u...m........$t
i.5.........'.S=Xc......&...B....3%"..G..z".`k%V..........L..H.......E
..:..........x.....;...670XgH.k.L..Z..r^...D1..9B..W....K!.....f.m....
.FP.?(..Nd.V..x....].._R.X*Kr.j..X.d.B{..5.......9.O..hhM&.....dlv....
Y......8OZ...-x.v.4..8pR...M...mC...9..p.TF.1.yq...4b..".b...uk..K....
....._.q.][email protected]...>.B.8U.^...#d5.e....<
[email protected]*.5...i.s.f...tW.~.*R.."..S......./W...
...........Q%...|.-_.]...&.8...m~S..RW.....%.........%.....}..'....IV.
[email protected]......,#./h....mj(`l..T..z......=..s.b<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Xg-BBhKSb2OnBWRaP9C4JWVmxAKB71AgLuAzzo9JV-4=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 2321
Connection: keep-alive
Last-Modified: Sat, 25 Apr 2015 08:50:29 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11900:4:2306.{}...[[email protected].{6....u./..iC.Y....%.R..\y...h}...n.,
.~.Iw...).....m...;...4.e........q.\.*.....Q..]wa..y`...e....p.)..`..t
.....3..X...;.H...........x........?.b.f...${. ...g..%JcS.....Q....e..
.t...$5K.=.v..]Y...E./.wu....x..#...-...._8......v.yc.....Ut.-C.......
.7.S....k?.#97.w.[....".............e ....XT*.=yp5.... 5.~... .E...=..
BW.........Vu....nP.....{.qkY0G....~B:... y.x......w.V..9e... ..;....;
...Z.%l.Mn?n...F.LE..7.lU...[.z.?.....kz.......r.~..........V6......C6
....1.........C...2...].QY..............7.c.3.?.....V.3<.....an...H
;.:.-.~!A^.C..&l-........Hmt..$BwN./...42..c....r=.d.D......n.....n..'
..:.V....*k..n..C.o...K........]g..MM2\...~bpl.U.j.Z-].%D..g...w.H..r.
.@....}}\moY...~ZD?.p... o9...D....b.^....`...;... ............>..1
...~HA..j..`...E.T.=;...F...*.w...a...3..IKN.......6.'..a.......F.....
......."..p......(w2...m.$ gc.ac..F.`........!..|92.T..IB........U.{.%
bI.......@hd..*...s.;.....h.u.........%...u....Z.g]...). .......9..f.
. 0..A.2...>..Rl......#.......U.........*..T...G3..R...1...5.rT..Z.
.N.....G..rt....2...vy...\.,{.b...ct.....W^."...<.Y1}....|......"oF
P......y.6.T<.-.. .*..T...=o..Z......o.._c[....g...K....DZ.Cl...d.[
.M..)...$...v...................12...'....7..S..:o9w.:o9w}]T../.9.x_..
...g...|..Ke..f....9[...P....)M.z8&w.z8&wku.x...x..8.E.(............vN
0..4.%0...G.:.wQ&..S.......V......0.[A.L..r...H.^........^.s...I8..G.x
.......4...`......ZTb...u-.?...c.@......... 3.^..e5.<..N..vd.\U....
l..........([email protected].........%V<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/V9yxb_-jWRKub_r_OycXW1yI82vShiVrr6LGvZYg2PI=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 4329
Connection: keep-alive
Last-Modified: Sat, 25 Apr 2015 01:50:17 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11899:4:4314..U.......Qz....|....!....:.=.MB... ......dKLy.a....a...
..l..5VmFa?....e1-..A..._7.%.....=..t."[email protected])..*
......j.....{........{.W.D..].Q..X....zR"Q......u.i....N..,g.....r.{..
P...3.kh..i.G(6.'.C...L..Q..{3....8a$..)..r.%4#.............mcF.n..J..
6...|[email protected]..:\..p.r }..`....#J..O.F.=.
.........e C..e...e........eb.^..P6v)EN..#....!<...'.J$y.9......r..
._.!.RIj........-b..o....l'.....&..n.f..b.=...v..........Ir;.&$...&$..
/JQ..A.='.).....l-....1d...`.........a...hY...3.V.8..v..X.....'...9...
.}[.F.t|.....o...".G...6v%.F.....<..\..BdvX. ..F...m.6/.......[....
..)....jb.|...DG%...m...-.d..U.~..}[email protected]>m\..O.I.j..~
..Y...d./:a.{s........:.......g.L......S....S.....r^.....!4=..T.......
...o..W.........8.A..C.....L.....c^.....)x%S.P. G...{..w....%?..C&...K
.......o......Tb.%...G...S....S...'.7....>Z..H.[v.v.'..E......J`...
...}..UC.{.....{f....IS......HC....i;..YL.[.y...A..e.x......DR..t.%..a
.J....\%......R.EJ>..W.8c.&......Bf.n.g{...j .....n...P|U....x....H
....S...\.6.C....pl.I..#c.../h...V........43...^.......Q.}..Q...K[....
b'&.=..z.{..iq...)REO.C.....2.rT......g2E..m.3.wC........k.....=.Z....
=....q............f..*E........h@.;..nY.g.J.bM.....F.......... ./...h.
...r2.f.vCE!....k/.uJ!....~...s............&.....u..(...07...i4...aN..
4].7.)..-...;.{...6....|`c......!Ij.?=......=.v.p..........T.7-Z......
..B7../.4..J......c...x.7L.3...% ...JV.........n...3.....^....oK...*..
..# %..F.....\..C.......[... .."H.......=.17......QG.....d.s..u.&g<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/63xhlxiFMezs4dQO2Wo28dlZUouaROKHvZDLwt1eVSc=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 21
Connection: keep-alive
Last-Modified: Fri, 24 Apr 2015 19:40:27 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11898:4:9..\[email protected]....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/oo-e1VxPfy8b3acjW9TlUivCKwFQYTLtR_ZXD2Rt2JU=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 543
Connection: keep-alive
Last-Modified: Fri, 24 Apr 2015 02:00:47 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11897:4:529.R..o....]bl..........E......eB.P....xK..4......q....O.T.
x.~.N.. ........Z....A/.1I.2".....T..3.L,........R.%..M.zO..y..... L..
.3.C].4..........yH.(r.Z..O...?.L:.rV...ha......G(..."{......,A.P.g-.w
1...y..p.......g....g....j..`.= ..p.c_..w/.....N`%.........>..j..).
....#.6{.BM..t..qe.......A<..C.....v..b.n...oJ..........a.GU..W. 0.
K..{..$-....cJH(..JH(......g....2K......Z...........B.%._...?1... y..s
...;(.......L..fiY..........y...fO...m...1.U].....,.. ..1v.-~&......-.
.E..r.R......J...bM....2f.....J.e....c.FM.7u..d>..`9~.......
...
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/KyMR5Wziz02ixCTmA22bQKsv6wHxPwj9kjtJ_lLVou4=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 6011
Connection: keep-alive
Last-Modified: Fri, 24 Apr 2015 02:00:47 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11896:4:5996......9........k .U#.Am..3.S=.MB.j............[qKY..d...
.xU.uG'..x7`..w....T....Q......(. .......:1....~.........%.......$....
.6.d..V*..Qe..F.$........F..D..(..*..q...j..k..x.a.%.!..[bK.?.}......?
.}.Sw;...g.....*F.~...s..m..V..3......Y....*..1....].{...K..z..'@9...S
G..O.._..j ....Y..).e...t...........|v...'...5.o_..9...-...^...Mt...{.
....R.a...........".f..*[email protected]..*"HD.
..k`..j:_z....pZ.%.N...b..w.......*.......q..$:'..n.Z..L..2.M..."....o
DS.\....*R..... ~....^...}&.e..R..a<....EiD./...K..y.<..4o....n.
..`?...W....C...g...Yv..._..q....V.O.t......C@..,#...G....}\..1#....1.
.........*...h .......\3.)EN..#..0.u[k.Y.&.V.np...Y.<G...Qn...c..G.
...k-E.......Bc.U<W ..]..iw....j.E.."...o..g.......7..2..)...~.....
...X......Z.Y.......R.:.....w.H........$.....r^.KKW...W..c.j........V.
...b... {..Zs|D=...F.C....zG.../.9y.........c...mC.....ow Q..Dfo.Y0...
....EK..~.........p....<....h.i..i.@Do..'.7......W..J:l......<..
..<....57.....A./.;..6.b.z....:.Z.K`H.,.c...i..\....A.......w.#..w.
#.,I......U....U...uA.I\.......a.a.J........1...>. s..."X.5.....3W.
.Q. [email protected].>.4....P|.".l.I..7H@k..^..h.MS.g.t....f.ms,s
.b..s....a.T......K[...Vi.....Z._..r...j......e..&.........L....Y#3A..
... .xr......Z.....Y.&.....3...E..... s..-...=..jLB7...>..!W......m
[email protected]../<K.S....S.....r2..B[0.Ka....I...P......'
.....9.../.)....&52.....|.1.......Lt.....uJ!..?h./k.)D ......A.X....s.
.v.d..:}..]Q.......4z.V..b..@.\.p..q.P}...^K.eX.;...u....@........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/jirNZVS0n4RradSHkZnbeYzGa2hV_bkuj5A7qemLfn8=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3933
Connection: keep-alive
Last-Modified: Thu, 23 Apr 2015 03:20:15 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11895:4:3918...B....B....N....O=.MB......9.t..x#..N....y=.[qKY..[w..
.....;oj.,'K.......w....u..N......L%....f.dl...v.....T.."[email protected]
[email protected].^,.-...g.?.i.0..n...t.R..k.R....%....%..1....Z......W...b.(_.@(.
k....F.3.j.O.W..O.W.J..I.oB..3.J.,/a...v..'.(....V......_...M6[.......
....q.`{.}.}.....)6...\.....xU....*.2H...~..<.E....d.D..1..P....&./
?.8H...Q...:;z...,..\.!..MR."...}. ..pn..J..m...%K....U...C...ZrAO.X-$
>g.....j?.................1..)EN..Q.......Q8....MQ........H..a=z.
.*..u......By....4.=om...v.=.....\...`..V.v.....A.....7{.T,..q.....l..
j.e..}.7.&...]..c..H.......I.v....W../.-....N...]6@../... {..$^7...r^.
.8 ..L:..L...v..... .=...........H..m.?I.P..S..2OI..Y0...<.Z..K....
[email protected]....#./.;.`lP.z
....[;....i;[email protected].........../..M./..M%.....y.z......F:O..M...].
.o...m.......0........_h.....n...uX...."..^..J..x.u.)-/..0t.z>_b...
.......c....a.T.n.:b......-F.O.C.....y......0xUEw..3. b.....0."%..z.*.
........E....E....Q.......}.....k..|.$..?...."{........r2.e...]..a.t..
QOR"uJ!..C.M!.v.h.o.......|3Z..S...;!.I..m#hvh....^....R............E.
.........z...2....2J:l..r.@_j.?=.k.... .#.......|..Uo#..9y..o....BY...
%,U............O..T.i....._.W..4..p/...e......n....05.r|.B.k...d..V..H
e..o....i.}ui=...,......*....y/........=|..$.9..r^$...................
...[>..........2..X.Wcs..u...Z..O.!..\s3.....awa.... U..f."g)1.rB..
...~.......4.6L9a.=;..Kr....}T...i37-Z..._.d..cH....8N..5.?YX....2..._
....-.cP...\.W.K....u.......,...>&;6....jI....J.PM.H...R#...j.$<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/mMTuPD16d8c2k64LffvorHqu_-6USXYtJeOhBI7MOOs=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 1765
Connection: keep-alive
Last-Modified: Wed, 22 Apr 2015 02:40:20 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11894:4:1750.......;2). ......AS.\[email protected]..{_..u.....d.....@..
.....L.>.o.......3\2...ICB...r2..Z{.Z.."c#....U....m.....Tl...(6Y.n
r..z4.m.,e...U.E.g...r.M..D......,!."..Y...\.a... .IA.x..L....=...S...
..'..^......U......Q....h........."u.6...9.(6.q....D(D......X..d.....V
..).....lrJeG.;.A...r.6....5._P.....P..q.M^..2.._.}Fa?...}.D.2W....d..
.@:.g.4.R..k.,_]..9.....s..[.(">...`.....L..-.....?1....[e....>.
.......3...1....1....L......T1.U].-\.xZ.:P....r.M...&}.k.D.y.B).......
[email protected]...;O....:..k.....%...s.4b.R...n.2..?...........43...'i...
.....PP.....a.)......_.b1.z...s.Y............u......l.....'...d.../q.[
r.<.....p..l..*y~...*./.hV...q....w.F.#.U..2.h.........P.,/...#..'_
.c..^....p.._P....O.8....$.......{Hf..\..Lh..G.x..(n..J......O.!..pJ..
....7.....!..5a.P..-.......2_...U....=9.g...j.....1.l;..l.wf.*........
.......Q....l.....`.X./...{..w......c...-.......`....`.vE......y......
...7-Z.........u...g..'kG~=..".W.........7...l..,"..z.X... .h.0..cP..{
.2..*[email protected]>N.X..-6.,R....k..X....X...K...`....=.q.l..,.sL....7....
......r...............O......`.....n..Xgv..V.Q.V`........r^..9.......=
*..<....`......M... .v."..<.....z.>E........P...g;......V....
....$......:....:.....B...\.vR..G2..,....S^....g..............u......l
.RK.i.6.......)q....f...(.................."y.......f.M....M...z......
Q...BvY.f...H.B...../[email protected].[...UC.{.m.[A...;..=.c..
.K........k...y..?Qc.~v..4...L....L...R..}.R..}_.>.....:...b....b..
.....I<..}..d......f......).6.n.X........2. ......fu.Wx...o.=&1<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/4QA7fZWgrqxa94GQcWGjO3rvLLV-E4WktLOUf4lHHrs=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3386
Connection: keep-alive
Last-Modified: Tue, 21 Apr 2015 00:50:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11893:4:3371..Z....mD)h.W.....yh.W.2....O<........,E...d...}.C..S
.3HHS.;56._.z...ey.M..S....|....S..[.<....2.....aY.t.I.Zm...^.:...$
-..|>..{......#.W...Q......IK8.....p.a..O...].J.T~8-...../s.......v
.P.....;Gk.u..S.\....&.W. 0...\..Ja..K.aj..8.[...lZ8......_.>..$.7.
^.ise C......lgX........'...NT.ja.....k.........:4!...Ds.z[."..O.tQ...
..Xg...dM......T...\-,O...[.=6. ..L....L.#..........P..p...eb.^.:%.".q
....T........ .Q..hh...b.kUu.......[.I......j=.z!.....W..%.!.Q..-.....
[email protected][email protected].$.oKr...c..(d'..i...
...`.1.\.Y%..*H...h}y&.......WK.....g.\..C.........Ds..1........0.*...
....[jwj..x...?v.J.i..=`.s.....0=B..U.....CN6.e,h.....9XX.Y......I.N{.
q.z)o.C.........N3..q.E.'.j.?=../.R. .#...|....|..$l%..#..9y...5...rw.
..-...6.....a..QA..U...(sxC.q"........&O..P\.f.1B...cu................
...A#.....Rt .T7.M.....`..a.`..a'.(...<~..=...D...<......yF.....
.1...D../.]......Z........cJ.....<..*...6]z....x..sc.j....^A.....o.
..\..>.B...t.s.....E:...p. .}..{.d:..Ho......*i...r][email protected]}..<.
...<.....!......X..?...I....J..liU.....4M.R...........j&..[C......M
;..b..a...T......tY...B....?XI.O.%..O.%n.........*1..]U.^.....K.l";/..
.....(H.r...n...`b..3...................m..,...G../G...xU.%..7.....l.{
.mg...(......l1..(..nR\..=\.e......M......E.S..v9:.d.......KA.i.Zi...*
B.E}c...'#....%.k..O.:...vDKS.wiS.Y.......&..&$.C.....q.e.....b.?..k..
[email protected]\.\......DG%O.....e..`.yP..-...@9X.'.......e..@
y..N.....Lq>`.. ......A....A?".e..ZG..#.:...i.... .q....h......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/bY38XvWYcXsoQZ0FlaGOCgqYBcsM8Kjb72fvP8txRBY=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3109
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 03:10:21 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11892:4:3094.Vmo"....1..u...3&.O.....~:_P....)O.........;$.rSn.....D
.%b/;.!}y...i...\-,O.Z..3..uN.tsm.......&..Y.........e.fd..Y.|../>/
.~.......r^...s<.&..W. 0......|.......e C...L^#.2.$...6\..'....1...
[email protected][email protected]..|....T.$...zy....(/..6....D.w..
{..l...X..?..~[.^..2..&....`W"..f........>J.`.......6..?6.G...2X@..
w.`[email protected])....N......X...X=....%p.ù.}...).GYR..k...........(.9.Y
...2...S.Iu.h]..".....J.5.k....k....D....a.@.........$....$...#.:.....
(.k..C.w}.M$..Te.....<..~........B...9.t..Q..O.._.m.&.s....#}......
.VG...JG..t.p.......G...{....N.....j.u..$w....h=.Y.. ...<3.#C .....
..E:...........K..7*... ....}^L....ZV...*i..w."...=Y...4A.&...P..]y..&
.]j..!........K.Y......>n.R.ML...........c......l....1X4.;..(....i|
.%......R.!........_.yW.......[.[.3..gVa..b.[.(.b..r..[GC..F..r..%1.G.
.......Y...nFM,.........x.m/.m...p.....B....).I....7>........4t8..P
....P.Ian..bC=.x....|...t..@...............<t..................w..C
.l.......I..."...,...h..........E...2`..Y../...a.r........|...h..S.\..
"k...l7C%..........8.LG.yy...N.Pg.../W........cP..x.j..8.,D.........:.
".Z...X......\.7.d..~v.....`.=.&..!.....vw.?....Y..Ds..;u....x.......C
@...aAO....mR..c..... .....Q........J.....u..KVS].^..l.K...v2.....t.9.
..47..-?._D...).........&5..,....91H..DL.3....R6.....,......Q(..yxv..5
..s.....(x._.>....-.\....fw.Qe|.................K;B?N..e.G9)[email protected]
T..#.z......7 [email protected];......
3.).?.....L.%.0............h_^...8..QeYS$y.9...{...^...,.k|..Tb..o<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/1b7cTbKmHzzFa39lmYqZ5pm-PEkHzxCUXSEXIQ5m-0U=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 1183
Connection: keep-alive
Last-Modified: Sun, 19 Apr 2015 07:20:13 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11891:4:1168......t3p..1...o... l...p.'....M.x.....}k..}L...#.....]9
.y;.j.tz......U..XGn....Ja"O..."O..Rt<...m2X...3...K.MI.O.G........
9..g.)C..G>u..Z.C..J..RF......&.....&...."...a.%2...*.....I....e...
V:.N..?..6.....pp.~....S...R..1.R..1.td...Gz..?...<'7#....NYf..wC..
H;...Dqci}-...b..-.....|.A......K>[email protected].....~t...&g
t;..vQ.7..C_..4..B....L.q.U.a..|.....h..eY{q`..X.X....t....n2$|....".P
3[1...[1...H.5...YU..4I...NC|;1n....K...0...C......m=...f.......}.....
o.<...R......L.l.]z........w...w.5.Y.EDh.2B..K.gY.G(.T......,.>G
f...k........5....9.[....9.x. i......'.o...O ..~......._........;I."..
..."...)."...5...?.b..Xx'Y$.l....U......qZ.................'W.&..S.N..
.Q.. ..T..2....2...:|}....|h.]......{1..p..1..4.?5....L.`v-..^h...J|..
..PvW.W.<@?.\..g.t.........v.... .....y.....v.8.i..v..U_G.e]V......
.Z>...Z>.......7G4 CK.p7..@[.{.......n0..<cT......"[email protected]
h.?....PLc6n...Bf,1.*..f..<,.......A..%X.L............C..k.&...2.a.
.9.y.l{.7..0*:...U............R.`.q..5. [email protected]..[.#'..G~.":
.......'.kI...Ik.....>...l.M.....@\.v...ce.M OC.z.4,[email protected]...
O4. .......~.4...2..d.ks\..wW......,"....z......66.)......|^A......9.S
.JN...T{....I.75...m.....|....|.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/7qBdfHoJ3SU-MMdqwyhr_IzMeAwQHON2YMpt_zQv5fI=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 1732
Connection: keep-alive
Last-Modified: Sun, 19 Apr 2015 03:10:17 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11890:4:1717.=\G.............JbP......Ea.6A..=.f..#............./.`.
.4......cc3^....;s..p.iQ.K-Q;...uK.#.......................}0TpXC...P.
.h...z....D.v\[email protected].... ..C........A.=.....[.E.....F.;7.R...".^.
.2.......A/.9.}.:.......n6k....f.rH..2.p.....a.... .......f.f..(K.....
C..........u..T.k..k...Qsj.?=...i.......=.3E)R..-..aj.$.d5....P....P..
9y.....P........M.V6j..D.o.1.\....O...c.c-.*.{d...`.5...'......=...L..
;NT.{. [email protected].*i....2..8)%.z..V.I.Q.O...X4
.;.#jl..5....8.......~.).......H.B..........."..a(...8....S.._..9...^.
.h...Q.....f .......p.|.i..!...N.... ....I..S.\............S.(.l....a.
..>9k.....y...a..,[email protected]..........)y.e.....8.p..s....sI......o
k..b.......\....hFD\;....K.d..]A.9......s..'o.. .N....a.y.?.)EN..}.p.W
....X./....G.."...5....n.....f........A.....{...c..D....Y9.....c......
.s..i.............. M_Z...l...fcv...h3...n.,m.M.3.|$c..SV.Y..m:..<.
..6......|..Q).../J$.6P...P..f....X...B~.;...9.y..p..8B.AOX..f..'Z....
o..%Q...........*..x..$.. 4..o.U.{...r^....H.}t..."...T<).....]....
..[1..~...=....a.t....4.&._..w.y./.s..I.a..|..G.k.4......!.B..!'.4....
z...;......{.l.............4.-..e...GK....9u........L....u.- ./..qs.u.
..{.....2..,.~..\...9.".(N&3.N....#.u.....A......c...(.b.....1....Y..;
..........Rf...uP......|.=.;.C..."j...zfO....6Ef.!....!.......\4w.....
.............I.~<..cZiH(.5k.:l....i;..R)...w7.%..J..'..HGJ.../..j..
..=W....TH_.>..47..c....[F^4vh....0...._..G@(....H..d...........f.1
B....j...Z....J.&.....A'F..o..$]...$]..c2.R...&1...P$....R..C....f<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/L8YfZVfXg6CBxtxY09kJVtVDgBO0dITHTfapA4cuPXw=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3378
Connection: keep-alive
Last-Modified: Sat, 18 Apr 2015 02:00:16 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11889:4:3363.=\G..=\G.h.W......4.F..v....\....Z11..aY...z...A/.!P...
.AE...`.w.......u.s7.......9.t..;<.H......:Cc]/s.5 x.W.i...I.....M.
/...x.g...].$...f..Q._.....j.T_t..$...W..........9........e C...t....s
._C......Gp!..LZyQ.....j...|..Fy..p........_.,.}).......4sS..G.S..G...
......x..-.x..-.6.......c..E.....*a.*.t.D......o..y.;<......@./....
.?.!....I,....m......}A.....~^..2...%...t......l.?..b...."..../I...l..
Ig......`9~..p.)......0... p..e.;...$.\._....Dm0l....(......g.ù.....
..:x.....G...Q...V..........u.lgX...r4L.C...m .)...u...h!j.?=..T....F.
. .#.....r..9......aL....s.3..[.......8..^.D..U...(sxC.......Z,R.I:...
s>...w..V.....i.\....`Z:...P......E....H8..I...<......... 2...3.
......M...E2.J..R..'.b...c.;.....$s....A....ywU....>.. <.6...p..
.*JP..)g.p.....s9....m .}....$..8.W..u..'.4.M.,.....3sDY.&...nS..}....
~l.... .q....9T.Y8.<.B...#...0.E.e..L.....:a.#.HD...[l.S5........8$
}..v.gw.Bj...i.d....%.|r.9|.......X].....#fPw.........fy.A../....k..W.
u....q..u.._....!3.x~....~..~.nxM....4q|;j...n.$.....c.Aj.G.6T.....' .
...0.. ..&E.`.q....V#nj..3.x.qj.K..X........e..M!;....o....._:.~......
._..Z.F..)....]nwn..3T.D..C..A.b'... .... ...l..v.(P...X4.;..5........
..R.....3..m.-3...q...S....$B...!...Z^...<9..0(..!.j.MlH.F%....;i.z
u...g:....Y....\......N.......Q......4...P....&..[....p.....|.........
...n...0........L..t....o.BS.\..3..;..t...9..H..;.....hYs...&.e.O.....
.=....}i.J.!......._P...Z..B.A.}..A.}'.)..M...O....}x.....y..^3...:.n.
...Z...&1.....s.%9.2.....^dD.pwZ...yZ.ry...v..DV.M.. .&.P.i.....vy<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/8S0Q5rtA7KAKeU4Ehrg5Xv9EYVh3XYLrjsc_I2yPkxg=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3666
Connection: keep-alive
Last-Modified: Fri, 17 Apr 2015 04:20:16 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11888:4:3651...7V..1.u.o\{.n"&.P....0....L..S.\...Q./s._.aa.*.. .A$&
gt;.,.(y.9......9"}..<........).kM..)D....x.....|b..!....:.-8.{.. .
...&X.J6.......5.B.X.uL.ù.)..pC.....;..~.q..bS........' ....p....) .
$Y.w.6...xU..t|.B.....m..%....G...h*......R.....f..*E!....k/.uJ!....z.
...L...)Z..t*..A.-..{...].....v.....~........&3.N.....gE.mPz....^q...t
!...b....".s6.%.oU...8o.......!...q...^...H[^A.Y...j.?=.....J...x.....
.z...4".!N)..%.!.].l...XO6.H:......O........T....Yq............<.I.
.bFa?..s.s..t.ns`..6k...T.h.z.e)...K....f...T...a....a.x.o...t.jq>`
.....?..n...>...).....y..G]..(P...C.......s-m.......Z.Z.>..M.../
.F.MxhC.Z...q..w^.W..3....%.....=....R.Z.Hl..j*....s.T.R.&.[`.T.R ..G.
9y......F.`..UB.$.rw...GxF3.u~...................u..0.5C.......=......
].....].o.GE........}....=......s1..d.6.......Tn...D) ......g..[....c.
.....[.#.Y..(....C...J.%.A...%..z.......i..>.B.H=.n.....j...h...wZv
.53e. .}... N....R...Q..*i...........&......Bf.n.g{...j .....9...n....
.....3[7b.%...G..."r..W..S...:............Et...3.. .W4.Z .2.Il.mx^..-5
.Q...;..^.V.M..B...kX..._...._........)...P.V..6.JL%.B......-Q;..'.>
;E?^..;.U(.......v..3..;<./cc3^.gL.h...c.K.. 4......|...`.....Z..P.
.._...3.kh..iIan..nC....N...wR..<t...=d.........5.F.#.!.CpFn.;..6c.
5.~R...v....Do.r..l...".........W..3...>1....p..7.g......s..H......
.=.....lG..Ll.D.....'.)..W]..>....A .8. Z...8.-..............9=....
.L..-..4..;.%.7...Q.*;c..Ds..s$m.l.I..#c.... H..][email protected]...
....y;.1.s.G.gll...\~.........!..I....b...qL.z.....R|.......9.a.y.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/HKF3fPwAJeRm13miXe-4vI1FaGTPCwlI5utMJctwl8k=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 742
Connection: keep-alive
Last-Modified: Thu, 16 Apr 2015 03:00:48 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11887:4:728.Z.....Y.&k.......1r(.-.i.M.P.......&JH(..JH(....j..`.=.T
.x.~.N.&b7......5..P..A/.1I.2J.8....<&.....SX.j(......Lc...J....)..
.v.....o...... ..1....^.5Z$G....H^N|....Fl...,G.H;.$W. 0.4i/.K..{be...
...... ....S.y..p......mN..... ..;}...Q. ..p.c_.........I......6.d.c%.
..c%...$>..g.....`......g...%.........>....]......#.6{.BM..9*...
...-H....3.r....R....2e.......5.-3..$..(.u.&.<j...6.#..t7..A.v....;
v..b.n...?.L:.rV...ha..^.X....#...a.GU..|.H...I..Z.....6,$Fa?....?....
<....<[email protected]. .........v...94m
.N...$..)..%Y...?1.x.H... y...J...P5.....y..............K..Ow0Fz..'A.Y
..)-d,.nI..4._........j%as.......|d.%....'...`.....U.L.YR...w.r...Y..)
.e..x4.......t5.,IR.$tW.......h...on..pJ..`9~........_..<..C
....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/-4o5ao5EnwLZD9iXKCnEsuiZD1-825UgvePOW0l7Jig=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 6015
Connection: keep-alive
Last-Modified: Thu, 16 Apr 2015 03:00:49 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11886:4:6000..DMU.C8P@..\...._V.....k .U..j..-.>...2..w......S...
........xU...<.uG'....Q.ICq......(. ......V*..Qe...m<I....r.*.\.
.%....F..D..(j..k..x.a.%.!..[bKE.x".\"...?.}..|.]..5..Sw;.....?.}.....
ù.0...M.F.37Y.t...........I-..A.k7..F....F...O.._..j ..$Y....'.i1...
..:....t...........|v...'...5.o..A%.<.."..^...Mt...A....RO..,.nU`..
.....*i../`[email protected]".7....7..z...
.pZ.%q..'.q..'T....1.. ...8......N...b..w....".. .[K....P..dC.k..W;_..
....N..q..$:'...L..2.M.S.\....*R.....R..i.)....^...}RN..;R...B..a<.
...Ei]|1.....].if..?P.)D./...K..y.<.......H..q`e..[..Q.>....:...
C@....".z.....}\.~.....a.2G.,#..D?.8.P32....d.........05..R;..1#.G...\
1...J...C.~...X.U9.....#....X.f.)....a.y..S*.... .!...2......s.8.sU...
...\3.x.w..I.<.'.......I.7}.G....k-E../W..@...........~...s........
5...fP...lF)0..C.9..`..P5..1d......u.[~..c...d.KL...1!.....P....[.....
f!..F........).....Q&.....5.{.....V.l.D."j........"...c.}.||.m>&...
..A}.GP.....O.......U..2s.S.d;.6/.v%.F.r:.\..B..}..`.....k...[p.6%....
..eb.J....[.t.Q.....][email protected]&N..[C.1...I. .'_w.r..m
[email protected]#.{V...W.P}...."...o..X......Z.Y.......R.R....3]o.!A...I....
r^.KKW.......[`.....{..Z.R..#.....L..Y..s|D=... ..V........F.C........
.c.ow Q...z...61....t...B.J9b..,....J..z.........o......T..}(...}(i..i
.@Do.,.Yy..]!(y.. .R.._.57.....A..i^...J...A...........E........M.?.N.
. .#*.....y....]n.].x|...:......ue|...i...^S.: s..."X.5..D3...D3..-...
[email protected].|."...^...........*P.V...|..K..Du7..n.p..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/uZzH4jIf69GyNCTmL-lfy3mVpENyN_3F1IKOAXBxQwU=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3250
Connection: keep-alive
Last-Modified: Wed, 15 Apr 2015 02:50:32 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11885:4:3235.~R....!." .........=.`.8.#.&1........B.p..j........8...
..............D..l/..C.....2_.U..{.c..).Q...#... .$Y....<..........
.....`C...6....r.3...)..".B.=..."..f0.fS.\...Na!n...L......)(...[&.tY.
..N.l.....d]F."..9.............j...wt.......]\9.IV......U.......:}...b
'.!....%.o...-.lB.....4............O....Y..l...f.....Fx.{.....N[..6..T
x.c..b....Ej..wv..d.!...u...INc..E..x..<......Y]I..e.?Au.#.Am..3.S.
lU...9R.pw........uv.9?......X8..3......u.&.#...g....%.!..[.CE' .....e
...7...'.w.4.....y%.....??......_..:6k....Bl....<..R...,89f........
[email protected]...@:.>'..1N6~..Yv.......!0@'........lgX.......C..
...........P......7.....S?.^.W..z..w.......T.c..D.......%.........E.g.
e.........w...J........w.xk...Z....?[.'.(...c].b....4-"}.H~}..F%\s....
H.w....t..$..,t...k.s}.=.../..5%.9m.p.U....w...........\......U2.d....
.[~Y.......PK........A..y....h..... ..,..=...N.t$.H.\..t.q&b7... d.Gm.
..V.YO..A.......0...0Pe.b.....0.7T.El.T.ElO.Qh..(....f...!...mx^.1....
r....R..x...(.........$.....A....*..5.5.-Q;..*............m...p...F...
...:.....-s....~.......2.&..h...R....R...<t..2...._pD....2v....7.Q.
.6.#.,..&.17...N..].Av..........S.T......l6r<.H8....r..5...,.....xU
...E/>.......1..E.....u.Rd..N~...4o...s..........F.?.}..U..\6..Fa?.
......~v..T.T.ry.......GU...n...vyh.....T.E......5..)..`(}3......<:
K..^..E...A.......r...3....D...:.C@...[d37..u....6....E..1...Q.`.5....
c...,A...g.NnN..So..2_.....Ya..H..84......7B... .......n3.&..#..%.....
.c.`m...a"...u...3/:..........g..l.~;..D...H.B.l\".../..t}.A.rB...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/tcGKeAaBBZVoTuDyPdwzKOYsyfhYjDXJQJGBQURKxGw=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 260
Connection: keep-alive
Last-Modified: Tue, 14 Apr 2015 12:10:45 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11884:4:246..p...$k..R..).R..)..........KTM.h..Q..0.........=.4.eB..
..........!....!..G....G.../..../..A.~....F.....h...Md2..AJ.....,....,
"..G."..G.L.z..L.z..f.. 0...R...G..H..,T........r....r@[email protected].;....
....X....t..?....1.XX..............|....|\.|....T?....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/mmJ3t2zL0g6vWR1TMD1cCWQT8bHUYLHTQ62AC0A9DPM=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 2438
Connection: keep-alive
Last-Modified: Tue, 14 Apr 2015 05:10:55 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11883:4:2423.Qz....b....H..`.........-m..&...qw r(.-.>..lP.......
.&f.i..1i..`..GUs.M5...9.v..9.v.J.......v=.1.v=.1..nY.g.J......#8.....
..1p...!W....... .~...OjBW...$PS........M.eQ.a."G....scc3^........7.@~
..g.....J.rhEc.W. 0....*r..P.dA1..a.J....mR......... ...:}..]Q........
..........9m[."...J ........ ..1..K..........;CE......K..........@...\
...H[^A...Y]/....d.\./.|......A&Z..<u..-F0L..?%....{.w2...._.7r.0..
....=..~.e6.._...@[..."...........9;.........-n.....q.7......|...Fl.d.
...'%....t/..D..?$U.......A....?1...~....l..yk).BY...%,UgAw...!.RZ.[..
.UE.........y........;.c.&..N5..`%~$T...J..;..k..L.I.........~-......C
...N)..* .Y.j.....4.JG....C....{.u..m...x...6m..;O.ZqO.@q......}&.V..H
.................<..)..o......H.G..H.G..#...B.|[email protected]..
..g..`.x.B.......p..Y.X..L.....Tx.:vH....~./d......."......N="......a.
......i.M.I5za..kJ.Zh...^..P.......8..JW.....0b......&.....3....8a$.r.
%4S......,#..Q..h.....|..k.&L!..k..;...!...Q.d6......T.YS.\..2{e.P}.b.
Kz...B.G.........Y.ch..G...?.X.....Q...\.@.]..Q.'!..qz`..~v...........
.O....5.............1.%..g..#..a..8.tJ.au..2...qIw..........O ..L..t.{
i....,.. ...GT...B.....Ba....$.......M.....'8......-...9.:B..vW...._..
Z...U........ '.........V...T.o. &J.S...=}..9y..b0"E,H..z..K.........q
...*4....z.... `H..I.K..'}....M..P.zO..u...y...h.W..S..?.,R....>eB.
h.j...9.}Fu.B....5oR......ld...;.L.H..N...................m.......z .*
Q`..T.x.............%v=..AOk....3..;..\....S..........A....W.(o..Y....
R#...j.$.;...670X.>...$.....Y....V..^....^...........y........M<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/8x86bntNswBvF8StUDkyBYJScNTywKW-WxR6azPXUFs=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 5295
Connection: keep-alive
Last-Modified: Tue, 14 Apr 2015 05:10:48 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11882:4:5280..DMU....F.....gA..=.MB.Y..... .j....7I8R.....SC...,`.N.
...y=..o...~.."..xU..-....qE.D...C;.yCLj0...N. \.V.y<x.#.....x7....
.......Qn...c.......H".)t.^...._....*.O.......F.$......P..n.%.!..?...j
x.E.x".2m(}[email protected];^,.-....:c....a.......M.....D....
q)~..... [email protected][......i.;6'.(....V..2...Tn..D..0........w.
...............[.jO.v.)CW.mnb..YB.z...j......_I..1.`...C....8,L{z....'
...L..U...'.g..Q.U.......q..L%.B.D... CA$F.....qY....d.D..1...d...|...
...iN_...L......._?........%...X... (..&]Ap...!ji8{.Hc.W)~ep.lb.7.....
6E.%.;.=...Z......S.J.Q.....1O..{...`?.../[email protected]..^....g...8.Y..S
...$.....T.i.~,...<.I......H.$......1........7.bG..d.<=.k.>.v
[email protected].^.....$.......T..G.d..P.......c.]. .....a.D...9..
..<r..ZD.J........a...'.*1.....l.-.....e.h...B..2.<....B`...-=.g
*.}[..2.9s.._.V..U...!.......MI............$ti.3JK.......2..)...I.j..~
..Y.M...&.T....d./:a.c....4h...f''.g.e.v..:[email protected]....... ...o..B.
..-{[email protected]...}R.....y.&.R!.....qH.R./.5A.2.r...!..,...v.
[email protected]!.Y...a......~T...s@.!{..d......1..~4.....{....
.e.. |. ..E%.Pd..[..j.`..<..........0...k... NwD....L.....8...k...`
...O3.....V.O.t....e.W.u.y.....\.Q......?._......W...J...Z.;,a].p.K?nk
...i..... ..1.....Ux/......u\..N.s.A{l&...7..b^>.m.....,... ..w39..
o...m..........<&d..3.....P|U....x.~.w..!.T.B.. ...B..P9..6........
.....I...p_&......c...&.=..z.{.{........j....j.........f...-f......W2^
......*ft..;.:..V..!.kCy....... |R... .R....A.l..==R.....LW'q.^I.,<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/CZ1HgPkzCwCBxfRKtpfyV_KRZan4m07k2DINWshHBs8=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3019
Connection: keep-alive
Last-Modified: Mon, 13 Apr 2015 10:40:28 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11881:4:3004..Z....mD)h.W.....y2....O<........,E.J9..............
..9q?X....$\-,O...[.=6. ....... ...$-..|>..{......#.W..>t...>
t.....p.A.....xU.%..7......... ./..m...g.....$..W. 0..K.aa..8.M...y...
...mse C...........W38.r.....>3.%.......$.^g....&.qx...}..?[."..O.t
Q.....Xg..\.x0.nKL...fT...l..5VmIan..F....0..hA.SH......-gG.(.....sQ.-
[email protected].%.!.Q..-..............<..R.b..
..:X...-..(...6k.....JJ.$.oKr...c..(d'.cc3^.g.O.|...cc3^.Y.`......}...
{m......._."z.....g.\..Kq...."n.C.........Ds..1........0.*.......[jwj.
.x.?3....?v.J.i..=`.s.....0=B..U.....CN6.e,h.....9XX.Y......I.N{.q.z)o
.C.........N. .#...|...|..Uo#.3..q.E.'...#....%g3......k....a..QA.f.1B
...cu.........&............Rt ..=.....|[.#'{D...<......yF......1..*
..=./q...JG.......on..W.EXJ..*.5G/q..;O............WK>...........6.
d%...d%..h.....P......lA. .}..{.d:. .... [email protected]}..<....<......
...ZDQ...n..i."Zl9.Vp.......e..3.w.- ......ag.4M.R........./.]........
....X...mx^.1..m..~*.&-.......K.l"P.....;Gk.a.)..`b..3..F%...~........
Wy....G.k.c...d..................[.mg...(....Ay.... ...5p.i.IC.<t..
.......A....A.F.#..dQ......$....."....oD].Av..x..&..3....v:9`..]y1y...
..PiT....w...wELl.D....O.H.u._s......'.)..4.cIa...S.\.....b/....cP....
.`.........s..u.."..).^[email protected].!.......-...X..vyh...........,R....k...
k ..bl.l....l...0=..T.b....4..`...C@......'..j.>...$.p..pA.......#.
.9Oi.......vu .66.7muJhL..Pz..Z.\qJ.........$......d....56.........a.y
.?&\e.&-<[email protected].~.*RU..f."g)1.SA8<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/UD0bsq7CgMFsj1L2lGlt_qMLDOVILsZp0MO2uGBvQDw=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 2267
Connection: keep-alive
Last-Modified: Sun, 12 Apr 2015 01:20:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11880:4:2252........;$.rSn.....D.%b/;.!\-,O.Z..3.......Y..IwM..uN...
....&..Y...d..Y.|../..F...8........a............a.J..l..e C...L^#..{..
l..../.......4!...u.........8.J.0.......S.Iu.h]..|.H........ ....R....
6.....)........J.`.z.e)....N.X=....%p.ù.}...).GY.Q.............(.9.6
[email protected]..|.J:l.........3...1..k....k....j*..qo..$....$..v.
..............E.......2`{...........w..C.l8yK......V.u..5rG.Y.. ...<
;3.#C .......K..7*... ....}^L....ZV...*i..S^.{w.".g......K^'.4..lD....
R...mmY3...]j..!......n.^..^........X4.;..(...._=..D.U|./vY;.....R.!..
.._...m.C3^.57../...v.T.#.(..g.T.,.Y.L%.B.|....R.<.-._.I....7>..
..P....P.Ian..bC=.X..?..~[.6..s..c...o................#.:......."...,.
..:4b.q...8..U.......Y../...Ll.D...;.x&.O..t....Ax..a..S.\.........8"k
...l7C.LG.......:."G0...?(.......h_^.vyh....`[email protected]..
..mR..c..... .........Q...T................J...RH..1........t.9..a.y.u
>..q.........&5...IE..U ....'...G......!.p..7Ho..7Ho.av..F.q.1.....
...6L9a.Kr...3...P..y...fA`[email protected]........".....p:.....N(..}T...*.$y.9.
..{.s.....(x..~v.....`.=.&1.gvI..,.....>z....a.....j......S..P....`
......e...\.M..!..||....l-.xbT..g\.!.g..v......&2t..t....r.*LJ......'8
.?bFr....Wmcc_4l1...b:P...........kn..~YM&|G..lbE..i..b...........J.A.
..ro...:.\.Q.......`...x}o..fV......k.....A=.Y.4 cb..hND..J.1....0....
....'.cP...*.@D...>N.X..kT.8.,..-6wg.e.t;r.U..8.f....E.....3..F.#.?
...~....P..2uD...*.W...sT....#[email protected]..!dq. .Kj.(B . X.6.5.Y
.9.........kp.......I........;l.V..l.V..l.......J.=.2.......p.xe1O<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/k79kxi7KCBnYOCQAy1vwtvAw8-UsxI05yt5LtYK6gi8=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 1977
Connection: keep-alive
Last-Modified: Sat, 11 Apr 2015 03:00:38 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11879:4:1962......*...S.\...k/..'{^>U..z.....B..@.]8.&.l..9.%..D.
...O8......rk....M.V.....xU.....j..8.[....Y.&...I.......8R^...Q...h...
r...&..A.=..7....%.!...3pI.H}....`S.l3...';...F.u!............Q.......
.C.....'.Y.6{.u.r._.....u...Qsj.?=..j....J..a7..3..[[email protected].#.:.......7.
..^....Iv.,.*..\y.....N'....Q....^SH.rw...]$......C=..J..Z....>....
..g*...\...CkDhP...hP....$....l..*i....2.<...........n.6._......=D.
. X.^.......e...X..j#.3.._=........4.".P.M..)..I.-)6...\...(....._...y
.$4S.....H..-Q;...w..m...F.. ........D...*./.hVz.....I&L...%..QLkv....
....d.$....f!.h........I.Q.O...V.=.....!..Q;...Q;Ll.D.Ll.D......Kt7z.!
...4.us..u......F...m...j...."[email protected]\..3p..UA.P.......'.b
....*..Yo...z..L......0..a.....j.Ba...'.#. .d...G!.e|...:./..........'
...1....<{.........Ww.3...Jj.OZ......:......O..%^P?..*r,Q.......^..
.<...s.....@[email protected]../W..&...G~=..".W......).. ...lY
.........D...|..Fr..FFc.7......-..}......2....Fe.../."....fc..@|.P*...
.<.*....S=jiZE..jb8..z~Py..K....7...;y....o..W"..|!...c.(Jb....a...
.GT. ..c..$.}Z...P.-..\.. q...y.MKB..uz..r..h.0?.|._..zI.v.p0.7.....l.
.4_.d$.ZZ.K6;..&......=...j....T...I..0.'..J......o'...M........i...%.
...rbr.....gk^..M[...1..`...QF..O.G.n.,..KD..u`|.~5.gl`Q.r..S..'.JX..|
......u..g.... ^...cP..{.2..\.W.&9...&9.y..p..;.H. 4... 4..Y...y.)..z.
i..'=.....]m.L..I.....9.f )....G.py.......,......K...._.JV.....a.JV...
........*!.......m4.........iJ..............dlv.... y.._R.X*Kr.hhM8OZ.
.j..X.d.d..HZu..B{....QQ..!....mC......p.TF.1..P.J..=>zow Q..$.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/UIig0slspRhngV1ffZg2oait9i-ELqUx4qMoBUagOvs=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 49
Connection: keep-alive
Last-Modified: Fri, 10 Apr 2015 19:50:34 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11878:4:36....a....a".PU.".PU.10...10...K....K.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/wzLxTSmOmorwmke1Edhp54wX_9dvNs5yPeP8oenPaK4=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 3055
Connection: keep-alive
Last-Modified: Fri, 10 Apr 2015 03:50:19 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11877:4:3040......s......f..Q._.....u-....aY...z...A/.!P..&}...b....
.AE...`..j.L..*$...uN..C4..sa..9.t..;<.H.......qj/....P#......Dg...
.~...W.........M./....o........PY...w.N ./......0....~..._.>..u..w.
..:.O.;_C......G%....f.dlqx...O.....P...~Bq..&..C,........wv..|...6...
....k.*....l.7..E..:>A..z...&)....w....w.}A.....~=O....S..*..u.....
.....l.?.7.L<.....6k...&...H..2.p...._....Dm0..........ù.......:x
.....G...Q.........6....|`..r^.. . ..D1.L:..L.....u..j..El3.. .#.....r
..9......aL....s.3..[.I..e......8..^.D..U...(sxC.......Z,$..).."..%...
..(...Q......py.h...O.....yj.[.<......... 2...3..9J....e....[e.T.h.
.UG.......on..../~.cD4..g......j...|..F..A....yw(.k..3.j........J0.>
;.B.8U.^....d5.e.zl....#<.f..s9.....,...w.].*W...!Rh?.....^dD..8.W.
.u.....s.4b.R."...I......n.$.........J......nwn..3T.D..C..A.b'...:..k.
.........P..\......X4.;..5..2......"*......_.b.v.T..o.o(....{4W..~a.'.
.p.oO.... .<..c.nB..c]/s.5 x......_s.C...*.......;..h..Z.F.#.yL..J.
...t....o.B...<...$.S.\..3..;..t...9.;.....hYs...O......=....&.e..Z
...IN*@(.5k.....'.)..M.........t|.@.!.. ...{Hf..\4Vf..^3..&....K?.T...
[email protected]..)[email protected]..&
lt;...".{J.Fc.O.5. r.J....R.D~..>.H.'.b.. (...c.;.......:.\....;...
./.....$?...]....]... .... y..p..... .d......e|..........H.AE........f
m.0.........B.:....>..l.....`)EN......Z....=.....U..;.R...}.{.\....
s.v..*..$.........^u.!<...'.Jvyh.....^.....[...u.t..O....1..a. ....
.....3&2}.......a..16..a.....6.....1..tm.&$...&$..J.A/.._..H..I..Q<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/haIwPWO7cofJKKFQxp4j9ZcAT3JtguG88lgbYRgGl0s=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 295
Connection: keep-alive
Last-Modified: Wed, 08 Apr 2015 07:31:09 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11875:4:281....j....j.?...ozO..1.XX.......RJ...RJ....f.. 0.../1.../1
.....0/|....A..{.......V...LY.0..t.Y.k..n.W?....&...x... ..V..j_lCCgKl
..f..D.".kb.E{f.*......@\..D.......x...X..d.3...F.K.....4...3}.cu;..F.
x.._...Y2!.D.....K.f..._...>.1.}]ws.U.\.^..t...k[.A..i..H7.........
za.Q.za.Q5..?.5..?HTTP/1.1 200 OK..Server: nginx/1.6.2..Date: Fri, 01
May 2015 04:21:33 GMT..Content-Type: application/octet-stream..Content
-Length: 295..Connection: keep-alive..Last-Modified: Wed, 08 Apr 2015
07:31:09 GMT..Expires: Thu, 31 Dec 2037 23:55:55 GMT..Cache-Control: m
ax-age=315360000..Strict-Transport-Security: max-age=3600; includeSubD
omains..Accept-Ranges: bytes..a:11875:4:281....j....j.?...ozO..1.XX...
....RJ...RJ....f.. 0.../1.../1.....0/|....A..{.......V...LY.0..t.Y.k..
n.W?....&...x... ..V..j_lCCgKl..f..D.".kb.E{f.*......@\..D.......x...X
..d.3...F.K.....4...3}.cu;..F.x.._...Y2!.D.....K.f..._...>.1.}]ws.U
.\.^..t...k[.A..i..H7.........za.Q.za.Q5..?.5..?....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/m9zSmPnZl43F61hsLKfueuH6VwYE7gGXeYYSB-pypy4=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1150
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 12:10:41 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54933:4:1135.......z...'....x..M@......;..?.pw..(..|P....P...K.s..K.
s.-..D.-..D.........S..8.S..8.]....].............m....m.OK(..OK(.*.k..
*.k."..V.=..j.y0...y0.>..:.>..:7..u.7..u.3c...3c..3....3..N>.
..N>....................{..K.~1.c...0....0.<=...<=.&..H.^....
.mR...mR!.l..!.l.>[email protected]............. .... ......
.....?)_..?)_l....l...(%F..(%F..J....J..nt...nt...f.......59.%.]...[1.
.i.nl&.-.l&.-wX...wX..Mp...Mp.....b..c..@.#..f.u...I....I.T....T...N[]
..N[]E..;.E..;.[....[... m... m..s^5..s^5..5....5..........O.6..O.6...
E....E...W....W.b....b...9o...9o..... .U.*G..W..(i....,....y.....`B..t
P...tP.V3.a.V3.a>. n.>. n.c....c...W_...W_..{....{...M....M..e..
..e.....k....k...........7o..>4[..u-...u-..........................
..&....8.At.....J}.j...k.G;.k.G;2Y...2Y.............1....1.v..=.v..=.8
....8...|.F.dA'.../....5..{.... .... Km...Km....~9...~9".5..".5.=....=
....../..../..........23...23....N....N...................o6..........
?..5."?..5.[<...~....).T..e!$.g....k....k8:rV.8:rV!....!...A__..A__
.jY.H.jY.H..W....W.j.k...........%4.....=..o....... ..................
...q....q..=(...=(...e....epj.].pj.]"...."...S....S............
....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/uq-M1FCqWXfGGjcE0dku9n1tg5Z59jjylidsIBdF6NA=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1034
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 10:40:41 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54932:4:1019........m? Yf.................q....q.{.G..{.G..........}
."..}."#.cL.#.cL.........(k...(k....2....2.3....3......~....~nE...nE..
:..a.:..a^Cl..^Cl....;....;.o3...o3.L.w..L.w.`.^9.`.^93>...3>...
..A....A............i....i1;L .1;L <....<............!..h.!..h9.
...9....}cL..}cLN....N.....z<...z<3:...3:...L8Q..L8Q............
5....5.Z....Z..{.n..{.n....=....=D.&..D.&............KH...KHl....l....
&....&.....*....*o....o...r....r...*4.c.*4.c.........~.-l.~.-l...}....
}.3C...3C.jT...jT...........o;`..o;`."..J."..J.#3...#3.G.>..G.>.
... .x...a....a.....e....e.&....v..a......a.(....hE..I.].a.....HH.<
.Y.\.e..:"..1."..1.).3.................(....(.mr...mr...?....?..n....n
....f....f.o.T|.o.T| ..}. ..}BX5..BX5...G....G..w....w............W0..
.W0..DrP..DrPz....z...#../.#../.L....L..\..m.\..m..p....p.u..!.u..!.].
{..].{A....A....C.e..C.e.."...."..........)N...)N...|....|............
. M.....8.,f.|4.j.k...$.B..`....`............S....S.J....J...a..H.a..H
.l2...l2.^F...^F...........F....F......u....u...Z....Z/:.../:....I....
I..............
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/O9JgGROBQ5x0P5QtZJaM8u0jmTgbS8oXBKn-Ktuo18k=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 432
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 09:30:41 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54930:4:418..._I..._Iq].s.q].s./.U../.U.........]./.gb&~....cW).Ce].
.Ce]..K....K..... .<^..._...?...;.q..;.q.........zF"..zF"..._...._.
.........F.29.F.29./..../...,.7..,.7.txT..txT.. M."k.....b....bj.k....
..A.p..A.p...g....g.&.....)rQ.....%.)&......!.D....D...n....n..{.?,.{.
?,...........{....{.............}....}........../..../...y....y.....4.
...4u..#.u..#.B`...B`.amu>.amu>.Hil..Hil...Z....Z.x....x..S.k.._
kK.{....{....g....g......
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/FDTTAe43Pc4fgrkoGNLqTPAl11sblwDJtByrMIJs2GY=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 3135
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 09:00:35 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54929:4:3120.A~~..A~~.z..%.z..%.V....V...".R..".R!.VF.!.VF.....lSbqY
.O..&...1........) .j...T.....e..M..|[email protected]....!.
.]-U,.Z[.Zfp.rA....e......n..Q..b..............fO...fO..........i.PA.i
.PAi....._c.5L...5L..$z.Y.$z.Y.....Z..............BN...BN.]....]....3f
...3f............z....zDlI#.DlI#.f...L]_.d..7.U..*...l/...........5.#.
.5.#..m....m../V.../V..{..=.{..=..........Ov...Ov.,.5..,.5....~....~!.
.w.!..w..}....}.............f....f_R..._R....1....1...@....@..........
].N..].N..L ...L ....T....T...M....M.=....=..v ...v ...s....s...8....8
..2;Ig....t....t.UD..YK.H....0A...G..[i...[i$....$...h..J.h..J..?....?
...?....?..O.z..O.zy....y.....;....;.`..,.`..,.I....I.....E....E...Q..
..Q..a....a...l....l................... .... ...._m..._m.o.t..o.t..lH.
..lH...`....`............X..F.......rM*..rM*....4....4.../..../.......
..7.K..7.K...................zH.(.zH.(..Sl...Slv....v...j....j........
[email protected][email protected]_.. ._.. 9a.
..s".3S|...S|..g....g......................=....=.....=....=.\K ..\K .
...........f....f.\-...\-..........wb...wb...........*E,M.*E,M........
...Q....Q...q....q.J..P.J..P...M....Mb..D.b..D~..g.~..g.Omu..Omu.!.n.&
.nf.Sg..........k ...k ...J.\..J.\...~....~-./2.-./2............/..../
.6.....i0)..m..'....j....j.k....k..k....k......y....yx.<..x.<.^.
?..^.?.VC.q.VC.qp....p...B|.I.B|[email protected]....'.!..Zr...
.:[email protected][email protected]&5..0&5P....P......]....].n... [email protected].
.vxJF....F...g..V.g..V..i....i.V..>.V..>.d....d..6.S..6.S.Z.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/5WSYaQ7LOD-v3GjZ6dJngOy3mUXWCdUykyYS_adogHo=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 3450
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 06:01:03 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54928:4:3435....H....H.......2...6i.A..k..<J....Cb.c ..z....qiZcI
.....{...I......A.PS..r.z:..N.Sqqa.Y.....U....U...;....;...{....{FJ...
FJ........F.9...........................q;r..q;r...\L...\L.........s{B
..s{B.\XJ..\XJ.i....N.-.|'....ok{)..9....9...3?...3?...#.\..#.\d7.].d7
.]]....]...;,...;,....u....u..q....q.............s....s.B..q.B..qj"...
j".....u....u.#nD..#nD..aH...aH5....5...y.Z[.y.Z[.<....<..e;8p.e
;8p.........Z..8.Z..8U..Z.U..Z...................R.$..R.$.t.K.....ex:7
.ex:7[.*;.[.*;p..W.p..We.......0.&....&...~v...~v...h....h...........q
h...qh.A....A...J..q.J..q.}.Y..}.YY.......... z... z... .S3...;..M....
.K.oI-b./r.../r.p..G.p..G..XO...XO..e....e.6..L.6..L<..:.<..:%.H
..%.H.Q.v..Q.v...........u.x..u.xP....P...p&2..p&2."..X."..X..p....p.u
]){.u]){..l....l.S.k....^..v....................OJ...OJ..............-
....-_.:'._.:'..FE...FE.........%.a..%.a.K*...K*..j.k....y..do...do...
.........TN...TN6N}/.6N}/g/.$.g/.$.k....k..T....T....Z....Z.....z....z
....................AB...AB.F.n..F.n.z....z..-..|.-..|XC|4.X...0,.....
...GI...GIf#...f#.._.ox._.ox.W.1..W.1.........W....W.............Cr%..
Cr%.g."..g.".$....$....RW.o.....T^...T^.~.P..~.PmWN..mWN...!@...!@.?T.
..?T.0....0....C^L..C^L2;Ig..v. Y.6.G_).).c_1.x.S............`..0o.).0
o.)V....V.............4]...4]...................=0E..=0E.5.7..5.7..!.n
...7..........L..7.L..7..!....!...x....x....b....b.Ki...Ki..........P~
E..P~E..Tq...Tq....F....F..r!...r!..........T....T..n!<x.n!<x6..
..6....n....n...P....P..H..v.H..v............/..../..........l.1..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/n1yFjPQFEChBHb2nPFdlSnxInZe06KGVB02Q5AxqI18=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2611
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 04:01:23 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54927:4:2596.....LwoP.U......f..B1..t..&.&a'.F.|.]..2a..^#.........-
[email protected].\$.})..J........H....*!...T...t....v:...1...._.#..Cv.rUg.K...
.V.........cI..^G..%..R.h...g.-..P.)....M.T.F.(K..>N.;!.5.5.....U..
z_....Y..E"......*.d..J<..;......e..^..G.-...../&.N....t...3.....J.
..t.........g....5..:.;:#....#.y..fJ.".Q|..l..CV<..-....-....!....!
..(4U..(4U.?xK..?xK..............s....s...........M....M...M7...M7....
.................f.......?.%..?.%.N....N....SA...SA..u....u..).Q..).Q.
.`....`..%..^..&. .;....;..E....E...Y.....E6i.......D....D...t....tk,9
..k,9..........*....*....V.=..V.=2;Ig...J. Sh:_.G~>*..|.S...=.0..N.
4...w..K)2,Q.....|m..W....W....(....(...3....3a..e.a..e.l.*..l.*......
......S..%.[q.l..q.l.q....q............b.?s.b.?s...&....&\Y...\Y......
.0.X{.O....O....D....D..Wx...Wx.d....d....{(N..{(N.a.z..a.z..F....F.v.
...v...m.D9.m.D9;....;....J....J..G....G......7....7.If...If....u....u
............l....l7.(....GU..:....:.g..`.g..`..]....].&7.>.&7.>3
....3............... .... .;....;..K....K...D.|m.D.|m.....;. 6.!.n.j..
...RW.5...E..3.E..3.........U,...U,...q:...q:.(G*x.(G*xU..w.U..w~....~
....t.)..t.)...S....SD.-R.D.-Ra....a............R....R...1....1.......
......f....f....AK...AK..G....G...........o6)..o6)i....i.....6....6.~x
...~x...deg..deg...S....S[..1.[..1#..J.#..Jw,)..w,)..........*.$..*.$.
..j....j....!....!4n...4n.....v....v.[....[..C.:..C.:..........h..$.h.
.$..............~jD..n..L....L....$h...$h.{n...{n..(o...(o..y....y...u
..?.u..?..U}...U}.o!...o!.|....|.............7o...%.Y.. .... ..,,.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/B9oFeiEQxNCzVOPSXAabZqrJjttO7a0CzH6NcQHUIYI=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1430
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 01:50:51 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54926:4:1415.k....k................0..Z.........._.....$... K918.|qG
..9s...|....C.6...r.k...^o.yv._..MLpH......!D2g ..)........!.t03...3..
f/D.].!...M....Mq.......!.1..6z......X.Z].B.0.Gn......]*...;WeZ....(.\
/...R'.M.U^;.R...R....w{...w{al"..al"..N.}..N.}.0.6..0.6..RW.......2..
..2.o..F.o..F#Y`2.#Y`2...0....0..7....7..........Q.)..Q.)..........Y..
..=.[t.QH8..QH82;Ig../&...~....C*...^....(.........~....~}..~.}..~..7y
...7y..................\....\...,7.x.,7.xw..c.w..c{.}..{.}...P'...P'.%
=k..$=k^.9..^.9.U.|L.U.|L..........d<?..d<?...z....z|.{..|.{..N.
...N...........9....9...~....~...mD...mD...ETi..ETi...=....=.r....r..w
....w...............^....^.[.1..[.1=."L.=."L.9......).N=...N=....r....
r..\....\.1..{.1..{.h....h..T....T......0....02R.|.2R.|GWJ..GWJ.......
...-....-....|...Ws..NaS!... .......b....b..0...z..TYi. .l....l.. @I..
@I............@[email protected]..)....)..u....u.....
......V%{..V%{...i....i..A....A...$.0..$.0`7.M.`7.M1z...1z...zcc..zcc.
).3......o.b..o.b2.P..2.P..........2..B.2..B............1..b....N....N
.Ou...Ou..H>i..H>i..........w4.:....v.?~7..?~7S.k..4...3S.6G....
G....~....~..K ...K ..z]...z]../..../....-r...-r..o6....*:o.;c.o.;c?GK
s.?GKs.......n..SN...SN... M.^...;...2......d.`.v..`.vj.k..3a.........
..p88M.p88M..&X...&X..R....R...........AE...AE..........m`.-.m`.-~fF..
~fF...B..:.v_..p.# ...# ..A.v..A.v...v....v..MU"......^...[..!L...>
c....~4...~n].D.Rk..&d...&d.1b...1b..............<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/7giqbAFh2S33m9VF3lXAepQAHn28qzEmckcfXXCSNJE=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1088
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 01:00:44 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54925:4:1073..........dw..6$..E....y.........A.Q{I6...Z.Q.k.*....ye.
...e...5 ...5 ..~.*t.~.*t......,at...................d.H..d.H.!2...!2.
T....T...!.#..!.#....4....4M....M...s.6W.s.6W..J....J.f....f......<
....<.O%...O%..........2;Ig..\....l.>...f,.QGZT>._.]...>I.
*..F~...F~............6....6.R.$..R.$..q...<....&g=................
..x....x....S....S....#=...#=d {..d {.E.f{.E.f{.........K..N.K..N.....
....Yu{..Yu{./..T./..T*.PJ.*.PJ.\....\...!.n...._..F....F.............
......\.[..\.[....C....C.-....-..X.{|.X.{|.U....U..Y!c..Y!c.3....3....
fHC..fHC..........0......[..Q^.<.(..<.(P.W..P.W.. .... .........
..B....B............... ......o............5....5...2.%..2.%...2....2.
I....I...7....7..cQge.cQge.H5V..H5V.........98C2.98C2.S....S..}....}..
.joid.joidu.. .u.. .m.P..m.P.f....f..)ca..)ca..E!...E!.:{3].:{3]O.!#.O
.!#...n....n.f....f...5._..5._.S.J..S.Jz.lf.z.lf...........9....9..%..
..%.....m....m:.2..:.2..U....U.....@....@:j.a.:j.a.D....D...........h.
...h.....4k...4k.%.b..%.b.........y....y..._$..._$..."._.."._..[....[.
y....y... .>.. .>..v.x.'.....V....S..S....S..."...."....x....x
font>....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/rJ5UiZfVNVY8I6QwHOGKfYO7eACujpZZ8S63AXGO_sU=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 4089
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 00:10:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54924:4:4074.....Ub....Dp..3}....[`.6.XRxo<.m"......ta...YJ.X_..$
cH.'..u......k........f.....M.MeX..sv.2MT.G?......d..V8....79.........
.....g..... (.....V .I..0..~<6..j7.H...5.9...L...... ...:....Wc";N.
...........,jjB?.I..P..9..f.j....F.T.&J......I..6...L....O.e......V..W
q*...A7I...ss..Q.. .R#....%......*.Z*.?..xi.b..-.&)X......T.(..(.F9.pM
..m.9...-....1.h..C....C......p......._....^....^..u.F..u.F..*.4..*.4.
.E....E.J.d..J.d...v....v."..V..F".*.....W....W.ay...ay...#k...#k..;_.
..;_................W.n..s....s..........%....%...'.v..'.v.:[...:[..=.
...=.....OS...OS...Q....Q..[ ...[ ..)....)..g....g..Wt......J.RG...RG.
JCB..JCB..........d6.c.d6.c.&.p..&.pk....k...%@.!.%@.!............1...
.1.............../........../H.....X....X..ni...ni.........L.IE.L.IE}.
f..}.f..g.I..g.In....n....f....f...........*.j..*.j....&....&.w....w..
Uo...Uo..Cc.q.Cc.q.6....6...i1s..i1sceL..ceL...........'....'....XN...
XN(.LO.(.LO1....1...&....h`.r.v.!....3.....i.............V...$........
..)...........'....'.k.Z..k.Z.m.>q.m.>q..................g .m.g
.m.T.:..T.:.........I....I....?~7..?~7S.k..]..A.../..../..W ...W ...D.
...D5....5.....uS...uS.i....i...........j.k...R.....#"A..."A...~l1..~l
1-....-.....C....C..w....w...T.j..T.j.#0...#0...>....>.{.Ig.{.Ig
.h....h..F....F...XC|4.x3!sSaF.z.9.l..<.l..<..^....^..........$.
z~.$.z~ug.K.ug.Kd....d....e....e....Z....Z.r..f.r..f...........RW....@
...C....CT_...T_..i....i...2;Ig...*j.....T%....\...L..H.......kp...W..
M....M.?....?......5....5..m'.h(.b0. .....3....3...~..H.~..H.x.}..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/iCqahQe97Rfv1mK1qV4HwQWuWFOF-fi0Z1SEHfHqiDo=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1581
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 22:00:37 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54923:4:1566.Y.J..Y.J......n.....a.\8....U..'q)..._.xOQM'.XA.....R..
.R.....D../.3v...3v.J.l..J.l.i....`<..L..3.L..3|(D..|(D..a>...a&
gt;.......?f[Pp.......|........ 1...=....=..f....V............v]...v].
.........6.[..6.[...C....C..........Z.<.......c....c..Y..../{......
.........2|...2|...........2;Ig.....u..0t.Q...JP..Y{.R.......;.L......
...-#...-#....P....PJ..g.J..g.JE...JE...m'....8..... ..H.U.E*...%w^...
.L~.i....O..Wf@PK...!...........y......m.W....`...N..*....*...w....w..
.X\...X\_...._...f.x..f.x...)....v..........u..#.u..#.Y....Y..h.V_...g
?.....f....;...../f1e.x.(..1..... m..Vo...Vo..1..K.1..K.~....~...!.n..
r..s....WuQ..n............RW.bk.......q...h;_...x|....8...Ou..........
[email protected].`h(.......A.K.O6.K.O6.t....t..i_16
.i_16...U....U...w....w}:g..}:g.j?n..j?n.^.)..^.)..fD...fD.;z.=.;z.=..
.....(i):...L......yAHb.[7*..}.{..6..J....~....5....5..0.........o....
o.4&...4&............7o...).y...K..L'....v....vY....{\5...,z..........
.. .....i.oH._..&....rk5........x#e............V.~..x..... ...a.*'.@E.
..Z**.......<.fC"....Iv. W.....D;Pt...6.-....S-...S-.t....t...L....
L....y....y..........j1...j1.....)....).T.5..T.5.|.F.........=....=...
r.O..r.O..p.f..p.f]..e.]..e..-3...............y.%..y.%S.k..K%'.4.n....
TM.....h....h....c....c.B....B...o6..b!.~-ZuFL....L....s,M..s,M..z....
z......j.?.0...yd.. .k..%.{.b..)j.-s.E.o..E.o...z.,.V.N...O...2R.|.2R.
|.|l...|l... M..[a..V.x......]4t.p2.t.p2j.k...o...n....n....?....?....
......U....U.....8....8.mYC..mYC. Ta.....P...h....3. S.3. S..M....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/_LeYmVcLjaymWdywoaBs2fZ3zvbAC0b1zHa4o6BHJE8=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
o..R'6..R'6...........l}...l}...RW.?Z...X.O..~M..zV..e9...e9N..p.N..p.
}....}.....<....<p....p...............}....}m....m...... .... .%
}v..%}v...,....,..X;...X;..[....[..7T...7T.c..G.c..G.........U..m.U..m
b&....t]'....%o a...A.n.Y..Cy[).1,... .u.s<..R6.../..sv.... G't....
.../...91/V!...!..>x..a..f.a..f.<V...<V.lUb..lUb.s<...s<
;..I....I.....W....W..C....C..9VD..9VD.7....7..............6....6.l..%
.l..%S....S...Z....Z...V.pn.V.pn..................d.Lh.d.LhQ7.".Q7.".,
....,..g@&..g@&.].....GAR./..../...........*.B..*.B..Hx<..Hx<...
*....*..........^....^..x.T..x.T...........ka...ka........~.b.....{=..
.{=.(....(...2.W..2.W.'n...'n...6..<.... e.....................k.K8
.2d.c.V.X`.V.X`{.,..{.,.t....t...zE...zE.....u....uG.X..G.X...G....G..
7o.....EQ.u..A._.?r..>....>..'.z..'.z../Ct../Ct...r....r........
.T..N.T..N...........W....W..........OA.|.OA.|T..\.T..\L:,..L:,...h...
.h..........uo...uo...d'E..d'Ec2.;.c2.;.........#(.f.#(.f&.........r..
.vf4..].................R]..j.#......7l<..X.d....d...d....d....s...
.s...pQ=..pQ=............@....@#aj..#aj....5....5.o&...o&..;|S..;|S.i.
O..i.O..,%...,%...\....\./..../..q`...q`...I;...I;....I....Ih....h...T
....T..............?&...?&$5.v.$5.v..>....>.y.r..y.r.._x..._x...
.t....t.T....{.................,c...,c...a....aW([..W([...6....6.J.e..
J.e...S[...S[.f.D..f.D.H.#..H.# s... s..l....l.....f....f.Nr.r.Nr.r...
S....S...3....3U.N..U.N.S.k....O.m}...m}.......................<...
.<!c...!c....N....N..........o....o..._...._.....M?...M?..'G...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/2Co669pBX8sWhrvtK2V8n-iyxDvdICtpqxZfO4qFwdA=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1873
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 19:01:03 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54921:4:1858..~....~.......h......#....... -.e}&s.'<.N..y........
.}......2.9.3.D.V..u..e*.......:.g.....``!N....(.nW..[I...pB..r.YM...O
...@./....G_..K....K.'..O.'..O..v....v.i....Vi|;..G.......q....ax...ax
..........G.9..G.9_X..._X....RW.!Su*.5.Y..5.Y.T........]..1.X..1.X.x..
..x............1u.V.1u.VY......J$....Q.4).9.y.4 >...;..%[email protected].
.........I..,.....;*.....]...'....'u/.W.u/.W...R....R.r.K..r.K2;Ig.$.'
.g..P.........bp...bp.i..^.i..^..........X....X... .... ....m'.j.....0
....0.i{...i{...,p|..,p|.B5A..B5A.6:...6:.u....u...[....[..._0..._0..L
....L...?.9..?.9.{E...{E..h.V_.x.....!....!..f=...f=..7o..T....\X..3..
.9!@u...#;...I.........@3[.EaCo...h;_......1...Eg...Eg..:.L..:.LJ..m.J
..m.U....U..dE...dE..............Z....ZGi...Gi....&/...&/.%.s..%.s....
.....$<X..$<X..c.(..c.(.....d<..U....|...;...}...N..d......y.
.D-&-....k1m.h\K.....7A.9...P^..m.].-,..-..C....>....p..W....4v*a.m
....#8......6..y..y#........0..........A....A.........n.*..n.*....K.V.
\...........5P...5P.2....Tz..C.......\....k`.-....._N.Y..... .[.b2..w8
B....p,.2.G4..7:q....q...Z^...Z^..&...1.GP.j.=k.C..a4......jK..]..E|}.
........{.$g!..9...V..c..=.....I....vNA<5.*.MX...[6.a..z...uk.gx...
R..r8...G.e........f..p.8 .4$!..j..0?%.:...G..!..[.("-.{U%.V^"......qC
......].:)^./...W}.[....J%.nv..G.v..G.9....9..'..|.'..|..V....V..a....
a...|.F..#.../H..E.X..E.X^....^.....*....*..........`......[.S.k...k:.
.."O.E.....V....V#=...#=..h..?.h..?..A....A...f....f..*k...*k....z..TQ
.......o7;.%y.Dy[..........p4...p4... M.m.....|.?_....&HZ".$..z.g.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/SBcYP83hLjrvJOk2McHsxGs6FsHWjiidYEUsQI1V2Fw=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 4116
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 17:00:42 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54920:4:4101...$....$.......S..OVT.B..2.q...U.n8.P.Zh.).j..4/m..9l.V
.P.....3.It.3.It.S....S..=....=....s....s..4....4...r.7G.r.7G.1....1..
M....M....o....o...[.v..[.v.. &... &...j....jj_[l.j_[l>.@..>.@..
5....5....I....I.[U.4.[U.4v)...v)..7....7...{n/..{n/.5do..5do.........
..1.,..1.,...........................]>.Y.]>.Y..........t....t..
c....c...7p3..7p3..5....5...A.#..A.#..........F.[..F.[a/.V.a/.VPr...Pr
..{?2..{?2...P....P.r.x?.r.x?WJC].WJC]N....N......N....N.^7...^7...{(.
..{(..>....>.i}f..i}f...3....3.............V....V.&.X..&.X...,..
..,...........K....K.......a.|. ..k5n......%.... .J.. .J.6.P..6.PYJ...
YJ..=.mN.=.mN...J....J... .=.nz....|b...|b...FRQ..FRQ.........&......[
...f...........W<BMw..BMw..R....R.....................*....*..p.m..
p.m..-.)..-.))....)......=....=8....8...19B..19B.d..N.d..N..%....%....
[....[...2....2.V.:..V.:'....'....m)...m)..k:Y..k:Y..........P....P..
p"^. p"^....Rt........!......7...UTN..|...;...-g|....]..n...W...`.....
3.(......=.B..o.... [email protected].{"....q..8...I.Kr...bK.3N..g...
..............Z..~..s.s.[......C.8...\...)...?..Jx.!H....}.K...Z......
c......1..v.2g!....D.w........F..N....!.Y(4."...3S....9..`.3..j.!.I...
L.....<jg.O.N......,.Q\......~.b..}.M.Z{r.8.^.U../#.&..,g.f!Z.3g7..
3g7...1....1|?=0.|?=0.>.(..>.(Z....Z....Q....Q..X7.m.X7.m..K-...
K-w....w...!....!............!. ..!. .e....e...j.k..].1....$..."....".
.........)C|..)C|...e....e..l....l..*iC..*iCW....W...N_}/.N_}/.1.i..1.
iQ{...Q{....m'.\.;^..V....V..?....?.....`....`M..n.M..n..5....5.i.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/skFus4cWDXN8GL8gnFtUdRf6nKmCCrZ4CR_AhQ0aau8=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2132
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 16:00:47 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54919:4:2117...../..Y..2;.FG.N.?..Y...o.tQ..........`...I...I..[....
.....{R..\.}...6.. ...:vs...'../..c.A..mT...W...|!.mF7A...G..8.E.....
Ws...IQ.R.[.....eY.Ki......W.i$_..........._L....0....!~m!..|......-.f
....f..i....n..#S.8..e....u.>.28.!x...!x......8.....rL...rL.|......
.Y.W..Y.W...RW..\7...................P..].P..].O....O...//%..//%.i.@..
i.@(....(....Z....Z..GB...GB...-.}..-.}Y...............C..M...b7......
..0.LY..Z-7K..4......P.~.x..|..N{.:....:....3zL..3zLFz!z.Fz!z..I....I.
*8...*8.....]....]G....G..."..V.t...v....v..._8..._8..`....`...&.2v.&.
2v...*....*l..7.l..7..m'....,](i.......8.......y..Am.D."...."..-v.l.-v
.l.........0x(..0x(..........Om...Om....."...."............\....\.[...
.[... .u.. .uT....T....=d...=d...h....h...^....^.>.z .>.z ......
...(o.S.(o.S.|.F.z|..Ux!...E.Pb4.(.>.1]>.G..s|..#.|..#.........
.I.. .I..h;_....L...<,......_.p.A.Z.k...mYO65..................j...
.j...1.2....5V.....D....D....7....7...<"...<"[email protected][email protected]..
.........1R...1R..........zY...zY..............}....}H..X.H..X.C....C.
..................._.jL._.jLo..$.o..$......yX..c;.vo[.....yAHb.....Y..
..Y...H....H.....6..d.............7o...[H.Y.....9..2F..k..K.B,...s. .*
#. .*#..W....W.... ....]E..6..'Y].}.......p!.z..uf._.?....?...].e..].e
&...5...A'.!!.....I.........C.._R..)..b...<........r..R.....J...T.A
..cS...A.......r.....Q..%...O.[...l...bX.o......h..Z...5.l........C>
;KX..r..3.W...I/.JYHN...O}.q.w..<.$.('..\B0;[].]^..T%........@'m.*.
An..1.rYN.c.|.:.J|...J|...).3.d.5>......^'.N.V..N.V.>.vk.><<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/77vHetNOt1hRHVuAH52FbCdQTJwqEgpbxZiNw8Hf92g=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 894
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 14:10:32 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54918:4:880..(....(..........%..D.57a...."...o{..T....!Z].....A1.^..
_n.`VM...L.n............B...J..!.k.4N.-.b0..A....A.3..y.3..y.o6......U
RuVE.....6.....\CIkI.CIkI.V.=..V.=&8...&8..>=t...S....nW...nW7.(..J
.s0K9..{..>.1%J..1%J..nH...nH../..../..|.F.g.......h.|87....7....W.
...W..<....*.@!.........Y.....>\............ M..W..j.k..."q I...
wx. .wx. .h;_..I...w.B..Eb...Eb........."H.h."H.h&...%s...?...^lC.g.F.
...3..#.....W..b',.A.....MqY...%.r....-..E..........`....I8......,\]&.
.. 5...KP.)x..2..w.n,d..q$..Z0......%..V{S..[.....W...8........P....P.
.r....r....................P...Z...r..S...7..s1p.(..^'.j.^'.j1.2...q`.
'-)..'-)..B.F..B.Fg;jI.g;jIi.....O..<is..<is...s....s.@u...@u...
.................u(...j.|59.pP"7..qb.K...N..|..m'..0...y....!MfsL..fsL
.j.-..j.-._..z._..zt..u.t..u;....;....Xk...Xk..j.,..j.,.s.,..s.,{..K..
N..S.k.....0$....f.d..3UC..~<:..B....B...... .G.><..?.E.f{.E.
f{Q..I.Q..I....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/QfkQ0yWr_4I0G1WQBVqa2lZJgzDfK_gsq3C_w3N4JYw=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 411
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 13:20:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54917:4:397.....b..b>.SC.l/(. a&..if...I....S.7..&j.eb...]Ad..b=#
..;.0RZ..........^...X..v.?h. .h"....W.^.|.*D..:mG..0[.U...... q]..dUA
.........y.....O.Wm...3[..N...`...3.?..-...X.1*..'g.>.X......F.....
2...{..M].H))D.....:...Z.M.h...;g...)zz&......u..H.....R....-..4....'j
..J.|..{i.Kxx..g.L#.....t}\......XSy.l...H.@[email protected]...........&B..
..../.4...rd..g{..`:...%.q..^.HqJ..2.. ...I.dH.u.x.....G. 9...d....ont>....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/EvqzcZp4bVd4cfZLC8AKSI9VMn_dz4QLBIdq4T2EPUs=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 13:21:02 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54916:4:1025...........b.....DV........L.K..4...%8.....6s$...Y.%.}7|
.?;U....A..a...#.-,..#.3.../..>...t...7.....qqc.`......E9..5.=.&n..
P.1p;...51.a...[..5.o...q..%.p......~T....B..s.. p..o...)\7.^....pb...
..h/o8.$..........0....]T&C.d.3T....../..\.F..!.......d...Q...........
.S..[.l...BCH...H....{.t......v....lY.$.7..L.X......[..N.H.4....D ....
.....85]R...7.Q...U.\W.Cz.V...pA%..<..W.Y@g)..."...C..?d.. w..K..X
....^.....yI{..:....uG".O..p=...k!`#....)...r0<7..x.H^.|A.F.A.G ..2
<..........C. .......w.......z..h..*^.o....]|......k".G.\.......f\2
&Fo4q5wN..C..X.3.X.M. [email protected]../..6<... ..OI...!..1)-......V
.^..b....z.r.~...z.J.$..ja.)../'.h..._.U.z..U.&..}.%..n.s.bjZVK}nE./B(
...J.#[email protected].}.G......H#QI-....Z.p.ns....K7H.yu|...
p...a&....khS.Y...^....$..s...y8....WZU6f_...ov.......o....~s.....zp.B
........A{f..*]..b.....Z......2..o...A..'...T`...|%..{.=~8R"...=..,...
.>......L....."...vA..!.=I...;9...7.j..O).j..3/...$q....ho.[.....&.
A}....}1&.!r...G.x.........x% ..KmV.....R'..A'..V.r.>...x$..gn..{..
....Y....UTHTTP/1.1 200 OK..Server: nginx/1.6.2..Date: Fri, 01 May 201
5 04:21:35 GMT..Content-Type: application/octet-stream..Content-Length
: 3809..Connection: keep-alive..Last-Modified: Wed, 29 Apr 2015 13:21:
03 GMT..Expires: Thu, 31 Dec 2037 23:55:55 GMT..Cache-Control: max-age
=315360000..Strict-Transport-Security: max-age=3600; includeSubDomains
..Accept-Ranges: bytes..a:54915:4:3794.><...><..8Eq..8Eq..
.................|.?....H.....k <.cR.!....:....:...........i...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/7k0BpIfoAfdNOp4XXRDJ3lpFbLKfBQF4dcG9tVcjVgE=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1007
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 12:10:59 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54914:4:993....i....i[....[...sG'..sG'.. .p.. .pd.NR.d.NRa.(..a.(.jI
6f.jI6fF.Y..F.Y.I.X^.I.X^...a....as.H..s.H....4....4..E....E...M....M.
...@....@.........`N...`N...c.m..c.mp.q..p.q.c.Z..c.Z.:....:......9.].
...(BM..(BM...A....A.a....a..7 q..7 q............Hy...Hy.........'q...
'q..[..8.[..8.<.N..<.N.-....-.............gM...gM..^....^....,..
..,Y.j..Y.j..J1...J1.Vm...Vm..y....y...<.\H.<.\H.........x..3.x.
.3.n...hR.............|$...|$.]cM..]cMge...ge.....'....'f>...f>.
...!....!...\Q...\Q.-...)...'..*.8.7....* l..'zJ..1.......o.E.[..E.[..
.X....X....j....j..........|...h.....F.... a.w_.a.w_..b....b..w~...w~.
..b....b....1....1.|....|............|....|..]....]....;....;..Nu...Nu
...........2Y...2Y....:....:..^[email protected][email protected].{..1
.{..s....s..."NM.."NM.WU...WU.l....l......t....t.........z**..z**.H...
.H......A....A.ty...ty...3....3.R-...R-...{.>..{.>U....U......4.
...4D....D....uC...uC.............5....5..%,...%,..X....X..L....L.....
......[....[....*3...*3....8....8-.-).-.-).............
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/HcTDZdOAqbjP60mqsUDke9Xw0HITGpAZnncOOQKDDKQ=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 6031
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 12:10:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54913:4:6016...... .../W.C_C^..Q.U....d......FWOn3.m..G....iZ~...z.'
5...P4...d....d.........l3L..l3L.'.]..'.].}.^..}.^..........T.X..T.X..
........{..5.{..5.j....j..8..P.8..P..%....%.V.D..V.D..B....B..TTd..TTd
....@[email protected]....
i............."....".3..I.3..I.e....e....Y....Y...D....D.R.B3.R.B3.XDy
..XDy#.d..#.d..v....v..lp...lp....\O...\O........."..b."..b......... F
... F....G....G..........3[.6.3[.6..EI...EI.A.o..A.o1.2..c...X......&l
t;....<..I....I...;....;..........b.o..b.o.7 .,.7 .,...:....:..n...
.n..o....o.............H....H....p....p<....<...............*...
.*.H....H....T....T..6....6...........0.P.......c.n..c.n.....<A../D
....S....S..:....:..'hW..'hW.Iei..Iei.... .M....[...0..`An.>...Y...
.[..XqB.:......UL/..#~...].r..:....:..a....a..!}.B.!}.B.5V...5V..w.?..
w.?4.l...U.......ELL.%..&s......{..'z...bl..........V.]:....DU.e...bJ.
.._}..Yg.%'Svh{Z.O#..$......!..UL..y..{..<.&..lk....r...Z...\.y .5.
...d?}..J.T17j=&...4...|.6..oCHPdK0......5..4"..N...7....!5..,.F.<.
C'..0e([email protected])".....qR......n.....e...pw..h... n..!n.z..-Q.[..
....1q..F.1AZ=.1.....c.d...rE1....... ...sT... .......[.;j.........K .
....$.....yw..........,ff..O..DB:M.nC.r....z..N.hM..^;.-|..(..b.d.....
x .s..9.:.|...II.....g..'A.~}............]......nNP...04.....s.hQ_..4.
.n2.=E.8=.M.. WZ".....HTa..).n..x../S\..Z..jK<....^>.....Ol.....
..,].O.. ..F.a. 6B..B.m......F..4t..Q.m.B..o.k...P..Px..~b.#e.N..(..|.
w<9....).U&...I.._1!...E1....n....R6......(..........3.].......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/T_aMBLuw7gCWF9l5r-w4H8u5L6uL0GLJfqLot_fdaek=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 62
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 10:21:00 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54912:4:49..T1C.1D{..[..u..L....d|.........7.:Yi....m....._/.
...
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/8pHhQz9xknZc2CVxwA-g54bDE_T_5LY6xJIORyAqCv4=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1101
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 10:21:01 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54911:4:1086..T1C.....d5eO........?..y....P.j..:....H..{T..y..G.....
..L...........l...1.*O..l...oi.....Ks......(....n...v...N....tN...>
....L.I..5z{.....8.....j .B&....]......5..<..7......hJ...$j.....gP.
..x.ER..C....Y>.L.....X"..h.....,...=.....D..p.lDm...4V%.{.ru..L..0
.`...8.p.Z.....bo....s..c-M^.Zu}.7.E.... l.-.#..4...PH]..{..L...}..6B
.y[......wW... ...8....<...!...N"e.o)M..Xe..nK.E.."1k..T7..Q.....a.
...|..Q....[.}d....c<.Z.<....Z.....n.I...7u.......x.Md.G@l......
...P..D.F....[C#A:...3.P.{..X....5..Mw....&...$...nGw.... c.0;X.3.....
P.h. ...$......`5:..6..@t.*...T........6tk..7.....6..M.....a.&..G..q.&
lt;lG.& ....N.z/....[.K9.e..w...C...E.......s......6.b...5U..j..V..c..
...ZK!1CRl..:..I_?.\q.......N...&..p....Z...|.Ab6..u~............$7..`
.e....}.NM....e..&....k..........>..E1...j...7.. [email protected]...#..^'
[email protected]}.. .]...> ..3......s.....'.- t&c.P%.1.f
...1.R...|.."F.....8..-.(..h.4.N....:.*0...mE"Y...\.&6....~x......9...
..x='.B.,r...V{&9.~!.....v..Lc...*....[.i=<.z..U.W.F....3..j.%D}.=.
]Q.....T>O..Sy0#|... .k....h_b..).R,..7r'|D8[[email protected]}Q
...#Am....S.......
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/mQG2X2AwB1UBKbcXP7oraGgK9_Js1nl7N2vjMKo_7Uo=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 10:21:06 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54910:4:2050..T1C.I......i8.....;TnV .x...Z......."......qgt....C...
.F23.e.Y`N:.%z....I.?.r ..Q,............L.k.]Mc5.<..X.J.UMs...7..5.
.1....r....u...^.)....j..}}....Z.Q.^...........-......x.........~7D.I0
.!mL..'`|6e......F3=. ...........s9..79.?.....Nch....C...."...<J..A
Q....j...\.N...IW._.r.../.W..N.....91...$.:..Zg..0..yzvN<2.:.R.....
.....V..O..C.1.g%..h6..V.$.p.........p...F4.CI.5.b]...(/A.R....Aq...t.
m/.b.<.L>..]....E.Z..d..G..VoG2A..(...\......O..~bQ..-..I...G...
q..K..7.{._.i$.....*,V"=..G1..'.Y...8..j...Q.w..F3m.c.9..nO...........
.\..$6...uA*...Kl..N.t..0.<..=...k...p.W4...n5%zO..]PTa.&h..je...k.
.GQ.9QF..qr...-..6c./.D.w.a.G.................94...Gp.=..S...}.X..L>
;...q..Z...I...3.9..3..o.5}...C|...(.B.Hb.# M.i.Te...o.D1........bF...
.A.r.......Gm.)F..9..~?..w/EFN..z.=Gj6..b._...l....T..>e a...v...s.
..-z.xv..P....O..q.>s.G..I=...iS.....J...............|.Q..)...`.W.k
.?...;[email protected]....[.. J...|.w.~.jz2.r.D.^..G...%.>;5 ..I..r.,..
...f]].7.h.oM.3-../.#.T...K....Y.M........*[2qR.x...J..N.;....:......9
r..9.8;...[....c..0. .k....(..Q.j./..X.... Q...XJ.0P.1. .....kWzu.I...
k..yB.8..x..p.O..2R.A.7'z......j.L..5... ...?X.t<6.|:.O..W,...(eE..
V....]...\....S~..~?..R.O0j>^_.....$..kF`..Gu.....;.%.5AI.].1.9....
.cT....x.m..t.....l....$....m...-..S......T{W.|..E...Q.|kA...........]
..c.%C..|s..u7.2)...f..2U.....e....._O/#.N. ..B.PH.H.....w.#..":...o&.
X.....W.H.C...F..j..3.7Em....\4..k/.d...&u..\X.-. w.$..s8.-.`...JW..`.
.q..b|."D=..MI.....M...le..a...). .Rp.............a1j..jg.j....E_-<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/nhJUhSVWvHs0hfzlykFUz6TAZgIYTI2u0kvRVsqf6qQ=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 10:21:04 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54909:4:2050..T1C."....1.............X.P..Ii.n...^.:......K...7.....
.....{......"g.DZ.-AW...Z..,$...........*I.......L~.....F.`_..P.e...5A
..C..uno.&.Y...O...)X..f.....`.9!X.Fs...Vz&. .6...&y~Mh..8=..Yn.E\I2..
....g.%.}].........[(....hD.. .>........`[.A......U#....!...e....Uc
3...5..IX.U..&&.p.K..AS.h.i..RN..,......2.z.V..~GU.Q...JAJ......|T.(i.
...........C.....S.....JTcd.Yh....5..E]......)...#..}...$<% 2...^..
.O4.........6..G.l..._...u`...~....&d.$..#..2i>.e.1....@T{c...v.C.;
u..s..8.P-..diN...*];.Po.;.t= {.......bv*...%...T,.......r.FH.q28.D.*.
)....]M..6..z.....b.Sn .j....l......CL.j=..y%............}.}..jP....v%
...j.E....|..H.j...M....&.O\Y......J.......8.....?X.C.....o.......O<
;p:.&.]......cS.P...).X.a..F......1!...z A..,j..PV.S.*NZgL]....>=.H
...@.;....)3.0ln.D.................h..U..a...K.2R.^..c..{....yxA.50h..
.!u..y.]....T..14......>..^......1dE-...p.}....,.gE.[.f.-#OX.<..
...-./:..*..C..rj"^7....~.....S?.....j..=:.f.(......2.'...BTY...VV2..Q
...2.l.O.HW.e..AA.....%qb.'S....wqo...4W.o2_.P.q.F.l$%.... .......x.qH
.W._r...[(. .k...XdY.<.....-...&{...l?./_.].c.&..%.d..r....m...X..p
T.I.NNeI....%?...[.i.. ...............?R].h...bX%...w.......P..r..h.T=
T.%o....H..........C.E:.V..... h|............8...%.."8!......n;L...R.Y
`6a".Q..Bdx...).nL...nkh.r..........c.*.]...}...O..`z...KK.'...N6...\.
_.G.*..}...b~..pS^.m...$/.u.!.'..4....?K*..R;.....T....)".s)Z.D.w.. ..
....-...}....BC..l...-.`. ....A.2c....,........E..E.j..>.'$)|.!.*L.
*Qf.`J..y.0.}..OkUZ`.:o.;[A....u... ...Q.!...}Y..A~.W)"y..)[.#V...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/DaxhlnrV0XFnHcnQXoIcYI3Ok7env3ziAM9YJA0w0-Y=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 10:21:00 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54908:4:2050..T1C............=.....T......[.\...C.guv..g.g..c b.f.w.
.UG.J_W.>..2..o...5..?D.nW.f.....H..^(.O.&|S..!&_...-`".P....q....O
R......y.....q<Qm..x. ;........X......1vw.(..(.l....xLG..M...R*.E.v
z.....*...8.l....b.gE.~.<lm..,$Zi.f[..7...W.H....I...N.."..$.,3#,&l
t;b)n...y0..R.L.`.t\.J.7..H.8.>!..F.......2.]..IQ....D.....:..f.E..
2.....5.m..1!...".U..B.z.....2.......?.f.&.Va7...PNp....._3"....1.6w.z
[email protected];.......r7. ?...73..iw|.l..zm"~....P..E......Z...\..H:.X..IF.
. ...,@..^..-..1.....8|....2g.)..].?....8.........PN.S$]..6).?.v? ....
.. ..^..Q5 e.......U{..Lr..T..a-.R.S....WX.....r.1..D..?...T.....O}...
.2....P. b.i3.u......x....n..*..K.....a.x.^.I...(...}.I[.b.^0..m.l....
.W......7v.J......I7O6....0Ab.I.]o....@!U.......|=.....7;......@......
\!..'Nzn...S..].0M..uJ..j..T..vW).L.H....ne4.{.`.......SX.>..1..J..
...?......&......6..,z...............2.......g..?...).cI..x:.C..(...,.
.j;..*..N.tV..=.z....jX...kj3.%.^...D .D..m.lU!.....N......7..6$.\. |.
{.o.....O..............*.t...u-d**!....\.....e.s.......mq.....*...3.c.
[email protected]. .k......R..D..z...f..rs.r...:.7.Y....1.:....>.Xc...j...}T.
..H.C........o.V.....FL...t.....Cv|Pw9I..S...G.A`./z.v..V.............
.?>?..K...Ch*...1..*.?=.....i.#.).u..g..Vw.,...........V.Mm.F{^....
.I_.%..}...$PA.........f..z.%..V.9;_.M.3.....w.........WS.......T.V.&.
K.m.I....6.mL:.jG......c.}..I...E.0.L..&.J.........Q=...]..=..'..'.I._
...Z...~...s .?}.0..mfG.Zi8...s..V%..7...e../...9...n...9..{...q5._!..
.Qd..$)..O...?.8mtb4I....5...,....a...9..j*..WzYO.....1N..........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/vDwva6A67JGbzpy7VPkWvdbtMgYd7qMQ8rFwR2vbEUA=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 3151
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 10:20:43 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54907:4:3136..........Qb...Qb...T1C.~.\.o.v......]B.#/....8.,.s..Q.V
......g.Vn..3...]N......e.....R4..b......Z..m........t.../...48.Z.&R..
....~j..\..)....Yf...i..4,....#.1A.......e.m.HF.....L.Pw...H=1...f.f..
U...../...P..T.l,[email protected]..?M............_....j.q.)'F....
....p7#.c...w...."......nr;.R.g............".....uw%..........'A....9.
.(~.[A...../.A..2..(...W...b.M*.dlr8..h. ...oF`......9.<...*...RF."
S...!.[..$..D..,....0.... ^..u.kG._..X.Op....Q...V..OC.....;J..!......
.....<...Y./.z ..w..H..d........K..>>.I..L....s.b..yy..d.th..
........i../.. .0.T.....M.....{...m..f_...C...7.......tx:.~...g......(
.Tj.k.a.......3.lAFv.<n>.y.EzFc....2.,....b...B...*.oM....N.Y..p
....i.)m...NK...E.%5=E...dX5.w...K...E.Z.....W..8.T.q.&..q.......Y .F.
#..E.NtC.PG....c5/9O......o)..G.....J....m...w...5h.R.$.1....b.R.#]...
....I... 2"}.;..pH......-...r ..z[...7O$..M].........7.W.^}7[...j).N..
......7.b.{.s.%A.. ...E../.i...n0P..d,[email protected][vR2s.._`mK.S...
...Q_.|..9...4y.<.......i._..R...9..i..^.c....n.xC.8.|..4..W.pK.T..
J.....`..m...."}.8.#M........`..R3...V.;.r)..aE.^...^.y.....O...A,b..Q
.j......t...z$..F.Mn.X$...,....Qd.-._W.%..5..mxq.../P....w2i.|D.T.lB.#
..!. .....5;.%.`...Zq..E...;.2.. &..b....aD.h.VLB...`.j...b...%".,u..0
1.../...S..C.d.z..u....Z..........(I..!yq>..&vP...vP...o6.. ?n....Q
....Q.ue...ue..L....L..5.p..5.p.R..R.R..R..X....X.6oW..6oW....U....Us.
...s.....L{...L{...H....H .k........:.....&.5....E..,.e..N....E{r...r.
J..4.hu............_Cev...."_n.[.....:(a..../...!...dE.>.....x.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/jNaFSriOZfpnZyKuKOMt15IDydkN0sT32zGXqNfHpk0=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 259
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:56 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54906:4:245....z<...GD..)....Ty?R.k....(P.....|.....(C....S.Q5Y].
.h....Y(N...(9).....f..$....].....w...C..5..J.....=.x.z^......m'....S.
.Dw......7.g...B6.`...l......!qbt=0..e~..H.YJ...iCK.u.......p-.H..HC..
.....|..tyJ...|J\..T....E!..k..9..W@..).V.S..q3...U.....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/u_hXwLRpsoJeSOsazeFzQYvUWnjbcqzfxK5xvSHfm3c=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:07 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54905:4:1025....z.{I..Uq.fN....G>...'.X.Dzm{..D9^..B7... ........
........j.....X....-...MM?...H.....%...kK...e...L.G.v..j...j'.....qz._
.`.cALe..-..,ZAex.GN..)......E;HU.#........feE.{y...V@n.....|Zl..\.^h.
VV.q].K...D.....k..r..|....&...M"..*>.......CZ...........H.x......%
%#...9'..t....D...>=2........."..&...........!..8...-...L...k[.....
No.mtl..E. .tI...................F....`...$S....X..........B.,.......g
xmq....{....1m...>U. [email protected]...=. ..q...`../!..}..
..}:.zM.Y.<'m.X.{.|..,.....r. .......6.Q ...k..Q.QW....<w.......
....S..>.."...a 5..D...R.L.. ...N....N...Q..%D......xl$E.0wq.*w(p..
...qI..._...5..D....o%..u.WU^...6...o..\SI..Q#..D..;..CBm..........<
;,...=.....S...h.O.L..?...(9....t9....N......_2.g..y....b..r....F.....
.......o.v.}N7.......q..j..)&p%.L.E.nS.Kc..9._.q{][email protected].
.."ZW.>6.....L..6.q'|..kC....i.:AGP.8V._..;...D..B.M =k..X.3....2Q$
.......q..........X.yRU...?...Z:!SJ....1..j...$.pz.x...Y....8.....P.5.
..~.w.........Pu...9......\;.`G../.Ax.1..r...%.&.O.j..U.......r.bc...g
K\@..PE.Vp...u.S.....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/AFGjLCcPvpsG1HUPtkI98qT8qJteSviPkekn-QzuSyE=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 1621
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:03 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54904:4:1606..h;_.j.<..Vn0.^..wlM.w...I{..SD.......X.t..V|h.6..J.
j...UR;....>..].%....).....L...,..'......r..S.d.....jcS.r.pI"..m...
FU....Q..l...3..!.......[.m ....\..g.(Ih..J...Dy.T.C.. .....u. .......
...M...q...-. ...4...(U.B...x..6.]. ....L..N..5..t../...E/...lV.......
...;.2. ..1.]f.^...m*..}.|23X.X.4 ....FI=.../..........&P ...l^.wB..&.
.8.\2_...09.6......c.K1.2.`u.gv.:..z..cBE.:.ys......_.......o........e
....\_k..y...6..&..a...qS..pno..........pb#%x...F.......".a{.iL.z..TB.
..#..kx..t.da...^}......p5n.\...ImE.......d...c{..w.>....*{G.......
^%,...[..G.j,......AI.0t.E.z..Zh.......q7.......z..G.mC......IV...nvJ.
....&.>.R...k.V.Fj.t..O..Yfg..k...6$ )..s%S.e. .9.]:{*L...O..Sx.Ae.
j.7..&p.QK......b..A@u..>[email protected]..[99 .i..l.....*"C...".... J..I.
.....6XI.. ..5.o.u.i.8..`.#..{.a........]mD..cR.e.....*.b...6.'...e...
S)%...6.ki?....<...Y.....dZr.e_..x.6.....'V.........<...........
Nf...0.u2$..,)....!e........&......6Z}.=..M.......9......53. .....Xb.]
.3..|...H..uM..X_.!t.[. .p..a..__...qv..%......00.\v.....d..4..u......
.N...|..l..'...r.....w{ .$.......Cg.8......]..o..SC..\...V...3{.....?r
m..pjqGW.....I.\.....a..1......0$H...\.al....'.....}..F9....{...4.[.U.
![.a.9....hf..q..Ix...Y.r.q._.....<?...K/.E..w..q..:.. .../...I}}..
?EO..l.7K...?..........;5.......uN......C..A....G... ........vyq.....4
..I..ca3=.o..v...mg.........!.4*-NY!_X.r.nm.....R.D..>.W..r.`.2.#.2
.........#...?.o..../.......h...m..bh_Q~(.H...Z....tyrJ.F..ed.m.j.V.}.
J(..B.....t..J........-%@[email protected]%...e0...&k?.....H.J...)..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/cnGzzgLWGwIcOtVgK2IvD7uAdng1hM9iLWbSHDXzFZ0=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:06 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54903:4:2050..h;_......Y..8...)...k.".rCNXu..4.GO\.N.>$Y/zi...>
;..]...D.,.$...,.Ie.w......`......|_$...........Q.J.mu.........y.7.H..
.W...p..S.}....k.nZ.x....qn..dY..\....1....].......#a#g.......... 0.6.
\....w..$..i.........Y...iURM...m...3....-.h......!h.'..j.hL...c.cFo..
..c......!.....P.'.....k1[...f.M'.Se..Sg.[.1Uk.f..MY.x.......d..A..,XG
1o.....kD..:Cf...........E=..Y.G.{.^i...../?.l.C..RzE^.6...b.....HosIw
.t,|y1./.q.....c..;B..}...O..rb\4^..G.w.<.C.g......d.{p:y.T.;.M}4..
N_5.=.........".a......e...&..^....>.....z...x..xO#.L.....&.v5.....
"C ."..^.Da......a..]l.......=%<..MHDv.uhb.."X....mvpf(.G.H[..)....
.=n.>.....et..8".....w......w...tr.....wCy.c.m...H.Tk.>t..~...9.
.*.p }.E......yW.]....6...-;[email protected] .`L"[email protected]/.;.N.o..J
t.5....W*..f..#.W......6........,..B....1X)In..H..=,).a...Q......<.
.-.'.x..... ..AH(.PL....f.....kY[.^..P....VV..V.ip.o...A..d.X....O..M{
.T..h..Xg..s%....Q0..0.!.....}.U...I. A..d..~..@,r....n.w.. ..8....HBT
...s.3).....t]......z(..q.f.f..0`M<.......u..o}}...WR...(._..;.vX..
\7r...,.D..."#.(....z.........*C..'elU.|..y[...r...Wd.........].....g#
(.....".I..o..`X..^a..'..^...(B.9..Z...........x..........ge6/@.:6....
[email protected]....<kI/q.....5...R.?<...,^..`V(...7.!.
..^.cp..n.Q.M...m...HB.\...>...].2.wU.....]E........c..5X8.....K...
.C.m..V.....r9U/..^..E...ws]..i.Z._......&..y...{.G.k...!....Ic..s. .r
m"....h.b.KS..E.)....;4Z..s3.tV.JS.....7...~..w......Z...C&h..G..#....
. kY0..x..-oD..i....C....Ao.Q........../@.bZ...x.9.#..-.I1..g.).~.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/cjyIJrK5F9M1n9xrACpzp-cw6OzC-MNqeGjrqaNgpCY=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54902:4:2050..h;_....3..0}.~.........hu...b....R.4xT>.qL.....6.\.
v..!..v[....-?T.ul...L.q....LjG..4..mrJ.gd...3..#n.......xN9..-w....#
.$;......L......V'kZA..rra..v;[email protected]...
Q.......\X.1V...V........-............T......[tx$...6E.....T....u...e.
z..Hz....t.{.....3...wA....[k..s.Z.....v(...%'....X....`';..hYu. ..>
;@.M.\[email protected]..=.8..gJN..@E.......[..
......d..n...C..7....F....&c.S..#....:.J87D]..cXm.q[...G...:.9.i..%;Ek
...5..."Q...A..1.....f!3...i....,.=V..{*..)y%.}\.D.....r......T....*&l
t;_...W.`.Mu..*/..x>.Q.P...?..J....!.l(.2KmF..-.q...%T{{%cw.v`....&
lt;.3~u.a:)..S./SO........hIJj.\H.S..$Q.;2L..:.m.(..a.XF9R.<..'~..1
.o.&..o....|...:o.....c...>..d\.........87..z.}[email protected].
j..E....[G..U..SY.&(P mU/R..XL{H.^..b...,.........t...".Qu;.~...IS;<
;c.......|..."-..>.4..g`i.U....OH^...O..cSt...[...L....`.....|..5..
.x.L.....j.0.).O..~KT.....E......k..O8".T.....k..$S.m..Ic?.}..q....T..
F.N~=n.Z|.H.e..v.U....j.mR.?"..W?...ya^hu..SS...J..y...p.,...-J/..`.y.
.,c....H&. ..2*.....z.E...<.n.......~...:I....^..1.w..RO.%..Qy.N..&
gt;h.9.?1..7....$..?.FJu.d..B..H.G%..'b2.M9...C....70...Lp.l..........
{..0Yh...t.......a..Oy.....Qv.tIn.g...(..w.$...a.....o.........G.....M
(.......E....(.qbM.....d...J.^.'.`..3s.].IIk.....{.H.nV.h/....*..9n.2.
...z..l|.6....g..i..s.{...US......h....MI@"..o.......b...YX....hG.....
.u.......0........D#q....Q.g.A.}.......gx.".F..V32....w.'....Y~..#....
*.;.b..[i.F._l....%].@6%..f.Y.H....3.,......Q.X4.43I.c6t.'..E...5.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/LUPMCPyJrbw1OieLTkZuI4-fa9veuo2URB_xdN46leQ=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:00 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54901:4:2050..h;_.M..6c.k\......z.@K<T.....ZT.e....;.8..J....."..
.(.>....q.,Z.... [email protected]?x.T.t...6 d...^.....q.
;U.....-.=..L...c....)./......i..V/.a0GuHq..............Xv.,o....>.
.<\..8.../[email protected]..:..`...zr.8.t..\...D.%a.
Y5w{[email protected]|...?z.u.=..Im9....'p..s)8./.n....wv.z...]..`.....E
!.B'iG.-.l;...r./...D.&466*....J.P.l.*.?P-.3...A..j..u}..j........I...
C..lTCM.Tj....ZH..f.......O.c.tu37.I...7.<g/...f?....n...j .7...E..
....y..kHG....Y....&4...zyIP..Fi...TMht.....-...03.A.5W./..J...*.....O
F..H....g.T.Z..8O...3L....U6.?y.....#..R..v.r/h......J.]a...bsO....PB.
. ..>[email protected].......^.w........F......b9....4...CZ.....2.!.
.2.].6JbbT`;.qM..Mz..:[email protected]......\.aF*:.3m.....vu5s.)..J
..=.......O-.l.! (..."..H.".|.....n..vl......O).)oZ..*...`>4.XO.C..
....%.B.B...T.._..s9.....;.4uh...l5..c...G.i..\..|...?K.o^J=.sDr....d.
m..b....yPH`. ).3.C.~..S.q...4...5 (1..D.r........y.8A.[.S.B...4...s..
;4._f;N.$3[f..[4..h.Q3..Du...?.Be..R.OUG.....?.........y........;...d.
...i....m.....z......n.."...*d...u......*..{.D.m.t._....P..C..g.\TM.=.
e0.$~%.P.B.........'..:I%RB..`E....v1?...9m_.p.....9.Y..N7..>w Z..j
.]...AV.. k.L..k..\..{.......N..=.Y5...D...O......B...&......#...D...|
.aeb7.X#@...rw.V...KA;..}| .Ve..kk3.^%.j.\1.^.t..y..8.ra.%..|S..A4...e
....-O.z;?..)......~....<...$..N.6.8.?.O>...^t.X.....%r......q..
w.......'...|_..>H.g....*.2E..v........p2D.u.. F..../....C.....[".-
$0.2..,...y!J.Hb.t.....cw....x..P......o].f..... ..S-x..0q..}.3BsZ<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/hK7NEVX0GuFHKMVPJRS41fUCr-UYuBOz0-nU7cXArDc=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:49 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54900:4:2050..h;_...H [email protected]..,iN.Y ...Z..k.....-'I.r..n.......j
....5B.U.{F....0m6..q...Q...R;..IC.i`...S.OnMg.M.......M..o..w.D&..zYs
...._[~...2.7.pD.....T.RH*.9?@.%...f..#.M\..n....Q~].W..A.>."q.Ra^.
...Tr,.z......g.o....ea..J....sN.....d>...1.H...........bK...6.H.~.
[.H(.|.,WTK\yio.....uT..p...h..#."n.q$..h.B..t..5#-.Y..M........)6.1}.
....B...Y...."{.9.[..'.5..x.h.0..X.`..f..m......f2.}......i:..IU...d..
z..."..q1...6..R..1.5.E.y..r1.X<u.......[....1.......6..(..e....v..
.....F..E.K8.]bN...k..Tt.b....H.U...&T...K.0.g.}i.?L..j|....L<7....
.\...6.(.|F..;:2."fC...P&....M..'.....R.o..)....E....p.CL....M..oL6l..
8.....m....~6D[.\......;N.J..`...l...q..y.R.}...(...uL.S[..k..oz......
.T.........\.}.v.....H__I...8y$...6.m.Qg.P.3..y...IQ...<.8%d.....m.
.i.F=..I..{f -\..sA..4U0AA.7...0QK.zv....$...Q.A[.@.]......f7.M.......
.....3<.)...`.....7QP..W=x...R..6....5....`....tmT...'5.."....^B...
|...4.......sd.W..O..=SUKHP.5......hP.J..08.Q..._?......3..m.%....U...
At_n.i...Y.3..*.C..H.6.....?.......r..d...-,@.De..p[$....Q...N0..I.. .
...........z.......M...s"/.N.V.....z.t.X..fc'F..W*T{\|...9....R.m`...h
Tv3.cM.<.......D.mA...`>[email protected] n.....#.......q)......q...R
.I.u...m#...k........D.gc..F..9...J..zG.Z.*..c.G.1.1...G..*i.V..J...{.
.vF....>.tBz.f.u.k....g..[..`..s..!,Q*..E.*q......#d.n.cY .!"d.....
......H..I:Rn....L....._%)F...kV....b...X.....p.....E.....j..|.y.. .7.
_..EvY..G.....(-yW%m....<.sG ....n....1....\.e..O(.f....G9. ...r.03
.............5.j......|{.....D.y......]s`G....3..1EAo='......!..U.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/M_uIHnItKjxLGZ6Y6sA3mLX9k8jkxrLA4WFXXMB8GPM=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:59 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54899:4:2050..h;_.y .......t.m.R.w..].^..Dx....s9....KR...ut.Z.L...a
U..:......l......|..}..1N...a.....o.....v.....kEo5[...I..C\.]n.'m....,
.|9.|....1....6.UO.w...Ok.T.[....."@.?z..,.au.QL...|....I..^".P.y.q..S
N....N.....|ty?ZC.j.w....J.xZ~......v..4A\<.v..`.L..H=......e../UMi
U...}=.*X`0....N.Yf......=.G.ZC..~8o.!......:<.........pv.".PId..\o
J.......*....3(EE|Z...O...pU....!K...#.b-....t.......Cendy9I.....$.c..
; g=..G.y.Z..=.!...b=#.......L.......]4.w....|O.0.e..(.NkV.:]^.j.M1s.e
.$0......b......G...2gkV....Ot/..)................,.......S.G.'mh.P...
s"V.9.,...c.L..p....=...q.D ...|H...W........2qRZ.^.S(.......H.a.....1
.#)....t...4..&..._E;T...p/...5 ......u.<..}Z....t..8.(....oE..B1n9
...*.a.....t..^#.5..KX..O....^}.2=a..8.u..x.D.s%..IG. 8...X....=,9.W..
H1..........!4...l.T.1;_.2...... ..".Hn...5....-.YL..............:.;..
....e|....l.........y...%.[.....'.$...........q.....k*...r.......8q0t.
o.. ........Y^.....b%_..v4gJ.#..T0..xdn...)02.T;2..5P..ky.>.b.e(...
..t...t..F...}M...........k'.J.xFB..x........<...iu...q..<.(G..O
FcpS.~=,...z.D..Y.m....".|[email protected]...!f..?L4rO..R.`..
.......5......a.e...r%Aq.J..$(..Ru!..X..7..j.u;K9....R..2.^.\._F.%y.Nj
.M.o.p..?K..v.d.=.BU.....^$..%X.........-...e....v.I...P<N.X...PA..
..Id..p.kG...Rj..."....q.T.p\..V..O..$.y...7V...,........:E.c.3b.S_.eM
.T..E..y..O..G.S.<Yl..h.N.(.6....7....>.q.A%..f~.*.a..`.. ....;=
q..`." .....n5,A. ....SA>F...'....q. x,SQxv.ta...X.g..H..........H.
.,>[email protected].`..eM4...5YGg..J.E?}]....#..*..f.d.y........vc.e...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/FFVlibTAzjsLur4NAXQOZA6peE6IVXVI3LCXkKUctgU=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54898:4:2050..h;_....*........8.}...1...gB.Q...[......x{T^.*.qp..*r|
V_......J.1...F....L.....5.../......2.S6....J3..,p.....C..I6T...`b.|X.
..I.c.scLB...*..Y.....''.70..;..D...L.x..\Z..... p.....A....bi ...RKB/
e........u."F.pd..g.c%...[.. [email protected]..%..........u...........H
...$U...A.'.^%..6j..Z...U....q....{(.*mv..........jJ2....../..6..u.i}!
F.r.......c....."JiD\....X!'w....}.-.......F.k..=.&...../.RAB..g. .Jm.
..$2...Z.I......>.....|[email protected]').".qV."..BB(. .X.-Y.
...[..S..i.~...;..e--..v\%..4E....\..8?.....kJt;....$,[email protected]....
.8..z...<{..../....../..r..<......3.....!..zUw7..1.4.u..r.x:]...
...L.l|..iS.....C.........(bX..@G._.p..j.Y..e.q.Q.Iz.h.P......a.u.o..7
h)N..Ey.q...3r....a&..%...G..C.>....nJ.r(.zD...9.C..p...9M.....I...
.M........^....B...X0.c.t..3$....N.I.... ..}[email protected].;.-y....?.v
iF.ff.....9dZ....9 _....>.g.([email protected]*(`.
}..X`.....-....*....B).u...W...j8.qX....w...L3.]\h...Qw.^p.Oh}](......
.!...:#..T..&....k.gd..s.m<N.....G..g.Cn]w....#Q3..B...`f.Ow.L...%s
C.....=....z...K..3Z.....!..5.P....|...dy....K.sW<..>9.....^gs)p
>.... C)VA.R.A..i...(e.nGi...f3.p..jXl.........MS.^..J..9.&_.{j4^$.
[email protected].]&DF..c...3..u..I..D@\.'..lh#.-_..........b...\"]...m..E.
=.Z}W..].y......3..2.v......%...<..o..h..>..F..={.'.....E0......
...ko/.UI....S.q.,....$2...2.RZ.T3.4gI..id.J.qr...>.>.1.\ ....W.
......[B.Y.%8G-"[email protected]..[.y...o..$5..`T....9)...0...%G..
...1:]X.._L.Y..c.q'.*....h=#u.....bg&S.\...:....p9.W.@.~..{.P.ac.L<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/MuNLeGrVYTt6Y1cOK2042BI3JSNbelnx-pT6Oqdi4yg=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:06 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54897:4:2050..h;_.tJ..xC..B..Y. .q...s....c)..&...F."...9.w,.......:
G......G..Q..=...^..~...Q.R..'..l. .h.C...[;|....'1.RRh:..2I.W...S.LoG
.N...`...[,R:.3=...f.O>.d.<...M93..1..x..~.{.%..L.y.Q5...:...22.
....7gT,..|..z.p.Y..I...n}I.........%b.d5..H4.N.{]....S[l..^....x.....
#..>.(..V.{9..\.:..e..r..sF.75?...q`T.V..M.....`...;^....i..U....U.
..d.......r..|l3eI.S...0..^]....1`c....y.-Y{z.2:...~.6..<.3..jm.p..
....i.%....9..:..a.^....M..0.4..'..4.5-..6.$....H.._{.......y..F.q..aZ
.$5w&q...(..6..._..".%...79..J...P.W........>{..o}=..L{MbA..vK.....
~pn,...~0.Ih.^OWXh...#.......3}...%......"..X..>.5.J...>.m...A.*
aq..ea8 ..j.T......x...30r.....il.H-.Xx.{.....,X........).?..0G.[.FR.?
........=vS...c.T..'=..[;.......|y.}R._.T..f.T..%M.:.u1o......G.......
...._?....i{O*..S...*R.........#)^V.C.........V..........-.8T*........
.s.........,.[..B\m..9.8J.......'.T([email protected]).k W..$..5....-."..U.....:.
..*.,.HE.t.B...n.q.R 3.....,..o.D...0..I(...'..'.#....^'.L.u!.{C...:h3
.H..|.C$....ME&.>.........POw...1.....l..:kW.8.b...j.w.?..-.^......
/^|.nE.N.?;......z...c.Q.Y....a>.....]A.'T...](..s3P.....|......!.|
W........;.kfq?...U..~..Wn...g.D..*.U`d....J.>.........z.u.........
].....V|-...Br.A..:.b....>.......a.9)..*.Y..>.\..jz;{L;.\,......
...t.&7t...I.E..q..:O.....T){Y..1.i.m.Pr;|.@..)K.pj@....'......$?....i
...O......Mr.8....l...V^7..7^L..u..................9p. .....2....wD@..
...P....Cj.(.v8j...0<..........F ........}.*...<.~GO.JN. .87...7
.U.....6...5.._.t....>..e47.k.#.5}..4N......S4...........Q=!=.e<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/hlE57wFE9-b39VNjineSxYXaPA_KVKlB2kHnmNHWNAY=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:07 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54896:4:2050..h;_.I,.H......3).)J>...._..4vVAA..8.....:....x..L.:
1gX.b....>*R.G....-.. .B..'Vb.`h.......u..b.d.%.O.V.)Z.......q.....
.b....... ...Y.XY.*..[...2..lN.Jt.....=...1.....j..f\....Fo(8.....-aS
]..S..;..[.........C...s|..s.. .m9."I_... Yn}...e.K..gX..T...^..t...}.
U..m. ..A..G.....V..... .D..#w.O?..............%ZC.........{Q&..J5..U.
..^ B2......`.G.G....W.YS.;....Y(A.V2.."...=...f.2.. .^/....,&.[.W....
.4%>..O5..E.8n......M....:....o>K.j.'9...xW.)1.K..?..c...[s..pfE
^GA.....h.....q......&.ks5W...ND...-....R|S......9.gj....!B......E)i./
...N..'........Q.LD%...<!.bV..e)#.z..L.Q..8..2 ..z..i.]9N. ......$.
.....:...)_{.V...G...Ggw...2[@.9..../jkiE.C.....d.id}=..>.GM.{<E
9.0.`Nf#4.....{....>m.{........^...%...D....A'..c...q...*...m.C.9Cd
_..w...._.........U...[...L...wQ.{9[....O.Q%v...DD.x..4....U!....@1Im8
...y..Yc.."......XL.'K...J.e.#2....Q...7c;V#.....I.....lx...)..dw.r/e#
)..A.@V.]....L..YB.._....."%.....5O..=9.7.p......oM[,[7.;Wj...?NJ..r.*
...IPl..g.....U.xJ....>v)$`ZV..CC c&.............o...d...]...%.Y.2.
.B)<-..t...|8=.c_...z..Fn.w....}7G.....E^8nf..,..J..E.U.).~U"..tF.r
B7|X.....e......".......`..j......S(%..(...L..........f..4..6.N.;J..bC
N. .g. .e"...8.k.K..wZ.........L.{.e|P..`}w.96R6..4O............*.2*.`
m....!....`%...iZ'kx.......y.`..(.. .V....V.........w..7..-..}k..R9;&}
.T.N.......-N...gC-....Q.9p;uH.a.P.15(.......cVPK..lQ..........#....q.
.G.V'8.Kv.G..6.p.......~.SY.$.x.}V....1........W...u....\.^.$x...9oy..
n.g..~..f.......HK...teoE?..S..V.=...I../C..].l..(qd.c.kl...j..en.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/LpJqp1zoQaivOKHY_YxfSfoQzXr8OBdeGyXfwZFuU88=.chunk HTTP/1.1
Host: cache-kiev07.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:07 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54895:4:2050..h;_..:.....;D...{.[Vy.55.9.W.........%.[NG.........BS.
.'....YX.#U ....?.(....?u*`..'u.z}._SwNG$2..j..|...Y......e..G..V....k
...D..*Z......*x....v....FL..r8AH........o| ...,r5.....r....).1|.I,X=6
.B.N.m..BB.8.....O..'....B.#..._...}Rf?.P.....~.YH?Q.[!.)[email protected]..
o...Lq.......Tm..0......f.8ur.*....`J~'....K^QH.}{....I.....`..9..]...
`......A..$Xj..z..h.y..m.0y.-o....J...H.b$h....x;....#9..8K....m......
X.../...V|..'.Q.-1..W....._E.F..........b.%h@.*V.....u.E.m.......ss..e
.sL1h.elI.B...q.7...o......5AEi....0...:..7#..c.M.'u.... .1.;...z.gH's
*....X....H..23.X.,j.=....).0.!w..4...-<..%3......L...Q.6.h.....#`.
.B.b.!x..4cT._..r.....d...>{.J.....?..n.Bq.Z1.T7.....M.=..x=.....yu
%.M...... . ..oU.%.....P=..B....I.......c.b.\...*.aO.y.8f..d..QG.<.
.......~>..}...A.ddi...S$......V....[h]kC......]........RsZu&..b.em
/z..j...L'.&:..i.J..Y...8...\K....!f.H\..n.Y..@...!...@ZN)..#._.-S7S..
be?..z!.(o..-s............G....I.XAa.W..Eya.5y....'..3....O...:.......
QY..-y...MBP-...E^..`/.J..a........F...z..Z..........O. ...........z..
.....z.P..)g..X..a..V.............F...n.q....#}5.....*=N5..
GET /chunks/goog-phish-shavar/lRSiPs_nDoWaue8Z9Qu4rVd7SFCZjV2jZ7ug0nBaMDc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/lRSiPs_nDoWaue8Z9Qu4rVd7SFCZjV2jZ7ug0nBaMDc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/skFus4cWDXN8GL8gnFtUdRf6nKmCCrZ4CR_AhQ0aau8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/skFus4cWDXN8GL8gnFtUdRf6nKmCCrZ4CR_AhQ0aau8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/mrShvsGmYWxwJ8bB2c4E3CxapAoOdyeN940T9aUr_4s=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/mrShvsGmYWxwJ8bB2c4E3CxapAoOdyeN940T9aUr_4s=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/QfkQ0yWr_4I0G1WQBVqa2lZJgzDfK_gsq3C_w3N4JYw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/QfkQ0yWr_4I0G1WQBVqa2lZJgzDfK_gsq3C_w3N4JYw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/xxhx3h0IzWuRG-tiUmGAPmqcSkzL7CgGn2_WLc4XndI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/xxhx3h0IzWuRG-tiUmGAPmqcSkzL7CgGn2_WLc4XndI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/qrBdq_vzXiEdm9iLCIY8GNMEvsBCJGveNQ3YWTzJMIM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/qrBdq_vzXiEdm9iLCIY8GNMEvsBCJGveNQ3YWTzJMIM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /PlayFreeBrowser/GUID HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/octet-stream
Content-Length: 647
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-287"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytes// Copyright (c) 2012 The Chromium Authors. All rights reserved..// Us
e of this source code is governed by a BSD-style license that can be./
/ found in the LICENSE file...#include "chrome/installer/mini_installe
r/appid.h"..namespace google_update {.const wchar_t kAppGuid[] = L"{2F
0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}";.const wchar_t kChromeAppHostAppG
uid[] =. L"{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}";.const wchar_t k
ChromeFrameAppGuid[] = L"{8BA986DA-5100-405E-AA35-86F34A02ACBF}";.cons
t wchar_t kMultiInstallAppGuid[] =. L"{E91D0BB9-0D56-46e5-BEC7-F01D
89F9CF3F}";.const wchar_t kSxSAppGuid[] = L"{4ea16ac7-fd5a-47c3-875b-d
bf4a2008c20}";.}...
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9+WQCtWAQU1A1lP3q9NMb+R+dMDcC98t4Vq3ECECVRccvD8Qb29B4D63fPT+k= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.thawte.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1396
content-transfer-encoding: binary
Cache-Control: max-age=459540, public, no-transform, must-revalidate
Last-Modified: Wed, 29 Apr 2015 12:00:11 GMT
Expires: Wed, 6 May 2015 12:00:11 GMT
Date: Fri, 01 May 2015 04:22:54 GMT
Connection: keep-alive0..p......i0..e.. .....0.....V0..R0......Qw.}`[email protected]
9120011Z0s0q0I0... ........l....r.vdv0..*.~Y..X....e?z.4..G.L.......q.
.%Qq.........w.O.....20150429120011Z....20150506120011Z0...*.H........
.....kHK.....f.(..D.....6...^.2..-.mc.y.....\H./.....%...t./f.s.U.x.D.
..&.<...i\[email protected].^..N...t.4Z....^,H.......5..:........,.A...S.
.v]j../.Y].......0....b..,a...P....ND.}.......".bkK2..<Db~.E.y.....
.LUO.\...p./..i...#5.-.M.z..d=.CBP.t....u...:.<SN3..4..4.....0...0.
..0..y.......^..........N...)0...*.H........0J1.0...U....US1.0...U....
Thawte, Inc.1$0"..U....Thawte Code Signing CA - G20...150303000000Z..1
50601235959Z0Y1.0...U....US1.0...U....Thawte, Inc.1301..U...*Thawte Co
de Signing CA - G2 OCSP Responder0.."0...*.H.............0............
).Z.......O.~.l...,\.3.".'.'W .ih./..}OA...K...HJd....K^..<.....-.r
WJ.j.U.._......W.../.6....J.y.u-.\...2..U.52B.>...=F...RbR.y.zm....
...{b.bj....Y..J..m...*=.^......V.}p......rmA......9.L ...{?.g.-Y.....
.......8...k.$.:.5..6#4..F.#....t.B.8.O)'F.p).........d0b0...U....0.0.
..U.%..0... .......0...U........0... .....0......0"..U....0...0.1.0...
U....TGV-B-32450...*.H..............C.....8.Aw.{....`...y1N...W4M..M.J
.3~..7#}..X..:x..5....$...Z^%.?6..e...}I.)....... .A.w......_...B..j.T
..Yu.o.....g....H....q.Ju.SA`K.....~..O_.....S....I>..O.X..E.......
]...y..L..F....K......../...._XSk6.:a};.?`...:^.....p....4Z.3L;.......
t....>.....j....<<< skipped >>>
GET /chunks/goog-phish-shavar/uZzH4jIf69GyNCTmL-lfy3mVpENyN_3F1IKOAXBxQwU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/uZzH4jIf69GyNCTmL-lfy3mVpENyN_3F1IKOAXBxQwU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/qnZ2HvzM37H8A8rLm-gJ0ujA5quc_OP3jtgBUBXCJmk=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qnZ2HvzM37H8A8rLm-gJ0ujA5quc_OP3jtgBUBXCJmk=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/iCqahQe97Rfv1mK1qV4HwQWuWFOF-fi0Z1SEHfHqiDo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/iCqahQe97Rfv1mK1qV4HwQWuWFOF-fi0Z1SEHfHqiDo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/qZC_0gz5QY5TFOHvTQ0KoWe5B3G87JxkyA8cg5HkIiM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qZC_0gz5QY5TFOHvTQ0KoWe5B3G87JxkyA8cg5HkIiM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/BN_fefG7YqPXI2wavBHdY_Gcg-YkjI4hH8Z1sED-s8s=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/BN_fefG7YqPXI2wavBHdY_Gcg-YkjI4hH8Z1sED-s8s=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /search/lib/ptwidget-1.0.js HTTP/1.1
Host: imagecdn.infospace.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Content-Type: application/x-javascript
Content-Length: 10095
Connection: keep-alive
Date: Mon, 27 Apr 2015 03:42:13 GMT
Last-Modified: Wed, 15 May 2013 01:45:12 GMT
ETag: "42c5e3520b26e6d37007f3d8b40e008b"
Accept-Ranges: bytes
Server: AmazonS3
Age: 1865
X-Cache: Hit from cloudfront
Via: 1.1 73a3bce79e63d88b3a25c9ced0be16f5.cloudfront.net (CloudFront)
X-Amz-Cf-Id: SKtJv090EqrudpeaZmnionIl0sAbRtonv-1cpMWtuvE2Giqvc0fCKw==function loadScriptTag(fullUrl) {.. // Build a script Id with a tim
estamp and a random number...var scriptId = "JscriptId" (new Date())
.getTime() Math.floor(Math.random()*11);......var scriptObj = docume
nt.createElement("script");...scriptObj.setAttribute("type", "text/jav
ascript");...scriptObj.setAttribute("charset", "utf-8");...scriptObj.s
etAttribute("src", fullUrl "&reqID=" scriptId);...scriptObj.setAtt
ribute("id", scriptId);......document.getElementsByTagName("head").ite
m(0).appendChild(scriptObj);...}.. ..function removeScriptTagById(id)
{.. var jScriptTag = document.getElementById(id);.. jScriptTag.p
arentNode.removeChild(jScriptTag);..} .. ..function ISuggest()..{...//
RFCID for search suggest...var _RFCID = '114';......//original RFCID..
.var _originalRFCID = null;......//holds reference to RFCID element...
var _rfcidElements = null;......//holds the xmlHttpRequest object...va
r _requestClient = null;......//holds reference to textbox for which s
uggestions are requested...var _trackingElement = null;......//text bo
x which has current focus...var _activeElement = null;......//the quer
y which was last requested and being displayed...var _activeQuery = ne
w function(){....this.query = null;....this.response = null;...};.....
.//time to wait before creating request....var _timeoutPeriod = 500;..
....//index of current selected suggestion...var _currentSelection = -
1;......//selected suggestion...var _selectedValue = null;......//refe
rence to div used for display...var _suggestionsPanel = null;.....<<< skipped >>>
GET /chunks/goog-phish-shavar/1b7cTbKmHzzFa39lmYqZ5pm-PEkHzxCUXSEXIQ5m-0U=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/1b7cTbKmHzzFa39lmYqZ5pm-PEkHzxCUXSEXIQ5m-0U=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/hlE57wFE9-b39VNjineSxYXaPA_KVKlB2kHnmNHWNAY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/hlE57wFE9-b39VNjineSxYXaPA_KVKlB2kHnmNHWNAY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/QDOtk_76wVL3jPoaZs27-7533knjsMtnCdangZmx1Wo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/QDOtk_76wVL3jPoaZs27-7533knjsMtnCdangZmx1Wo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/IBkAcJkDe-UMa5JcZSHqewm1J1FPxuue9BBrv2HkV2M=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/IBkAcJkDe-UMa5JcZSHqewm1J1FPxuue9BBrv2HkV2M=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/gGlRwSx8Dzo1uJ0yLqn9uPHpLoXJEVWw4QTefK6Bsn0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/gGlRwSx8Dzo1uJ0yLqn9uPHpLoXJEVWw4QTefK6Bsn0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /PlayFreeBrowser/setup.exe HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/octet-stream
Content-Length: 1663784
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-196328"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytesMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......f/.B"N.."N..
"N....L.!N..9.J..N..9.~.!O..M8..!N...9h. N...9j.#N.."N..pO...9m.?N..9.
..wO..9.N.#N.."NC.#N..9.I.#N..Rich"N..........PE..L.....UR............
.....h........................@.................................@.....
@..................................N.......0...............J..(....0..
............................. .......*[email protected]..@.....
...............text....g.......h.................. ..`.rdata..........
.....l..............@[email protected][email protected]..
....... [email protected].......|..............
@[email protected][email protected]..........................
......................................................................
......................................................................
......................................................................
.............................................A...u....N........S.V....
t.V........P.....j.j.j.j.j..3.........U...E..V......N.t.V.w........^].
................j.j.j.j.j.......U...E..U.....E.QRP........].....U..QV.
[email protected]..^..].......U..QVW..j..M...t...G...t....
s.H.G..w........M.#...t.._..^..]........R...........U..QW.9..t;j..M...
t...G...t....s.H.G.V.w......M.....t..#.t.....j.....^_..]......U..V..V.
...R...y......E..t.V.>........^].........A..H..Q..D....R.P....R...y
..Y.....x..r..........A$.8.t..I4....3...................x..r......<<< skipped >>>
GET /chunks/goog-phish-shavar/S7ivwxHcennvSEQHDpfGAO5hLoKWJSnvokyqYRJyLx4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/S7ivwxHcennvSEQHDpfGAO5hLoKWJSnvokyqYRJyLx4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/Ze8uEZAqHBtd2fK7UD2v7hiXbNOJV9Huo6Wkh5s7vRw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Ze8uEZAqHBtd2fK7UD2v7hiXbNOJV9Huo6Wkh5s7vRw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/lrktrb3ULzYGcvSXgGL-wk_R08q3_A7yVtdfyRyz1IA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/lrktrb3ULzYGcvSXgGL-wk_R08q3_A7yVtdfyRyz1IA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Tue, 14 Apr 2015 05:02:07 GMT
Accept-Ranges: bytes
ETag: "2711f7277076d01:0"
Server: Microsoft-IIS/8.5
VTag: 279782516600000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 554
Cache-Control: max-age=900
Date: Fri, 01 May 2015 04:22:52 GMT
Connection: keep-alive0..&0......0...*.H........0y1.0...U....US1.0...U....Washington1.0...U.
...Redmond1.0...U....Microsoft Corporation1#0!..U....Microsoft Code Si
gning PCA..150413163223Z..150713045223Z.a0_0...U.#..0..........X..7.3.
..L...0... .....7.........0...U......Z0... .....7......150712164223Z0.
..*.H.............WK....e.\.-.n......./......."]..E!.. //=...[....w...
..........#...[.l.J..f|..... .s......w...J._.......3.[..#.z....ko.I..
Q{....e.nV......F..d}..rF\H.jlH]dQ.E....x......W............j....&L. 2
.$.?...X?.#.(.....pK.v.......y..r....t......=.AW......K.G.gJD.b...
GET /chunks/goog-malware-shavar/lDCWU4HFh7141Gk4nPtxKfqUBMi3DgioCNmziSQFSAY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/lDCWU4HFh7141Gk4nPtxKfqUBMi3DgioCNmziSQFSAY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/bY38XvWYcXsoQZ0FlaGOCgqYBcsM8Kjb72fvP8txRBY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/bY38XvWYcXsoQZ0FlaGOCgqYBcsM8Kjb72fvP8txRBY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/e05WcOZMZtbisUzbwMUQfS06o1PHFsMK1SygyXrIjls=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/e05WcOZMZtbisUzbwMUQfS06o1PHFsMK1SygyXrIjls=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/Ly1fy95I4zNghg2731CfD358KsWzHvU85o0EXH2g6OQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Ly1fy95I4zNghg2731CfD358KsWzHvU85o0EXH2g6OQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/Jftr8wgkwo56H9yX6nJePhy2DKlA48l3kn4aJ2EZ6DY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Jftr8wgkwo56H9yX6nJePhy2DKlA48l3kn4aJ2EZ6DY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/lDMYCTCxctZtPK8ktsRW5E2Vn2pRjEfv7ILwgql5UKY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/lDMYCTCxctZtPK8ktsRW5E2Vn2pRjEfv7ILwgql5UKY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/47t5dK4QAJ1BiKhFGh-dfr0-SMJdePVognk64vffMd4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/47t5dK4QAJ1BiKhFGh-dfr0-SMJdePVognk64vffMd4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/KLnyMTj-WDDYVL1nZ8HROsuR0XViDZpknDqSt3f8tZ0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/KLnyMTj-WDDYVL1nZ8HROsuR0XViDZpknDqSt3f8tZ0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/Zc1p-chDcLtgTXbOPHgnX7g_F5Vddk2CGPFY7CZXFkA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Zc1p-chDcLtgTXbOPHgnX7g_F5Vddk2CGPFY7CZXFkA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/S68JNpsZmJZq6F4upq2Bd2Dw4N2MAoSZ_bdHW_x4e2g=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/S68JNpsZmJZq6F4upq2Bd2Dw4N2MAoSZ_bdHW_x4e2g=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/0eYbR7AY1kV5MF7bqScyKku40te-z1-r0eu-Er90fgM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/0eYbR7AY1kV5MF7bqScyKku40te-z1-r0eu-Er90fgM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/GgQ4WSYwIL2jgsYgnfOjR0qqfePaXmb-DX3XOtsW9Zc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/GgQ4WSYwIL2jgsYgnfOjR0qqfePaXmb-DX3XOtsW9Zc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/0CUhV4Pw6226fhXk7ayz0zEcPuXwbi30h1RwoGHxmII=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/0CUhV4Pw6226fhXk7ayz0zEcPuXwbi30h1RwoGHxmII=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/V9yxb_-jWRKub_r_OycXW1yI82vShiVrr6LGvZYg2PI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/V9yxb_-jWRKub_r_OycXW1yI82vShiVrr6LGvZYg2PI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/2GIB_v116SbEk07Zs-UKwNZth2eBtM7lJtrdsWr_ITI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/2GIB_v116SbEk07Zs-UKwNZth2eBtM7lJtrdsWr_ITI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/TehQ2ixiUtxEpr0ycrxRN_kCJgW6Bhwks3x4Q93OUW8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/TehQ2ixiUtxEpr0ycrxRN_kCJgW6Bhwks3x4Q93OUW8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/QE5wpfxYC4_ZkRiYpgWBMaPIipoEvJ2MAg3pKTv6kqE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/QE5wpfxYC4_ZkRiYpgWBMaPIipoEvJ2MAg3pKTv6kqE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/E34UBcOsmTNnqLeVWPOaryM0WWvyZOIzlDl7WR6cc80=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/E34UBcOsmTNnqLeVWPOaryM0WWvyZOIzlDl7WR6cc80=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /en/gameinfo/?game=farm_frenzy&browser=gs_en HTTP/1.1
User-Agent: Game installer
Host: publishers.playfree.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:02 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.38
Cache-Control: max-age=3600
Expires: Fri, 01 May 2015 05:18:02 GMT
Cache-Control: must-revalidate
Cache-Control: stale-if-error=14400b9..{"id":"468","name":"Farm Frenzy","last_id":"468","icon":"http:\/\/
mpcstatic.com\/gn\/468\/farm-frenzy_71x71.jpg","description":"Make as
much profit with your amazing farm as possible!"}..0..HTTP/1.1 200 OK.
.Server: nginx/1.7.10..Date: Fri, 01 May 2015 04:18:02 GMT..Content-Ty
pe: application/json..Transfer-Encoding: chunked..Connection: keep-ali
ve..X-Powered-By: PHP/5.4.38..Cache-Control: max-age=3600..Expires: Fr
i, 01 May 2015 05:18:02 GMT..Cache-Control: must-revalidate..Cache-Con
trol: stale-if-error=14400..b9..{"id":"468","name":"Farm Frenzy","last
_id":"468","icon":"http:\/\/mpcstatic.com\/gn\/468\/farm-frenzy_71x71.
jpg","description":"Make as much profit with your amazing farm as poss
ible!"}..0......
GET /en/gameinfo/?game=farm_frenzy&browser=gs_en HTTP/1.1
User-Agent: Game installer
Host: publishers.playfree.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:08 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.38
Cache-Control: max-age=3600
Expires: Fri, 01 May 2015 05:18:08 GMT
Cache-Control: must-revalidate
Cache-Control: stale-if-error=14400b9..{"id":"468","name":"Farm Frenzy","last_id":"468","icon":"http:\/\/
mpcstatic.com\/gn\/468\/farm-frenzy_71x71.jpg","description":"Make as
much profit with your amazing farm as possible!"}..0..HTTP/1.1 200 OK.
.Server: nginx/1.7.10..Date: Fri, 01 May 2015 04:18:08 GMT..Content-Ty
pe: application/json..Transfer-Encoding: chunked..Connection: keep-ali
ve..X-Powered-By: PHP/5.4.38..Cache-Control: max-age=3600..Expires: Fr
i, 01 May 2015 05:18:08 GMT..Cache-Control: must-revalidate..Cache-Con
trol: stale-if-error=14400..b9..{"id":"468","name":"Farm Frenzy","last
_id":"468","icon":"http:\/\/mpcstatic.com\/gn\/468\/farm-frenzy_71x71.
jpg","description":"Make as much profit with your amazing farm as poss
ible!"}..0..
GET /chunks/goog-phish-shavar/fhv1pKXYMHqded8rPqy-jx4dzaITAE7VPyaCqcXmEPI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/fhv1pKXYMHqded8rPqy-jx4dzaITAE7VPyaCqcXmEPI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/haIwPWO7cofJKKFQxp4j9ZcAT3JtguG88lgbYRgGl0s=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/haIwPWO7cofJKKFQxp4j9ZcAT3JtguG88lgbYRgGl0s=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/5WSYaQ7LOD-v3GjZ6dJngOy3mUXWCdUykyYS_adogHo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/5WSYaQ7LOD-v3GjZ6dJngOy3mUXWCdUykyYS_adogHo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/bP9cwuh_axs0J-Nbuo42kmwnhgt4rWNfe0gHrOFh0Mk=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/bP9cwuh_axs0J-Nbuo42kmwnhgt4rWNfe0gHrOFh0Mk=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/lF47Sh_HLEdUNiXpguEQ9zZeeyjhHFGZNZVIF3fgnXw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/lF47Sh_HLEdUNiXpguEQ9zZeeyjhHFGZNZVIF3fgnXw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/rJ5UiZfVNVY8I6QwHOGKfYO7eACujpZZ8S63AXGO_sU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/rJ5UiZfVNVY8I6QwHOGKfYO7eACujpZZ8S63AXGO_sU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/ULvy5kahSMHS-3gFwUXe6fqhBgBfxAEImQvAcX_9780=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/ULvy5kahSMHS-3gFwUXe6fqhBgBfxAEImQvAcX_9780=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /en/gametabinstall3.html?game=farm_frenzy HTTP/1.1
Host: VVV.playfree.org
Connection: keep-alive
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: image/x-icon
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.38
Content-disposition: attachment; filename='favicon.ico'
Game-LPG: farm_frenzy-lp_en
Game-Info-Url: hXXp://VVV.playfree.org/store_bundle/en/gameinfo3.php?lgp=farm_frenzy&browser=lp_en47e.............. .h.......(....... ..... ............................
......................................................................
..............\.....z...|.........n...................................
2.........b.......n...t.............J.......................7....b7..A
...c@......_7...mN....... .............................3...8...7...{r.
...........,...............l........$.......q]H..J...8...9............
.........%........................ukkk.mmm..........~.................
...................}.....dee...i..|...{8..yV..........................
...uG..6...qX......{.}...Q..........[.................................
.,...iY.........}..].......:...3.................................MB...
q....................:..............................}..iZ..C..........
...........I...H.................hg..//......"!..9#..}e...............
......1..W...R.........jh............../'..dU.....Q...................
....1..|.A1..%!......mh..........nm.....I.............................
......V.....z...~.........j...........................................
............................................A...A...A...A...A...A...A.
..A...A...A...A...A...A...A...A...A..0......<<< skipped >>>
GET /store_bundle/en/gameinfo3.php?lgp=farm_frenzy&browser=lp_en HTTP/1.1
Host: VVV.playfree.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.382bb..{"Id":"468","IconUri":"http:\/\/mpcstatic.com\/gn\/128x128\/468_1
28x128.png","Name":"Farm Frenzy","Folder":"PlayFree.org\\Farm Frenzy",
"Executable":"Farm Frenzy.exe","LGP":"farm_frenzy","XXX":"farmfrenzy",
"Description":"Get mad about farming and start your first business now
!","Icon200x200":"","Icon170x128":"","SetupUri":"http:\/\/files.playfr
ee.org\/gametab\/farm_frenzy-lp_en.zip","Site":"lp_en","play_url":"htt
p:\/\/games.playfree.org\/en\/play.html?utm_source=lp_en&utm_medium=ne
wtab","website_url":"http:\/\/games.playfree.org\/en\/?utm_source=lp_e
n&utm_medium=gamebutton","game_play_url":"http:\/\/games.playfree.org\
/en\/play\/?utm_source=lp_en&utm_medium=farm_frenzy","target_region":"
en"}..0..HTTP/1.1 200 OK..Server: nginx/1.7.10..Date: Fri, 01 May 2015
04:18:23 GMT..Content-Type: text/html; charset=utf-8..Transfer-Encodi
ng: chunked..Connection: keep-alive..X-Powered-By: PHP/5.4.38..2bb..{"
Id":"468","IconUri":"http:\/\/mpcstatic.com\/gn\/128x128\/468_128x128.
png","Name":"Farm Frenzy","Folder":"PlayFree.org\\Farm Frenzy","Execut
able":"Farm Frenzy.exe","LGP":"farm_frenzy","XXX":"farmfrenzy","Descri
ption":"Get mad about farming and start your first business now!","Ico
n200x200":"","Icon170x128":"","SetupUri":"http:\/\/files.playfree.org\
/gametab\/farm_frenzy-lp_en.zip","Site":"lp_en","play_url":"http:\/\/g
ames.playfree.org\/en\/play.html?utm_source=lp_en&utm_medium=newtab","
website_url":"http:\/\/games.playfree.org\/en\/?utm_source=lp_en&utm_m
edium=gamebutton","game_play_url":"http:\/\/games.playfree.org\/en<<< skipped >>>
GET /favicon.ico HTTP/1.1
Host: VVV.playfree.org
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmt=1; __utma=120822935.470092875.1430453906.1430453906.1430453906.1; __utmb=120822935.1.10.1430453906; __utmc=120822935; __utmz=120822935.1430453906.1.1.utmcsr=gs_en|utmccn=(not set)|utmcmd=hp
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:26 GMT
Content-Type: image/x-icon
Content-Length: 1150
Last-Modified: Mon, 14 May 2012 12:39:14 GMT
Connection: keep-alive
ETag: "4fb0fcf2-47e"
Accept-Ranges: bytes............ .h.......(....... ..... .................................
......................................................................
.........\.....z...|.........n...................................2....
.....b.......n...t.............J.......................7....b7..A...c@
......_7...mN....... .............................3...8...7...{r......
......,...............l........$.......q]H..J...8...9.................
....%........................ukkk.mmm..........~......................
..............}.....dee...i..|...{8..yV.............................uG
..6...qX......{.}...Q..........[..................................,...
iY.........}..].......:...3.................................MB...q....
................:..............................}..iZ..C...............
......I...H.................hg..//......"!..9#..}e....................
.1..W...R.........jh............../'..dU.....Q.......................1
..|.A1..%!......mh..........nm.....I..................................
.V.....z...~.........j................................................
.......................................A...A...A...A...A...A...A...A..
.A...A...A...A...A...A...A...A....
GET /chunks/goog-malware-shavar/hK7NEVX0GuFHKMVPJRS41fUCr-UYuBOz0-nU7cXArDc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/hK7NEVX0GuFHKMVPJRS41fUCr-UYuBOz0-nU7cXArDc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/KyMR5Wziz02ixCTmA22bQKsv6wHxPwj9kjtJ_lLVou4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/KyMR5Wziz02ixCTmA22bQKsv6wHxPwj9kjtJ_lLVou4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/J52fEe2QVgYIVr0w6hxf-y0ETI71vjR26TUJdnGrq8Q=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/J52fEe2QVgYIVr0w6hxf-y0ETI71vjR26TUJdnGrq8Q=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/-anZCDFwCsiDfCOfxIKUAJrW0FZfXw4lV2mDR_XwEwU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/-anZCDFwCsiDfCOfxIKUAJrW0FZfXw4lV2mDR_XwEwU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/fUN4SJ-LG6yrIjmJB2RL0iC2b3UdNzVs5BMan6CE2JQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/fUN4SJ-LG6yrIjmJB2RL0iC2b3UdNzVs5BMan6CE2JQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/wEXpqs63b7RAaV1YPIGl6QqBL-E4S-69bDQwGU7vRBk=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wEXpqs63b7RAaV1YPIGl6QqBL-E4S-69bDQwGU7vRBk=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 24 Mar 2015 05:02:25 GMT
If-None-Match: "a1132b8ef65d01:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 304 Not Modified
Content-Type: application/pkix-crl
Last-Modified: Tue, 24 Mar 2015 05:02:25 GMT
ETag: "a1132b8ef65d01:0"
Cache-Control: max-age=900
Date: Fri, 01 May 2015 04:22:41 GMT
Connection: keep-aliveHTTP/1.1 304 Not Modified..Content-Type: application/pkix-crl..Last-Mo
dified: Tue, 24 Mar 2015 05:02:25 GMT..ETag: "a1132b8ef65d01:0"..Cache
-Control: max-age=900..Date: Fri, 01 May 2015 04:22:41 GMT..Connection
: keep-alive..
GET /chunks/goog-malware-shavar/684__O4vQZnuf-5-LkTjdfmz6aY3sfpIgE5Jb8qUdsU=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/684__O4vQZnuf-5-LkTjdfmz6aY3sfpIgE5Jb8qUdsU=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /gametab/farm_frenzy-lp_en.zip HTTP/1.1
Host: files.playfree.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 02:55:43 GMT
Content-Type: application/zip
Content-Length: 17924988
Last-Modified: Thu, 21 Aug 2014 14:02:18 GMT
Connection: keep-alive
ETag: "53f5fbea-111837c"
Expires: Fri, 01 May 2015 03:55:43 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytesPK.........".E................farm_frenzy-lp_en/PK.........".E........
........farm_frenzy-lp_en/Data/PK.........%.;5.E..8..'h.. ...farm_fren
zy-lp_en/Data/data.packt.Sl-...w{k........S.>..m..m......m.W..H.L..
..z..Yk.|...........9..Q0.kQ.....#..U........8.xyD....Jp...?T2@.......
.I.........?%./.2....w.-}.T8t.:.:2...d.6...l.....L.Q.?.:x...9...~E?...
I5).JE.hU...-*.S{. .Ku....N.....5.bC..LC...*.s...k.Us. .g..;....6..>
;.......bg...sv.....>...M..v\..q$...y.@>..._h.........:.=.....bm
t....).'....V.7Yq....X......w..|... ....5r.U...`.,C.e{..z..Z.g;...Z..K
.......~....>...p....L.....yI..>......=.J.N.N..N.nft.4r. Fp.....
U......x...b.. 4.....i. ..y...........`Bm.i....F.|.x<`......)m.l.d6
S....vi..............qRpN..e..f... .D..Ck..^.....sM..B...SP.V...i....z
.....&6..-.Y.D4.S.vX.K..9.F.^h-...sv..=.Z5.......T...-`..?y..kq.k ....
.Kb.j.`..........H.$...~..(.-d.76v.N.*.L....ld...m..~...".mn.H......-.
`....t@..~.z.....qv......}Y..9... ..R...H...X..(m...y)i...=..-.OY._rev
z.:6.Nlref..V..............z.QmE...Q_.......BV...k..x.!.......4.9.a^.I
$.0`...(f`.S.....".zQ.....}.....n.{..t...F........6.........{K.V... .
....m.6..5..........&\..F:[email protected]@Y2...=ZHHW.......9'm..~.2[..f:....
>.P.....x......0...T..o.2..5?..N.. .......DL.P..(...C..ae.8..6IaVl`
|K,.....t.p..l.N...v..vv...y..xr....C....@.\.`W....Q.4..C1.8..0.... .[
..1N.z......Bj](.hl....O..:...{[Z.bn.,3A.../H.f.u.`......A.J?..i8..d..
.R....Z..7...t.7y.On.!..}(Q./.aXo...H..x|=.Ni#.u.....L...%...`.......{
....*=J...<..../8.cB-..=.M.....H..F7.....nJ..........Y.c{A*5N.&<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/U8XthtUjP3fHyhoWlkwxuCvAK1rcLrnp4IlOMe4QvKA=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:55 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54894:4:2050..h;_.K..|{...'..S. ...&...1'.qR0W(.>.z. ..........-.
......[^.}..L. ).r..6.t.......<..]D..L.T...S'J......T..:.D.....S.^.
.e....R....K".o..S....`.U..@'.Ho.........G.^j.v)I_4..;.e.U ..x.yY..pET
.....k4..\D.'.6..F..E...X...;EtP.......m.l....i...>....2t.'.8..G.6.
.eZ...:.5r.U....'.(?3.X.[r..2....B.......a.`#Q...j.m......... X~.O..cX
.,;%.8...}.GEY.s...c.t.$...|...*.....a...hR...1.{))...A..%......w...6Y
,=1.0.R....P.HS...}..]40..82.g{.h.D..DS.Hf...W...*.".).T.d...Y.....M..
|2...N..O.5#...../ .....>..O...J.T....x.x.....g...v.:.^'..vh....f.}
x.....s.!..a...f.......-<BC.x6.\.u..;...vo..~.........W.A2.V..T..rM
..f..2..?......V&s.....T....3..7F.ox...-03W|...).k?=9.#.v!..:(.....S..
..Z$M..tw...(x..$.`@."...&.h.....9x.......%...2S>...O.B..._..{....R
p....!....9.C..H....k1..W...L.IK!..^.o.b?....c.X,*6...n3.R...E.....b.;
..#p....."m..8....... v......7 =...</./..$TX.......:.....Bx.D.Fp.E
v..j.%..|.S.|.....e.....4...T^w.m.,...#.r.2.[.......N..1.(&e.e=Us8_,..
. M*."...4.!...C....:.04.Z.o....(..#EP.L..?X ~Z.=E.....>..Up43.....
Y.].?...D...Gg...z.....Bfh.V...6[S.5F...h.;.......b...=."1x.....~.,...
.; f.i.. .C...2:&.O.pna)...D^./M.PC.. .CL"5...1..$.G].%...&b..=w....)#
.".6z.&.....S....L..Y...|v......t:.*C..|A..I.w...._.u..2....>iVS...
.....$....j$.(.]Q..{ .qc..,......A.Z:.A@>..J].6#..<p.1D]H...1R.v
.I..iN...u....A.u.Q<v....Tb.......'_........3..ZH.!.[~..Y....^.C.&g
t;.@l..(.........7.....N......|ad.5.l........V.[2..bU...8$...O..Z.$FI)
.D..x...M..n|.]...I..[j.Z..bk.^0C-.....wO~.c......K....m.....yf.(.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/F0fpy84reqUnQmBQSuHR2vNOoa14FpI-dzipR4EF1LQ=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:04 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54893:4:2050..h;_......].....xC.....?Y..y..J.(r....... 0...2.....&..
.1..;s.rs.C..Z.DQ,..a..... .bXa(...kn..E.=.....M.(........o..BFc.n[&W.
q....<..J.....G...........$cs8..z....c..I......aj.x..N.....{..w..F.
.)V..6S..y.w4..>[email protected].,rN..c......5p..t../..
...f...n..N..........|.p... .2....NY. .0......;.~o..WG{!.....j...lxr..
.\[email protected]\.....=.$a...x.)).X.|........
...a....\...Z..0.c.Mpf.U:.4.&.b....Ba.o....r......6.5q.h&.Z3....Y...D.
...N.g.RX.I(gquT/.....8zH6GER..S..-...//.:......YN2:........5....:.b.(
.............%..:D..}..v.?.?.1Nt.......qv:..*=.H....R..rl5.m..-I...8L.
7..U.H..>U...xd8...$.Ow..]q.....`.t......q.F.-......z.......Y.v..2c
....]X8..y..g>.....e5..........~.....C.u..*N..l.@....%..:)s}.. .^..
.......7.....l .~.Q.a.l..;.".$4.RA..........'.L.........# ];.5)..4vB..
[email protected]@E5....m..._...l.4...C..d....Y...L_...,....
9.......$..>y.@*....)( M.Z...f...*...........Y.&.[....L..i..o.^}...
[...p..q......<H.....C.m.-.....C./.f(^.yU.g}.n... M.].x9r.-H..r0..o
X..;.......z...YL*...).B DZub..g/S.....D......8......l0...g_..mQ{.R,U.
..MZ;.@{.JH.:[email protected]...,...\9.X2......d..I!._Q....k.J-.&~....\[email protected]$..
._..7....4..L2uw...T.9W}.T.....'.".S..%..z..fQ[.......U.....dgV.wh.E..
...-&v...V9.............j..0..._.Q.ei........X.G~..S..1.M.,.<..b...
%...x..vHM... R.2..kJ...p...|...........\$...y#..V.......'w..R..<U(
........'x.t}.}.z./....7...G...!V....b[B%.....:.$...a}u.Q...2..B..j.hb
.z?`.%.K..h.D....G.. :s....py..r...W..$......9,....}Ba.....-..N...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/J52fEe2QVgYIVr0w6hxf-y0ETI71vjR26TUJdnGrq8Q=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:47 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54892:4:2050..h;_...Y.fU....r. .9..."..;Gq.m..|..a... x.o...".R[..i?
..v..v........O.|....~%....".7R/..H.Y5.>..O.........s.).....Z..f.@
..t...|.....G]d.z-.),..~.......3...-.H.c...4......6..UI.)I.d...}U..|-.
G..IL.V.Om..!.....!.S..`-.;.._.f...E..=U.....;. ..>...o.. 4J...9...
WZ...2..N_.!..4.*E..i........~m.w.3..(WL.~..].b.v..%..}.M...Ua.x.z.3..
..O.h..f)}i....M.DT..Y...v7j.....O..7.] ...pY.....][email protected]?.;F.C..L
a.d..N.Ig{_..W..G!....D.....Z"..\..'.fK*..Uw.<_#Hr.1......_a.....H.
..W ....H..... .....\A....J.o..9.m.zzu.".V...I1..O.nA..%..7.4.M_9....2
G...'......)Q.O....ib.GmI..}..H[[email protected].{B ...aN.i.=....X~..d....4
.. ..Jm..A.*.8..GZ..OC..[.......Q.....,...V..%\.P...v..9....%.C.-..3..
.>O=-4..;..N.....~R...v....(.E...,..h]=......V (.}...q..&.... ...}e
..:......Yzp..*...:[email protected].".....T~.\0d...HI.)...?=g.Fs.
.a&.>Cu\......)..J....E3A..W.. F.2.A.^..;......s..Z...l.q5..n..l...
.?......l1g...6S....e..g.A.~...#.t.K.dchNu.Z.}'9..7.`...:w..U..t....@.
Bu.B1(.H"2..s...F...... ..}.i....]......}96V.;.......Q....V.J..P.....w
[email protected][....}^[email protected];r...agjO..
....o.!..l.[....H.....O.......F.../..O7..H.......t3.E....L?....k.zL...
...6.>.g.(..J..QwH.. .......e.A..t)|( ...0tV.?Br.."?..r..Qc.d.....X
..?...:.........kUY..3..7......PE.......}........'...Y.'b.6.._..tb,...
6.s:...%.!a.G.p.g.f..j:.....2.9.="~.......R~I.0"....z%&...,8.".;P..I..
.|p..w..3........2.....`0.r..t.....S9.....t.8618....X....c v....!<.
@....r..Y.>..dk?..z.~.......i.. ..u........7..9C...i.{vU.:...Q.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/zPBY_ZsUBv6JGy4o-VialmS3BxJzABATPHbco1wNs3g=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54891:4:2050..h;_.c2.WR......@ ..k......B..5.Td.....n.,5.N9.........
).......<......7B......'.(4......qh.e.*..`[..C..*8-.N...\..b..-...q
..m.#xW't...O.......>..U......>..*.c*.K.JYK.<..........Mn....
Q*.j.h....g.yQ.....}.HW..S.c...$.(.....Sk.r./cV.2<.O...O.ZO...._.F.
..h...3Un@./.....Cy......s..]>r$....J..86U.v.G.R....r........x..)..
x.#?..........{w.X......5...%v4.`9................;..Z..J....W0..}~..S
.Kz..v%...o.........,Q..vM...p[..\...t...)0-.cc1.x..1.`*..=..o..e?.]..
....R."..Zy.....}...Tk5..c.?4.EU..V..!.......g1X6...!{.{d.ZD..L.. `...
F.....4.Q0..j.j..j ._..$...Pt..J(.FiUf......o..?...Y...K4.......0...O.
6.~.A$.~W......=..*Rr.....X9.....GJTA2Alai..<."..m....;....#.....Y.
/J.Z..#"..3O3,.@7@.....]~H3..]9.......&.1e......,..G-.?..n^..g....}N0.
..".'.4?.?f...y...f/...eB!..F...x.7..-\FA.......\...j<T...`x.c...b.
.0.'P...`....C....0k.'NF..8L...v...=.r...oo;R..!a,..%.D*.H....C.P...i.
-. .......?;..y_.J.z.P.F p.zm.7X.........B..O..@......?.1.5.. ...,.L.n
....J.%.yK........|.k........j..~..?.=h%..A.U..`.h.dw$c.P.gO..y..z.j_.
...._dM&..6......z.O.V...kB..S.W..s.Z.....m...t...2D.n......n5j....]..
l}!...fg........".g/)..B.oa7...,[email protected].&..^..
...l.5.9...39.o...h..#.E..kP.7...0.V..96....Y...2'R.z.]..b....A...[`.=
..E.,......!....Y...$2...N....HR}.;*./..d..0.{..0.......-.>.....tj.
..4.aI..Z.v...Jt........r.-..H......U...p...8.KK.Vc..;....e...a1.....A
<>.......T"&=.N*...~....xte{..}.C.C.D.N.B..,q.$d..n.<y. .YG..
.].${...1....!).63..........ko.M.|b...8K.....l...<,..f._....a77<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/UDsJW951ls6hXgbEvhwDLWhn1cuoWuX5hKld43jlNko=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:06 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54890:4:2050..h;_..^I..13.eKn..C'G.Po.....2(..#|......3.v...t...@`I.
.f.HF..-.h._..d...X.=.k.?...g.{$3G.......na.}l......;...D._0WBx..S..I?
.H..t....M.!.J.b....x....e.....P<..Xb......D...6.U.L&...gh0. R.....
.1...<.....h.X... ..].....8.4.....$._..(:.l.*...Gl...I.R.......Z~".
.%.......U..1.......cm0z....D...@_...];S_xu4.C.G..........\m.W.sn.....
.x5.3jZ............i...`....BW.x.;./n3.[.!B3..9..-.;Y.*....../..|. H..
M1"..BH.S....x.%...jT.To...7O....B,.Z...#6-8l..&....FZN41.u... l.....r
~...Y.X.{.[%..?./[email protected]!J.Z..iJ....,f.|....7,.`...D.m...t......
X..>.3.d.......V........~...n.....t.L"...\.Qj.`k..0.......Dw....P..
..L..v..Qs..I.o.I....#.P<.}....t....)...:........."....Z..xR.g%....
.rJ....ra..2.z&R.*[email protected].....!
T."isJ..{.R.I..x"P0...M..,..*(.....`.._b...:..3....!..xk6 .....6.v`A.a
.....W..f.(......Un-...s.......Yh!.....F..I...3S.d...~...O.0.9.....z..
.#...r.}.N.....GO.....s..i.p....gqL.A....."a..j.<./.0V .^.....0)d5c
......51V.?. .&..#o...0...w}....5*.|.n...."h.X:..."N.8#....D\.<v[[h
......H....z..A..A.k.B"&..HOQ!=.b.$...B.yz.r.}-.......g3.R...c...6W.1c
K.sq..B*.!.c..G.%......L!...u._.~!9............YbqhI.N3....D#....t....
5..}....i8.....*.8..`'..&...m\....v....h...._.f.|K.W...A.x|..I|....y.P
[email protected]. ...f..[8.Z^{..v#=.b...{..6.3.:..
..:^.......{.D....c.r...... }.e.?.b..........~.I.B...7y'..H|q.........
N..j.$2..._.....A......m.., {a....(..#[email protected].`...Ð...$.x.S
.T.[.c........}.&Q.g.....o.ky.........C.} 2eC.......bq|4.h.g.e?3M<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/pqIY_e0O3hSWRoJAeaHMgDfMFzzIEueabEuZVNkuFCQ=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:58 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54889:4:2050..h;_...C.....`..-B..V.H.X..B/?.....*..0..L..MS]..T.R.`.
...fh..D2176 .L...y.j.PQ.Y!c.j|...fLH".|.3I......N.$Ne..$.X......X....
e..e...W.w......8....-...^.H"....f....FN..(9..w.....>.....[l...O...
'3=3.Pz;.tO.T9.IC...}.i..S..4A.......A.......E...=w.b.VU..xV..hm c...C
1.."..%..|.|E...D.. ..x..9....HA.....`..n_..E!..wj.........c....!#.YW.
..Jl.U..wGc@.........:&E.v(T^.....(.<"....T...{.7....*as.v.Q:...{..
y..V3?l..B...V..6.....CC..7..<.^...r.......z..fhPK.O ....~U,.....hi
..Pt|....q.A..!..2....G..i.RmK...L...D.... 9..1..H........?..CQ*.V....
...g.*c...."<.lN.".n.mB<......E.....#5..K.S...^[email protected][....).
...0....&|r...<g.s.Y.XX.C.F.R.d..w..l.7.....sXr.....V<dc..qMrPKn
.q..^..U.t4.K..!...6.......&.../{.r".^4...uQ.K.E....C5..P.......Ep.r*.
.p.H...a.o.]....I;[email protected]#..3......-).....(.....z.W?].WMaH..d}.gb
1Yy..Q~b........fe.p.fX.0--0....1t..$........,....{.A.F...lU.:.A..pzV.
..<..`J......H......)R.!...........^..z?Y..P......^o....,.....8...i
.D...N...x..R.ViA3!7.Y...H.jrD....'P..rQ.....Y'..1.V.........h$_.SX..
DU....]>...^[email protected]`.....D.......-.L....X..k.O,6....h.lP...
[email protected]..\.{.!s.]....>y....,.dB.r.._....4.h..U.*#..
....exd...ce..K...}I...7MZ.o..P'.L. ....".1v.wo..iDO.~.S.....?\...d.d*
...g...6......p.7.......X/`_.........({[email protected]|N..r.E....
....8.....w.._...."..6Y....F;bA8..'H..V... *.....>N.S..\r.........#
e9.......^:u.........`|!e.} .d..o..R..p.D.=..LZ.`.m.E.. P_!......=...S
...-yz........A.4..c......H.3h8......O5..r #.F....=....6|..L......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/lrktrb3ULzYGcvSXgGL-wk_R08q3_A7yVtdfyRyz1IA=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:48 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54888:4:2050..h;_..,.....B..^.9.3..u0n..3Gi..........K.....~!,...At&
gt;.wj.s.DDnL.$F....eC......:.3w.....q....-.....d...?..?j....z.......|
....>..vIPq.0\.%y3.cbMS_..o-...I...b.../i.Cf......B.F4...['.H<.
M.a=........."....zK...B5D#[email protected]'...p..M.6..01..h..".A.....
.....VP8`Dz.T.>../ .J...u&L....$3..K......L.N....W.....Wab._Y...WY.
..zm....rYA.-.....4..Y......%..w.IB[M..U...18w.....*.,...`B..v/..O..3.
[email protected].... T=VlM.F)..o.....]....J. ...F.4f.U.V..G..%..%W9
..<.....-.c...1/6.Q."D..J.....{.........9...........l.Z`..uY..I....
._.=.).........Oz..z.........6J.... u.{.,.N2@".1...q..._H|.i.-U.!$.No.
.x4..Vj.o~.......F;..%P....xX.....b........9.....i.....m^.l.....S~,.{2
..g.x.S.CW..*wf..A..........>h.HO.`b....[<.3.......8$..)J$.$@m..
I^Dn.....m=.C..C.Cz..#.X....xD.Qp..[~.M..`...z./......[.9O.....0......
..T....9\=f..(.F..o.....r..>........_.....[.}..d..%.........o.r...%
(.......\..\1Q.....=sW....KU{..7...'......-.6l0..x.46..I.....\..~.....
.....nV.b...0^.s..N.u.k.Z.........r.>.p.............(........)5F$.e
.... Qvs....a.*.I...z...=......'.........SC...pz.D..e..........J%...R.
.!0-.,.W...b..#2f...|L.=..^.....q 8K/.L.....M@.}l..&..g..,......fn?..!
.......sI..g.....7.|T.L...pJ...&.L(;........;....f..]..w..".._.01..Vl.
..F..][8_.6..oK...H.g....G........'D. .oC.$.1.......;#....e..A .U...h.
.....w..m.....n.4md=.......0...1....%{...s.x...Pi.$.K...*.......b."K..
k..1...z.........Jp......b.9......$.&..._^../P.1.O....^...$..b.$.i.5..
&u.J7/,.V..nW... ....C(........x..U....P....h.q..k8....k...\Y.2..=<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/684__O4vQZnuf-5-LkTjdfmz6aY3sfpIgE5Jb8qUdsU=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:58 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54887:4:2050..h;_.o.6.........C... .Y..:..`k.............UT....x...!
[email protected]...?.\..?.6 i...#..U...6%.v...e.t......).~C.6..aG......*....
".h.z|.]...?w..F.egy..f!.{.._5......Pw?.>[email protected]..(L..c...N.
`.t~....Y...9_.R..CGpb.z......).V{\..'...O*. .......F..We..x|.1.......
./4....Y.8.......O8..cu..?,..@{..$z..x.],..QM._.rQ..x.....a.O......Q..
WiN...}....6..N.?..L..A..)[email protected]}...C...k......R.F3....C...........
.....>7(g..=....*...%d.g'b....ER*D=-...ATQ.3.G..?._.q..'.4.5.......
.j....Nx....*....vuNKI(.j..DH...*.0\;....U..J..... .}.....g....?......
j/a.......O.~....kA...<X.\,>~.Q....M.....[ke.o0.#...g&c.Z....VM.
.x<..\....b.=..Q$G...0..!..^.......R3./..3....M...88.....T.E.... H.
...XV.>V.1jZH...T..........}.x.W[Y.7.4....y.......d7J.aa.D. . ..sR.
.......V~..........l..8....f...i......;.....}m.k..=.t....XvM......Vc..
/q./..2........]..O....b...../.L../....'W.*.z.....N..N.~^Q..h..9 ..#H.
.,..Q.{....;.S....8p.aH.~..6P$J.h.]......9.x6.}Y.#R.?..=../.(......VlR
...M.8..e/z]....F^.Z....T......iF:x"._%hp4. ...V?..K=..=.aj8k.>.^3.
._.....2.i4...z...Z..5.}o@F.]...(.,..K.......{.,.Mv.O.Px.7..Z..."....z
..&........b.0o^.p.'.._.aEl....M...C...$9.....&..t)3..z-.&..G}.;.:.=.E
G..........D.qD.,....\..e...... .......57Ib...R....h....4~7...d...3.k.
..........H....Y........ ....Z..H.q....<.n..Y..ItOU.....s....WaF`".
..][email protected]. .m].....t....]
V..k.[ZT..Ef....%..^K..O.e..8........I......a..H8O(@V.u..n)..6\{..p..Y
xIr...;....:d.9....f.m.*.=\...:aH....7q:.|i..=...z.I...f....l..TR.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/tdaKepnAEP8GIBFsntEZotPvlWuEMLmm1oKs6ppIzjI=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:48 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54886:4:2050..h;_.^&k.....7".Gc...4u."i..vcj......d.....-.._.:V...P.
</..5.N..s8".mN.2_*...Z.C.}&7.d...x.7.;..t=*.....h...6..'%..<..Q
...&T]We.G`5# ..74..r.}.,.......m_&y\Oi../../u.f#g!....i.....]:!7|....
.~v.P....( .'.3.q.........yR.5.F-.'....FY5.P.UV;..I?R..i.h'pc[..u..gQ.
4..)..3..~.^.t9K..1..-.q.'..2......e...8...}..Ec....P|..C........'Z.Mh
.eq.....3[...q."......Q...2...U.lMJ..dh...U_.o[p....7........g1%.se^..
.t..(e.Y.R..........z. l.F...\..v......Z...B]....!...W(.............!.
.....z...Z..k...../.4..x..\.t.Me:.....J..<.idlF..e].'c..&1eL.#.d...
..T..$|...R.....g.|/.z...S.g..6.y...VA.o....F4O..{.....b..W.....$.M...
.........~c..dr..B.R.W.W.2P.F..... ......HD8..j.....X..`..h.pNkh .....
.....Sy5@...;..|Jt.P.,.....&......r[.I..[]dy.2.F)[email protected]..:.4X.]z.h.
.l.}1.u......n...{..`..C......yO..e=....*....4.....L...z}*$.7.xv./....
..[.i|z..3..ksM.N.GwX..|t.,;..J....'....8N.`..T...........T.W..s.r>
I.9..Q............8.!............B$.....:.C.w......Y....v.V....u.B..z.
.j.C.xi)......=..'w%...U....D....=....z..).D...9..j...WR.......]...~..
4....z.e...2uL)..N.f|.i..9.!...H..,...UXk......8`.....oA.1....L...v)/.
&...1.tk....Z=.#....4.[t.&^.n(..3.>Yc...}.BF.L......'.v5....;.c....
j.rC........!..aM>.............>.......^.4'dpfS.H..jm.....H7.ZN@
>..6.....a...C4K.T7...)}.vv(.'...........?O..f....@...<...W.tP..
....L..'RZ$..KP{I.#...B....h*....Q.m.....os6d.....(T. u.N|.N...`,E.f"C
O.<.`..s\ 9..p..9.~.{=.....w.T.....n....e...Ni.[.2....N>..`.. F.
...._.....v........k......_...Cdd../.w.@..(..Q@m6,....R&Y.>....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/ULvy5kahSMHS-3gFwUXe6fqhBgBfxAEImQvAcX_9780=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:59 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54885:4:2050..h;_..wT.x.I....N...m.>ECQ..?. {d>_C..0.3..6.....
Q....Q....{.........>v...1611.4.G..M8pW}.l.J..#..........2*...~....
V.{0...~...n.f....J9.8H #.K..........Y:.k..v.GX..}b..tH.Mn[.u..'..W~..
.\[email protected].@@...{..g$.......I..l...<.)..K.......F.b..
V.T...Z.F,d...z.....L"...{W....;........J...(.S..'m......d.Q.q...)...R
.......o.b..Z\q ..B...z%lPM....n.....w.i*S.QC'..X.....~.#........~H.}.
...y....>.b....[v81....V.....<y{..$^.v......(w.1-\[email protected]..:~.
..(.[[email protected]..|..S..............F...Y.*T./!}V.42.
-A....M....#[email protected]..<j.C.....WR.I...#..6..,..-3..d....
.H.T..In.U..{..B...Dh:8a..8.0h"..............c.8 ...`;."...,=...=.i.`
.......).7..<.u5,.W&.}....,nE..NJ.i..!...B...Y...a.. C9.....M)..p..
x..xO.*..}....8...e..(-......w^j...#G....C).KA8e...X4..C~Nu....h...v~.
....fdi..RI!.1x.[.B..Mr...-t....0.S,.l%..n..N.e=km.........Uk.H./...t.
.=...f<..d.LS.......8.%..Yxd......^....H8C0.vfb.&.}Ck.Nc.'......'..
...|b..)..~K..#...3....|.^{N..ye:...X..k.RC...owO....^eCVf......e.....
....)|..tD.c.L.8....z..l.e|.."}..K..G......H....3...Y"........3.".KA!\
.{.jRa.9.E....f..{.*i.C3.._.Gw.....".`..1........n.e...... /[W.{.pA0..
tCV.`.....R.(.s..M{H4.....k eZ..kT....D._U!.5..F.6.}..K.h.....GF8..<
;...I........\.'....;NZ,...tniK......Mv.t.J.x...J..q..I..1kNxE.. .R...
.........;X.I.q.}[email protected] ..........6y....L....).]|.[.J....b..
.....(.?...b...R^..f..a9o.......... ........ ...m....r.1i...|....S..40
.[..L.e...%!.4..F...*lb9.D....\.f....9..H|[email protected]~&l<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/t7wD0vKOutL6XFFHiHuakC8aXB6YVLa1sj730VndEqM=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:07 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54884:4:2050..h;_.n....g..G..........A...........e...*[email protected].
(1..!l..n..c..^.!T..B...[.:.G...Iwl=......-m..'..).2......e...S..`Qi..
.......j....X..Y...a|...\.;..t...B....J....I ..C....K%K.{..!".wG.~WJ;.
^..*.m..=.[.:....n5....WK.yr...K.>.....M...r.d..z.D.|b..4.|.5.R...&
.:.V..p......&. .C.y......;..".D.knO0......2VJ.....6A.^)d....(....j[I)
.@.=2...0Y.w.Hc......X..[..3..`..1...Ju.....&X*.......z..~...R..@O..:.
..s..BDB.H....[.......>....'....^..U..[!...^r.O.........{Pm...;.7.8
.f.....R.W7J}..0..%..Pw..k...!.....,fIS..&...'..W...T.-..'z;\1...#.m..
.'.~.c.8...jh.[...h...V5k:....:E*S*n...w.4...b.x.s.......j!...?Ju...{.
../.u.*.x..X3.x..B;?...:...qN.)....]H@=*v...j.8<.F.].(.g.[SNEUi./..
j.iTn ........D.n.........l?....Jc..*....NnT].X.p\..-.t.f.o....Fz...}.
]....G.K.CA.....!..[.K...D@.;..e^[email protected]...
[email protected]..#.>.5......=. [email protected]....
`.U..9..t'...i.*.t.W.....1M........|{]...L....|`P.......U;.D.....o.lm.
...z.......Y..._&...T..0..Gk'..j I..d"...}...sk......!...E0..D... . ..
.'...z...........A.g..I...t....x....ew.......y1....j...._2F...........
..q('...N4../.y2.$h..#.[.z.;.n.RQ.c.*.O9...YVu..B..t...e2...cX.[..V...
.]..&.6X........#.u}....sE.1.....TTZ.n1:....:.NS...j<P.he,...d.F8..
8.e.>1.F....:I...w.......#..M...O].].W.....k@.....*.J.4......d.....
...\......n.......o5..H^s.FN@.. /.j....[..."%%G?|0. .....'..j...5.C..0
....=...Lk..d.......z.=.xG*..IsDnhbJ..H.y.M...d.....'!..a_..Z.SF.D....
...m.Z....4..9y.=......zr........7..... .U......R...4.T,!D$d`J.vw.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/IJvxhg70GV20xTBQnxkJq9p6uz0Gge8MXTeEu5AhP78=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 2065
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54883:4:2050..h;_....{A'S...e...`..'y._")....H.q. .....;D......V...9
....I[.a..........kH...t.S.f,.G.K.%....."...A"..=..(..(...."v...P.o...
gO.`.y..)..3....=.*v~..{.....o.'-.:.L;<2...1......j..X.l. ..iWb....
:..Y.o...g..&.....a..=.7.-Okk.R})..WVOYrp.S........-........._..O.<
[email protected]'..l.u.......D.......7.......N}.8.6XW..S.3...).Y. ..\d......
.....].Ra........X.m....n.R......QI.j....b4m.......I.\....0...(eCs7...
..\.fW..m..}.=..k.=7..6-~...(JQ..(r..d..3...*..k._..%..?.L:*...7......
..y...... .......*t.=.x...%F..4.0..g....., ,..E..,...^...XV...R.....:.
(R..u..W.....v.g.O..>..W.O=.._....ZS....N..!E...p.}...W(>Z."th.R
.....L....|.%<.......C.B.>..x;..._....U%[email protected]?.W...............
..W.;.C.........Q.QAA..........{<..e.Hm.O..,....b'...O..1/...L...t.
.....K...kQ.Ze[.|,V....C....L1.....Gg...b...P}4..Vw...{...e..G.I0q...c
......G].uS..GS.D&l.[..G.O...a...K..O..U...g.kv]A..CW......5.~c. ..P.H
..F?.......e.........`.(.\....x.a...'<.e.fD..........U5/.|V7..x....
..J-.8UQ.&.J.r...F....P..T.sq6.....,?O..0.(.l..qTsI...k?iR..[...i.'...
......\.<D7......z.K............s.h...Q......b....0w....).\^0....t&
...=..0V..o..3d..n....\T.h...#Vh....3..0....U...z.._.....RX..)Y...bN.x
....h.r2h.hP...%.......8.U7.......?, ...........|..qN_.:.......a.....K
l.olb....<*=.m.......d..q.]._p.3Q[(.~.T.hx..gs5... .J[......HG@....
......;.Y.64.....L...h.a|.....4...W.N.....'z..\!.*wa>Yi4....V}.2W..
.m..Pl.aO..16-..Vv..~..........(...P..%.\...C.....#e.6..0...d.......XG
[email protected]..%.y.. .*@. h.d&l....~5..A.Ql=-....-..L.........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/9eJHkKBM28o-0xZBdcbLTRTKn5i6bdxKBD16b5XNtEg=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 5545
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:03 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54882:4:5530...Q.r.<8.F..W........2iO..h.&..)..."{....h...l..zM..
Ui.....;..i%3.K..d. .Y...*^ ..4=z&\..E<U.o... e..k..%.....O.;.....`
..X..}..Mk.i..bq....6.y.m...)...LV..A.8..,. ,....tP..T..g[.b.Q.?..)s..
.._.....V.3g..I.....=t.^k......dI..=.Lds..p.-..W..I.....W.(....N.v.\..
5:0.. w.....'1.L..].I...,... ..l.L......PAz......r.a.S.....TK....R....
.l..c;...~......uwX.}(.Wu.>...v;..rX<...A.G..-.w/d....z.i.1.(...
...B./:......8Q.......d........L... ....bp........(.......k.....1wp...
.z.......,n...1.........3i.hG....Y........a.8...CL.|....1..k2=......".
.s.;...Yq.........aU.4a.f...S..../$..1.XF..t..7..&E...la2..O.e.>.P.
.L.`.V..&n..r.....>ni..,.%......[.............9../......M.....I.=..
9..u..w..F...........4...5.!.C3".`_...H@.]c..t.......&..\.....n./m.8..
..U..W.U...3^6hE......Hby.v9<Q...e...)...,..M..B|...:&..$s...Q..P..
`..:.G...N....p}^..N..O1..r..9$...vn....V;..^.../d.6...2....B.........
.QH3E49.....}}|..L.t...,..H......`......../.1:.u%...OvD.khh....]....u.
......./....xJB.7-^p......p.%x......C.....(FM<.`..(...1....!h.P`Y.R
}...C.@.......... D..)$<?.2.S..n8Z..JOR*|.^....Nws..J....M.".L..2..
../f.."..oV.....I.P;u.Q..A...v.u.LJg... l?..w..n.......u.R;.3n..o8....
.`.....D..P.:\x^...._x,.g..S.a.}.Y.......CS.6..0.7b..Iz.~..[..\..fu..N
/4B..):.....N0|.aE|?.2D...fw.%s?Y.\-.u.;.y..B..\. .'l...Z5.h....$L.YO.
..k.....p.X.#RX.Ja..`.B.F.^zw.....Jt........$..eX..............F..~.8t
6...q/."./........dX.9......Q.g$..?q...s..&U..V#.}......EvE*.{.1!...(=
...C.0..l.......kO....by.O%.........A2......i`..<..6o......h;_.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/-zFjpKxKhsxytgDQNzMvJgyR8pvmFqwL1vXPvZg1oFo=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 14933
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:50 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54881:4:14917...Q......,78wy.x}...#...v......=y.p...be.e..V.v<...
...Y..K...c4r.......!......2....U..v..cBc...... .".]...w.|A...W{...._.
.`Y....}).Y..I2'........Vy..C......{..@d@=....}T..F"g;.S.k.".#.V&.i...
...e.....9.....> ...AWJ...V..>.0...... .....i.B..xO.U.....U.....
.........e~G_..T....*.8.)........G.{...n...|.o..R.S...<.M...C-.....
..3.&.h.h....*...Agy..A..b03.I......i.7.....1..h#..@$.)h...Z$.....Q(..
QK7. 1|....F#..YLh.E...g....p. ..,[email protected] K).J&..i.....L..o..A.^xG...&
p..d...~t~.&iG....m..0?r..O..<&.4..p./.k.......4...HG.'....xWk9/.[.
......y....&.......N3#.O..{AW.O.}.T.F.........s....%j....].9......pg.R
~`5....=..5^.#..'..z...H5y..!R....r......x....r..CR.h....%....K9.&. q.
i5.....[r..c..c.o.....7T.Q..,...,...V.$.....L7..^.....G ..u.j3...../.J
W1.j....@@./h].....Z..2........I#;2...m6!...r.....).H..4\).K.C=...s.I.
.b..8.5'f.ku...t ..!...i...FZ........9}f.8...h.Y.;.[y.g...5!..._.....Z
....\..Ek......Gri..,..Z.....$q....k....u.....Y....Ue...}..W.....7..l
....[.K.H..=.m^.E....oF._%p.J~.RqY8[...}...%[email protected].
..O.1n..O.......%........z....z0!....b..b0....=...m.(9.>a.A^..a.fB.
i.}..y.."1J.3C..-.%.7...'h.nAd9.=...J..Up.l...._.ly._ .....B.-F.V.5.L.
... [email protected]*5..g7.d.}.0y.......e...B....i.)MFZ-...)...3@......".Ab..M
.>.E.W.....2.......h|.....[......U\MCKn.Y....\.-....1r.J)..........
...j..............D3w._..n../....\o..z....&K.P....=.<!.......RI.n..
?....k.u.;..4...*(...=5./.._.......'...j.....4L......... b..[.v..V..5.
....cYP..P.j.ia#*......F..^..`...3.3.yv....)Z.......]....i..j.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/8NY5MEB8lUJJQjr0HAtADQtTEJjYvFsFmh9jeMOO_dI=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
t. ../..Q.\ d_BE..c0.f`.......k...<...,Q..c....".._.CC.K..B.:... .X
.!?.k3i.u.d...jt..d...x.2...k.L.Z..b_5.c..7.yz.....nI..Ru.....3....(U.
....fN=&...:....}.s2..h..'*..!._...`.......K1Y.....0.... &F.8...5%..s.
B.{?.-x......,.;.LY.Z.. ..Z")..>..<|.]J.cj.j.......R.I..uSG6.G..
........r..).z..&2.H.?rm..<q-...}Z..5;..b..G5i..DX. uV.......z....C
. [email protected]<....b..5.a...........Yr.-..3|
.....{..!...nl.:..(U........{.......\X.qC...K...].o..h.....5.3........
-{Z{.j.)NOF.-{.'.\hy....S.'.........<..kplx7......X.f..H.l.s.K.....
.:#..||.$J/.....N..>i.X.>.28X..m..~8......&Jf,9.....;1d..I.l.N..
..t.u.tA.;...:.....Y%.lM...Z.U...QUkG.,.!..G.<..k...X&..7..........
.........B.......$<..h....H]y..R.....O...pv..b].u|......K....r.'.%.
5l...F.1...........&.W...c9...$....F.2.... r:.s. .H..,..yN"..'.l..i..G
6D.L O......`...R=..Q.bzN...'...)...%0.O.O.Y.!yo.Z...|}..@...&.....ST]
[email protected].^}.LmpLA..z.. .Q.ws!..0.......;r............@
.Y....b.._.Tab,..q......>Q.....P..:.. ....Q.).tB.0j<S%..B......y
...4..Z.8.s.h_......Rt_.Z..W...jZ....G...)."$.OI...#....1.n.J.iiO....(
z)~....t.b..W..6fT....b...PF(L?H... ;...J.m.>Z..S..#..q.k.q'o.f.o..
.<.|R......}z........W.a4%....k%.%..."n....I..I....u.k.OI...{U.A...
.w...-.jo....3..I.....dH. .c........E.G....b=.....4E....`KCN.....`.7.\
......%zx..:b.cA.lK...w.6oU.......A.14.oWK(y......t...cf........2RE..
....v*[.M.e(....-.8..].x.!.wS..))(^........{.U..JY.>.8C....N....R..
xps. ...A.BR!N.6.^... .......R.......3.......T..(W.c.R.5#...V....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/pNLUb43N-OFdIP7mjo2tzPuDNjNF2ERBwUeIMlDCOF4=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 30362
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:49 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54879:4:30346...O.....)P..Qw9f.....1..7`.5>=...g3B-.}..........i.
.C.:..Mz.....Ij..E...]......M.lu,.T..o..........>....BB....K.\Y5|..
...}.e.Q[.D.|%[email protected] .........u.Ux......
C.X'..8..S....>."./..;P..1........R3.7.~..f|]1..bV.v..3.%omW.`.b..}
y...q...|zYM..........T..q.F}.o..8.c!..T.....;C[.|..m]..R.8..c...}....
.U....9.Y(..=.....2...9....w.7...zdl..Z.......9[.....i..LaI..it^{...ns
._.O.`.m....Z..=.wb<N.....X3`..w.=....u#'.(.2x.\My..jz.`..\0.d5'.o4
.X.B}B&./...`.. ........j..^.i.......b..O.c..r..cA...\..~.8R.V.7.7.Q2.
;....y..w..o....T..%....._O...S\2......K}....C..y.F..>.....N.RI.A..
{9......:.8\.n)lgV.H...VP...E..B4.bcN.......701..#Y...%..o.ku.D.d.?..f
iQ..7..HG...N;..%.].. e.pJ!.....X.....Y.WDg63....#.o...4.;.x...H.c.s r
..?........v.T`..>[email protected].../y..]..#..1.7HoX..6?......;.
...d...........3. .....V...9o.*TY.@...$u\.....5xLku..5.[s....6L`:$e)..
<o.R....&.0..9p...k.%....l...d.n%F...1.?.p.....[....ij..I..n.B.....
[email protected]..@..<...1...9^K.R...aS..]...]k...%......<..L..h-..l.
D4.x.......oG.....<......t....z.&Q..?....x._..........x .........4!
:....".R_.<[email protected].|...$.SH..iF.8....=...R'....\...Q..i..-..#.5.Sn
...K..!....#....\..k...3..J.[D..Oqii.."e.$.":.c..O/Y.B.....dh..K..0...
3....1.....0..e..8....j...)...[......,.k.0.r.A...-...l.?3~.?Z,yG......
..OBT.O...)....8..).p.e>.S..~>D.d..g...dy......qe.....1>.%...
a. ...j..#Cu{H...B ..................f.m..|.b}U.r^.....6.....x....d:..
.Z..c..;.......JK.'.......2 ?....|..............3...yw .....8.5...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/-UtvLBU64lZsXS6mufZK4XOCHgYcH3F3q8TmeiT9jS4=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 42713
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:30:55 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54878:4:42697...O...XR.C/..z.> 'm.2.....'.,@-..`.^..J......VK.).D
......q.}....bs...D.'[..Q.i......I.[.....JD..|.8p.qg|...v.U.....>..
........H.....u.f....v<...V....T...[W.d.^$.......x...Hz.F..}...3f.{
K).O.g......6...}.n...2vQ.}..~..^."..q.9....'I.......O..2..,~.. ..4.O.
.DS...N..{....6n.(.........{v.U<..]}.y2v-..j....q..L.R..V#w...oo..u
Fpn.. .......k.9...%`........H~l./.D...5p.q......|..t...|A.p....i..9..
|.....w....Ay......i.......v{.g.b.....^....1&<.....M......w..^W5..u
.x..L.j.,.....IP..>. ..l.Z..`.....MK.?.Y?|V.._../(M..r^lt=..\.u....
...5............v%;.V`...M.]q."..E.........2......w....:...'9\[email protected].
./b........#.....S....m..D.5@....;.....]..8...8....N..z&g..SkP.8....^.
hB5S.sb...].=........<....w#-..?....f.1s..^.......9...?...p...3P/5K
.@S,;ox.U.../..hI.f...G..q{54.h.[o....5....G....p..w... 9.B..U...Hl...
.#/....|.GN.PJ....g......|...8..8..r..4...P.2..tb.<"0d..~.K.V...x.5
..&.VaYp=mq..W..i....I.."...8`.k.P.0..J0.4.....{?;..?...:.-N..\DE{3...
.!....r.^9.>....I..^H...B]2.x../.#`,..{..-X..Q.W.d.A..C...#...K....
}.}../%.|H..M..%..<....v.. [email protected]"...E"...-.. ....ECj.CR.........s
5.S!.j..K.4.....E.1.p..7..w!....&.?...X...........YW..<....Km...'.n
.oqc..@...`{....Qr,.h.)rDZq7.1..gf(..X....D../....[.....9.............
`m..h.TVZd....P........c...C...z.....wJ.0F.sW..u..y<F..."\.........
....)...Fo.S.C.p.VQ.......h......x(Jk.Nl5...%.gW.....?...l.....3...`..
.........gl.{...w.).0.g[...M..".........%.c.xyF.)2e.:}6d..G..n.H......
Q.....h...c.m.!..Gr.?Ey...h....]..m.....<E......N....5...vt.g.I<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/fpYzgXlcgfr6ZD20Y8IItWMOIOC8C-p4aRguqTU9Ojc=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 50010
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 09:31:03 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54877:4:49994..e....e..s.1..s.1.......2;x..:.z.N..b.`z.4z.e..@.&-./0
[....x.R*...........M....M.s ...s ..k..........E.y1]{.......@.,...1u.d
..Z.r...A....b........P..J............f.k..'TNe..#...0......4^Pr..D...
{....R...f.>...S.6.l.g.y...,.....b...M.1>^..J..W'_......h.Q....L
...p.lF..9.. .>...t.B_..^....<2~...]X.t.Lq..[.w..%[email protected]<..`.
w!.O(..V..f.B....."...~n=....#...^9Q.vr.6......3.=.-_..vj.8...$...%0%(
(...~.i.....[.I...E.2%(w ~...A..{.. S.0\B[...6...e.%~.q.&.........d.UE
..{..<.;.k...W........%....,`).J.7.......(."B.aR.?}....e....#%...h.
>Z..%7..'...|U.v....a%{.s..u..F.V)./".H..<#7yL..N..Z].:.\...\...
..4.|Px|Q j.x.....B.._..<m.'.......P...j......o.\B{;....Y....n..w..
K ...'..$.2..K...C~..$!......#[email protected].{{oc.v.Y....E.......%..A....
/.`....</...2q........]..J.:.....|..R.%.>..u..4;.../..7..l..u..I
.....c...q.....d...v....\8qw.....anB>...*N7D.5.sl/.....DJ......=../
...S.?!....>/.W.{..B...y-|V 5...$...B..J...'....Q...X..ddIu4Z.H"*`.
...]vC.............m(.!.m?...`...{...u.....jE..6..i....-.F.g.1...&LcP.
..u...N.......5`.J./.9O...3.-.......2I.{............L..j..fb.RMY&..<
;n>[email protected]>Qlz<$..9.GhYs."!O..=.>.dH<
......$..%.....l.k......Gl....=M....0.&W.....mn....-^...S........."@./
...Y....S....5...Hu#' ..>h...4..... .&.R..).....<..............
......3h..Qj(.....=.....,*.....Au.o.\Z^.N..>Tq.dg?4..<p...b.5X..
.L..X%5ox,...fg.|<tm^t.2..?..2./..../..[.".....[=..xV.D~.'_..y.....
....k.......Eh>U...R..xz*........Lw...o.m8.....|/..zv.9.tV.Z.5!<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/DhmkbGq3IqOmH688Cmt9YunECJJ_kvFlB6mcbV-E4sQ=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 515
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:20:55 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54876:4:501..|..|.:C.7..ef.^Rb.B..Y..A8.3,.h..r...5......x...m.G...}
...9...8K)I..6 ...t...o.B..B.n.[..*...I......r.\gs...'<.e.?.<...
[email protected]...{..c=."U.9..........#........P..x...Q..
<](M.. .k.7l...6.I....v..G.....P.<FP......\L.U....J.I..hYA.MJ.&g
t;.%.cs..-f.._&..K...?M.tE.4... 6..\.)M..D..x..M...o.]......*...>..
....".4.H......A{.........p...b.....v=../....7..f........I..K......HUc
S.Y..Z....!..Zg...C.?.X%.}..=..%4.G..A#....H'`......<.B.,\..V......
.?. .....d..#N.j3..>..........Sq....0E..s.........
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/POqsACfqD9umXojHJh63f3wzdU0jArUnh2RZWVlPo6U=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:20:49 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54875:4:1025..|....#..QF......v..{...^b.y\.........a...#v..d.A!Y....
.F...=..R.ou...'.L..Mpo...El.._.P..L..i..0mp...ctsf..R..h..a..........
....Ov.\...lf..K........?..?...".k..s.....r{.|oz.Y.%[email protected].
..t]7.^..a.........{.`.b....o..X..g.!....dsq.I1..e.0W.$lY..m*.mG.b....
.F{E...)H_...].N.'...6k.Ci......b.Z.I...y......C..?..{.|-.0..nn6..#..&
d..O9...z..mC..[...%..g..EpiJ;...Yl...%Z.....X...7x..0........=:...` .
*..A.:.q....A...&\I...e.sI..=.....7x..r..SV.s.......%`..nw..S...G.....
.,..b.!......U....s....8....r..9G,.....U..|.;u.u.1A...q.f...Y...Q..r.&
gt;.E.(k.R.i...."..3....e......e=J ...VH.{.......o....L........'R...W.
......%...*.fMl..t.4.....&.......9......L..h.G~k..C....'$..V3..mk..b..
........_..../l>.\...x.y..U.f.....yqk%...e...?M.........s..U..e|...
.....6=......z.W...V.".Bfp..TT..$2.....n.1..c(A..D..E''.%U.....#..._..
....-`8...a|L..[..j.m]"f....I.0...<..[eq..1.T. (!..k......5..$>.
b...~..H.3.......k......^e.z%.^.Wi..gX...c.y..~..-....h.j..g}.hS~.....
...........W_........k........w.r.>{.IOq.../.../.NO..j......?.I.SW.
3%.......
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/a39oZB5GvsB3u7BxwIU71DqzAeakBAgZXyrOwzmZnik=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:20:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54874:4:1025..|....).J".).....Ù....W..8z..~'h.y'.=.......4.`.c#..l
.S....A.q...&....n'......6&M.;..^.~D.1...J8....\"Tl.........gn.ky.-k .
U.*.OM..=..1.`.....?.&Q.../......q.pYs.3I".$8...>..lF....n..6 ..;.\
..8..SU....!...j.....m..t.'.ZF..?J..|\......}.z......E.y.Da_.R.n..U.C3
[email protected]..^}..-Q...U5..T...o.1. .B.....dMw...O.3pC.}?...#.*.2..
..i..F=.m.e.M... .'...E..k.IWz.....o.z'!.P...NTP.x.PHA..eE........a...
SE,Y'm....I..n,..`.......y.Ko................Z...~.yL...... ..".#....
..x..............E{......6N_.D.$...~..-..X....xfs..AP..C1..G....YQcn..
...?.....De.2[A...o....1.s..[..M..wS.9U...... .{.S....v......7l...<
.@y.&..V..7... .$PE,........q.....O....`.........f].!.}...[...I(.zK..Z
...7....7..q.#`.c.g.B...............c.'.....p...3..L...:|.Pu.\2..e..*.
.I3TA."..0..l...B.,.A..qo.V_.p.......d.o3..-.*.\..b...0`............M.
... )..-p"...g.......P.5|.B.^.:..........BX.w....B..<R...<..5%4.
gB.....#.0..k..82.1IG.&.X....Hd.c.....oF)...<.~.I.;.w!.g..E........
.<Y.V..R.f..(.....$...T..l."..]X}.b.Hm%....m.cP.:H.......^)%.s0..W.
...`..Ql....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/Fejg5XK1yuNw_YRGnEjzcXe9IfHSn_fxKCR37v7LbfA=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:20:53 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54873:4:1025..|...!....Xf.,A5..V.{..BpW..'.]^.......2....c.2{.'.\..K
......p.p..0OG...k..w.~cZ.X..~....A.....ntE....D...<...j&..B..u..j*
..H......0.......*...:'..]....3. .....!..Ig.&.l..UW.M.6.......tY..U.4.
[.[j5................H..Q..Ao..d.5.V'.?S..%.).$....).d..$..f'.......-&
.)...?.m..-i.n.kT.@|.d..p......x.1.4D...@...}.4.#.P.\...'}....%....-.1
.......['. [2.o.....O..]...........[...v......)..:...Y.>.g.'..[..t.
.......!1..".V..dX..:I.$...hT..kE.. ......w.......*.(......s'.;.....L.
..';.a.x@......:.....U.H|.U..d$.U.H...HS.G#g.e.._.._...qv..}y.7..%j...
.<y...xi|s.bw..7i..`.w.......i....6.J-. ......a..P....8...vP.......
..$2..2s...A.P......}.B(......R.w..m .'........(..M..J......m}...C....
.Q.........N..!............[.......0.....H..../.y...Zm...J..t_.......*
..c..B&..].6p6...........L.`.4..O.De.....f.^...G.=.*W"....y...(Xg.@. \
vI<.$.g...'>......o.Q.4.."p..&.;[email protected]|...8I%
o...&..Y..%..F#..y....T....7.q..jY/..s.w.... .j.w.0./.AY..;...~E..;M..
..A..Y..DH...._..X.1"...-.......d..7w.h.....I.Y..}......N.SVV.........
7...|....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/KLnyMTj-WDDYVL1nZ8HROsuR0XViDZpknDqSt3f8tZ0=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:21:04 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54872:4:1025..|....In.l...4E.....s]..Os.;{...YU.Z.@>.(..'.o.u.9.m
.@......]ch...s..........6.Y....bRGQ,.Z....J.K....."....ki.QgR..w.b...
.P.....j..Eu@!............'g....v~..3....pxM.9....Y.$.......h..<;..
......s..e......>.-....UAn........-..~...d.....)k...B..G.....L7....
...y!.#b."..6.....y............".(7..JMm*../s. ..<...?..xc.M.#.....
...E.\@....d..2....X)...M.B...........M....[..[....%ko.2}Y-.DYG..;....
., D .u...4R.....D..-......>....N........W....&......./..P]........
X.5.v|...x.Vy:.1fP..#...L.."..a}7./.......C.q.L... N....M...57.}.4B_..
...U..q.............;. .yda2.H_.d.#^.Y.%YG....)....eCq....UF.ZV.._U...
....9}.h}......[.~."......3.s.]q..m..U..J....]vA........X.:.. ~CR!?G.X
C..{.....q.k..$....J.=.&...........S.S..?...K.....-..[.i?x.-i.6s..V.dO
......h..cT.Lv...#P.bp.............Y.6S....X.h/[n....L7.....m.D.e..;mi
..1....%,.....N&..L'.J,z..-....F.L.yq.r..n....\./...~...~.'....$%.....
V.I.......LN.g.2bB....u.....s.^&.....7........l.....L...Qp;f.X..Z...3.
..(..:8}(n.`$OiD....3..._.!...*.1.o.2..I4..&..-......!......W,.%].....
[........
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/XXIH_VyGQMK6X1r6-qVTBZRUmfW6hzxd-YkgYKOoYjY=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:20:58 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54871:4:1025..|...3.Q..*....B`......T ...)......WC....PN%.....K.UM.U
...T.a.Aq.6.Y.....(.]>..o...X..k.u...l.lk...,V...%.2..XV7ve..\..isO
'.e.... z....qx.v.....M...'T0.(.....Zq.!.v....f.rP..E...R.U..k.<..J
...<.......-.sF..;.......k....p4..|hqfyE.:..8t;..@....;D.t....l..*.
....6o.JO....-...q>.3..l=.....N.....;...yR/...f..}..._.............
vB....0.}..e...z =.O j.oA4r.Z..~6.o.r.|.>xZE..J...(.#...(.D)3[.N.v.
.:.J.1.;.Fy&`x.D........"$ond[....<...P6z.(...*.m.b.m.t.Zz6....y.H.
....bo..GSx..p....zs..n...M...m.p......p[......J.V..V.:'oA..HC3......H
..%%.h: .&(......y...aM.>.:.:....S.... .w... /."Z?..WvAv...bT.k..(.
".7..J...A.Q.C?J:N.1.P.@.^.P [email protected]\..m....KCrMJ!...yS.
.2Qy.x.}.......jI..(P....t.qA.-..n...M..m...{..OA.. J~.\.C.7.\........
( .........vJg..V(...r.? ._....(.s<.JZu.Y..2.g..{Y.......M.:.Q..*a.
.....p..0x.Bs.$...%..,...;..K..i....PC..%.<..e.K..g`"...S#G.......S
..r_..NL.>.G.R.;4jt....q.@?7.......@a?.......OC..$~.....>....@\c
4........pA....!..j..."_./SGq(..w^.NO.7.... s...xFet..P...f$.5e_j.k...
.Z`..p..O.g......~$rh......
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/lDMYCTCxctZtPK8ktsRW5E2Vn2pRjEfv7ILwgql5UKY=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:21:06 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54870:4:1025..|...[e....X.....%.8T.........c.....k.0.[..$.sst..G...F
....GF.2z9...[.b/...I..u*... h..YGY.2..p.gk.m....[...&..\D........d.m.
[email protected].,..T..?....j!.....7.Q....1o...>C...
.)...z [email protected]......,~|.....RRa..qH...1/.8.....bt......y.H..x
J.m.N.....r'.....[b..8......!m.c".R%L....W...(P<..I:...}_.F~...Y..X
..i...^t.yq{.{...It.~...Sz....d..m~%o....:.._.m../......e.H.J.=".V.b..
.$...".B .p.f.c_.-.j.3;P.A....0.\5...X.....M.......2.QR..Y;.N.&.....V.
ML...XF.5...P..4....Z..tq.w...l......BH..R....a...Z..5...$.[y$x.t.&%..
u.s&t...........r...dC....X.Ag..M..."=.......O..F.K.3|:).OF.....<c.
[email protected]}..H....t..c.....8.M.)....LPJK.....Q../...........
A.......a._.].9R.......'...u.......l..B..hO.O.AH.....VC..f...#..s.....
..#....k..8CJeB...'..i...X..!..Q....e.c3!..!.'...P[V......)..W.%'.d...
..6.p..O.1y......y..0`Y.G..(Y. .UT.`...4ne..._3..C#ZX..M...%.........e
......=....`.... n......._8]=-_....ceh1....w.k..AJ....p...nx.NB.......
..QG.......&..G..-.|^F}{...&L..eR....'..'.....n2........Q..H....C11e.<
/font>....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/5uO6Pab7G-Fdp1GqUSSzm2fYjQ24MkfLFcHw2lPcG48=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:20:47 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54869:4:1025..|....SU...KtA.=.....5..C)..w.........w.........>..-
qR.....`....{Q....... %.Q...\.h.Q9..e.r.;...d.].c.[.'...b.a.".dA!..u..
.........\s.Lf..Q.a$.*N.}.Yg...k.d-..WhLR\..,.....xh...R....u...j..Z..
.a....).. [email protected]'.E`.c...].o R.w.OdFe...V...
.$i......-.\4.....L..=..^..M........rA...TU......W4..Yp............D..
.{Z..~j.#H..H;].=;h..5E..si".%O...".....3..U......,....z.`cQ 5...*vP..
...K....}e...>.5.[...V.!.........w].$....%.i..M..f.....rj..-I.....!
[email protected]..........*..n...I..X*.....Pl....n.D.*..Q.
.T..QfK.7..J..n...z5..STqa........"/.....i.:&Z. .2.j..icd....s.l...Tw.
..X.kp...........C.....?.......S.:..'&..c.....h...:.vDu...d.J&k.e.@...
..z...........i.a...W.Z[g.LtR{N...T.6.X.B...Y........c]C.M........c.(.
#[email protected].=..1O.........Bl.H.;...BQ[.....E.qlf..ksY...=.........
.o..|..u.)2TwG....h5.x..\.4#.<.N.....k....^w..*(.D..".......=.Bk...
.....2uG....E.G.(........>..p[.....]....F.jq2Gk.m>..Z.....W.3p..
.T~p4.i..^.oL=...c;.(._..... ..@X%....`.v.o.W...;......mQ0`x...H.O-.j.
...3.....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/yblLd2E6Kl_fu3GsgarktrXxWijZbNqYOqggb8uZQ48=.chunk HTTP/1.1
Host: cache-kiev01.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Content-Type: application/octet-stream
Content-Length: 1040
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:20:57 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:54868:4:1025..|...4.........~y.OfZ.v.p0....."L.ds....V....O...Pu...b
...]..?m.|.^..LY...'.k.3./.....i](..........o2...#.D..3.}...B...'...M1
....G5_@P.$..N..e.L.... ..M~..,... ....IM.l..4..JJ..=.r.)....C....sH.L
(..,{..zy..mI....!...LK...f$?...M....L3G..y..... 9...E.o.O.$.wP<..L
.N.....(.....qQ6%#....*9u.15\.z..E.?.6o(.q.l.]./..'...6.._.Jf.R.......
...yH[..G.U1}..Yu.."4."qH...\Q..D.h:..>.a8.4kk..(S.......(..?..bZ.
[email protected]>....}Q.....wwAP6.xE.]v.....^\[email protected]....,Yl".#.`U....
.....A...F.6 ....I....x...i.]..WpV/....*...:.y....$.......GK.......d..
*D........n.......t.$.....VP9......]...4.W.B.....'P....4_..C...z.r..(.
.....F..`q(....jl4.s.<....p..Q.8^l..]1....i.1..B\I.......;d.!C.N...
....{p..z..P..).x..D.....i.CV.7...A.d..b............{N.......S...R....
.....pkU.......KQ)p..5v.... m...(...)........Z...t....;.%..}.U.......j
..F2..Q..p 1x.p.....|.\lq.a.....vi.3.:{.HE...CL...j.. p...9..k6C..ovp.
.{4..8...Y..!.J.-,...>...X}........P9.....P{...S.FT.N....._b%.!....
.:.l...`g.....w....,A..0....r.?....Q\......P....).>..)A.=..65..!...
.....L..HTTP/1.1 200 OK..Server: nginx/1.6.2..Date: Fri, 01 May 2015 0
4:21:36 GMT..Content-Type: application/octet-stream..Content-Length: 1
040..Connection: keep-alive..Last-Modified: Wed, 29 Apr 2015 07:20:57
GMT..Expires: Thu, 31 Dec 2037 23:55:55 GMT..Cache-Control: max-age=31
5360000..Strict-Transport-Security: max-age=3600; includeSubDomains..A
ccept-Ranges: bytes..a:54868:4:1025..|...4.........~y.OfZ.v.p0....."L.
ds....V....O...Pu...b...]..?m.|.^..LY...'.k.3./.....i](..........o<<< skipped >>>
GET /icons/product_logo_128.png HTTP/1.1
User-Agent: Game installer
Host: customisations.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:03 GMT
Content-Type: image/png
Content-Length: 24082
Last-Modified: Wed, 02 Oct 2013 08:03:29 GMT
Connection: keep-alive
ETag: "524bd351-5e12"
Accept-Ranges: bytes.PNG........IHDR..............>a.....pHYs...#...#.x.?v...OiCCPPhoto
shop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE......
.....Q,......!.........{.k........>...........H3Q5...B..........@..
$p....d!s.#...~<< ".....x.....M..0.....B.\[email protected]..@F.
...&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWf
H.............0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(
.I. [email protected]..._-...."[email protected]~..,/..
.;..m..%..h^[email protected].~<<E.........J.B[a.W}.g._.W.l.~<
;......$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,
..>.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..
?....D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/[email protected]..=
p..a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2
....G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,.
.c.."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b2
1.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!
.[[email protected].(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i.
.t.....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....
J.&..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.
._... .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....)
.)..4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....
Dw.n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC][email protected].
.....<..F.F..i.\.$.m.m..&.&!&KM.M..RM..).;L;L........5.=1.2....<<< skipped >>>
GET /PlayFreeBrowser/chrome.packed.7z HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/x-7z-compressed
Content-Length: 34442382
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-20d8c8e"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytes7z..'...3;..................z.........8%D.z.x../.Bg;....N.zN.......9 .
......M....4..hM.......X...S.-....O ..`..85.........F....$........m.cW
.F<$7i*..... $q..0D.-8.wm.=..`}.Fv..b......I....-...<...%RzE.5G3
PS...@!....z...c&s.....X..4.I...>.6..R_..~...Ov.t.Uw..I......r.U.kJ
h..z.S...1g.Y......2..aa..7..O..'M..wH.B'.P..}EM......y|...bc.a....^..
..."...Oaq......#o...2.U...nSK%.'m.f!!.....'..`...@...$..9.wL...!...K.
..g....sV.7../L...V...G..........k.<)..D.......H..-.9........(Q...5
?j...g...'..0g...E.3 .....k..z..<...m.......f.. .,~.k.......Q..7).`
......&..x.#*.a1D4...,...w.....=.....g#3z.{j.#-.........$....<0...W
.wE... ...t.....C........"BNB5h:.J..Iz.....I...#....6..s......R...7.N.
.I.l......7.2.=W..VO.. .....Zw...M...........no.q9..1.q% q.%...G.).g.Y
V.....Y^!g....|x..R...q.\H.;....~......x@,..*.&.......<h.X.4..~.&
gt;.z...T....:Fz.7.Y.^k.....e...........0.$.J$..rhX....E.<....5l.H.
%..O.D...w...4K8.....o^..P.~N....0.Z.'i.......K$..~.(x.C....>....y.
<...I!2.AB.....p.l....m...|.!1a..T..F..C.....~....:..&.....Q\_..J.a
p.. 2i..n.........'...g..'[email protected][..#.U....$..o.F.1B.&
gt;.k8.4r...a.aa .,.)i%.g.V. %...=.f6...sK.,B'...._.......z.x.7..).n~.
z....:j...J$'.j...L..^.c\.{.K...q.|n.$...F. .H.Q.~o..HT..I...[........
o..o..'Y-.S..6.IO.c.5Q.D.~...[2.L&[UM...U...1..I*H...f...>..C.G..V.
..b.[..C..KOB....X:u...q.....<.......=..eEt..D....D..T..../^.D.g.&U
9.........)%..k.p..V...,[email protected]_.A......... ....dT
.kK.&O..G..y....&N5...P........(..Tu..a......M0..dx.9.9....mV.*x..<<< skipped >>>
GET /chunks/goog-malware-shavar/lRebbZGau64hCEQVXoOFwZoCHsX1jFGWIfTr05I6p_E=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/lRebbZGau64hCEQVXoOFwZoCHsX1jFGWIfTr05I6p_E=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/quCU-R968hkl0cyruELC_MV3YrizvN33lCu_XyBmd4E=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/quCU-R968hkl0cyruELC_MV3YrizvN33lCu_XyBmd4E=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/dOYW8CT1uM5jIP3WOTesmR9-XVI73w_SIuLTAYZEGKk=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/dOYW8CT1uM5jIP3WOTesmR9-XVI73w_SIuLTAYZEGKk=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/oB-hUus1Xvl_1EQENOruhBHfNyDrwfBHGVPnkkgwHvc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/oB-hUus1Xvl_1EQENOruhBHfNyDrwfBHGVPnkkgwHvc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/0R1tCv_0z65MW3lwpOOkUz0Cpddp4rD5-PMCI8oOhRM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/0R1tCv_0z65MW3lwpOOkUz0Cpddp4rD5-PMCI8oOhRM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/mmJ3t2zL0g6vWR1TMD1cCWQT8bHUYLHTQ62AC0A9DPM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/mmJ3t2zL0g6vWR1TMD1cCWQT8bHUYLHTQ62AC0A9DPM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/63xhlxiFMezs4dQO2Wo28dlZUouaROKHvZDLwt1eVSc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/63xhlxiFMezs4dQO2Wo28dlZUouaROKHvZDLwt1eVSc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/a39oZB5GvsB3u7BxwIU71DqzAeakBAgZXyrOwzmZnik=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/a39oZB5GvsB3u7BxwIU71DqzAeakBAgZXyrOwzmZnik=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/LpJqp1zoQaivOKHY_YxfSfoQzXr8OBdeGyXfwZFuU88=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/LpJqp1zoQaivOKHY_YxfSfoQzXr8OBdeGyXfwZFuU88=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/Z-BZzgdR6niuNm6Dbw-4jp7KnREXbvzrB0Xn2C-u9d0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Z-BZzgdR6niuNm6Dbw-4jp7KnREXbvzrB0Xn2C-u9d0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1453
content-transfer-encoding: binary
Cache-Control: max-age=534394, public, no-transform, must-revalidate
Last-Modified: Thu, 30 Apr 2015 08:45:10 GMT
Expires: Thu, 7 May 2015 08:45:10 GMT
Date: Fri, 01 May 2015 04:22:47 GMT
Connection: keep-alive0..........0..... .....0......0...0......T3t.%..O.E..~..F.=....2015043
0084510Z0s0q0I0... ........H.dI.....3..^B...d6Q....ZL%."..1.m..._)..a.
.eR&.....Y.)..".\....20150430084510Z....20150507084510Z0...*.H........
.....S.F1....m^.f...(.Ss@*M`:_.GI.Y.I"..}M@........*....o9-.{2W..)'./.
A....VIl....Xy......#.J..!..z.Q...0.Z.W.e....{D...tm..=.(........W.3G.
t..mw....#tn%n.P...,...E.mD.N..P.b.qY..|.c.>..xBZ.J.l.G..wx.......y
[email protected].~.?.o.x.k.KB......6.....g.owYk........B(...D....0...0...0..3
......./...b.v..-....l}0...*.H........0_1.0...U....US1.0...U....VeriSi
gn, Inc.1705..U....Class 3 Public Primary Certification Authority0...1
41202000000Z..151216235959Z0..1.0...U....US1.0...U....Symantec Corpora
tion1.0...U....Symantec Trust Network1?0=..U...6Symantec Class 3 PCA -
G1 OCSP Responder Certificate 30.."0...*.H.............0..........'..
....Y..x.3B1.7..Q..`..d.. ....s..t.$a.....j2R.{ ,*..c{.3.....H..3-; ).
....0._...*..9M..V...... ...{m...-.......)..tR..{D....~...M...T..pS.p.
.^|o....S..v.).)[email protected]#qh...u1T.].G0.]E...=._..
.... ........TE...Sa.s4........r...3.............0..0...U....0.0l..U.
.e0c0a..`.H...E....0R0&.. .........hXXp://VVV.symauth.com/cps0(.. ....
...0...hXXp://VVV.symauth.com/rpa0...U.%..0... .......0...U........0..
. .....0......0!..U....0...0.1.0...U....TGV-B-2730...*.H.............$
..H......oU....Y!.z{*.V.M..u.._z..3>.. 0....3..m.....e.......a..D..
.........e..F6:.y.....di.......<y.Z.......x}..q.2....UZ1 :,.
...<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=343147, public, no-transform, must-revalidate
Last-Modified: Tue, 28 Apr 2015 03:40:02 GMT
Expires: Tue, 5 May 2015 03:40:02 GMT
Date: Fri, 01 May 2015 04:22:47 GMT
Connection: keep-alive0..........0..... .....0......0...0......'.V.8.F.V....H....JW..2015042
8034002Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
..M.s.Q~...@?j.......20150428034002Z....20150505034002Z0...*.H........
......>...|.#%....9.x.Fl.{.j..i.{<...B......5h..T.....<....).
nU,7.L.,UpM&F9~.....ye.wpA.W.(9...VO{R.".~.C..G.t.*B...L......D.tj....
[email protected]$...zL........{..G...............].A..z..:{.*&*..2Q
S..s..Nt3..G..CR..D...-.T....H...l.7\..z..:.E.}L.Yk.Zvc..[.....#0...0.
..0..........r..?.*......y"..0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of us
e at hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Cod
e Signing 2009-2 CA0...150226000000Z..150527235959Z0..1.0...U....US1.0
...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Term
s of use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign C
lass 3 Code Signing 2009-2 OCSP Responder0.."0...*.H.............0....
.........m5*R........2....>...yU4..L.. ...........u..Hez..Pn.....d.
..nz(...V7.}^...d!RX...bl..[..a...L.. .~..Ij......%..%p.-...u..:..i..F
*]...*....{NH..|0...gHX.Q.r....S..........._.9.(w...suC...N..s.....&."
...:.C.Q.i~rl..<..krS..8.B..o][email protected]
...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.v
erisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS i
ncorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...
U........0... .....0......0"..U....0...0.1.0...U....TGV-B-32010...<<< skipped >>>
GET /chunks/goog-phish-shavar/QFLQEh7X_zSIxjR1hvMBJtfwElFnYMMESeJW83KcD5I=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/QFLQEh7X_zSIxjR1hvMBJtfwElFnYMMESeJW83KcD5I=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
POST /service/update2?w=3:QEwJUu918gabi9_4v4ZCXohe4k_aFphJi5j2A6BwEZB-pjC258i8eQAf1dWV6qAR-a85v0lB6SfQVyclr06jCyjX1DxAumRSVTctealCogPFXZdsYghpnziAtOr2zw2HoPEwCdcMXfAz5Rw9Nrp_t3Ya9q4bmsU7lNiVgX66-5c HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
If-Match: "mH1alvHIexOBLWeu-xwAZCOwgLo"
User-Agent: MPCBrowser Update/1.3.27.0;winhttp;cup
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Content-Length: 630
Host: omaha.playfree.org
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" version="1.3.27.0" ismachine="0" sessionid="{4DE9C525-0926-4072-8EE0-A2804030D53E}" installsource="scheduler" testsource="auto" requestid="{EB1B5F0D-D8BB-4D99-AFB6-A54CCF10FA07}"><os platform="win" version="6.1" sp="Service Pack 1" arch="x64"/><app appid="{00337EA4-7B9A-44A6-B45B-B1722CD4343E}" version="1.3.27.0" nextversion="" lang="" brand="GGLS" client="" installage="0"><updatecheck/><ping r="-1"/></app><app appid="{2F0B3EEC-E5EE-47C1-829C-ADE0D31F2DFC}" version="3.0.0.4" nextversion="" lang="en" brand="" client=""><updatecheck/><ping r="-1"/></app></request>
HTTP/1.1 200 OK
Server: nginx/1.4.1
Date: Fri, 01 May 2015 04:23:01 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.15
Set-Cookie: pid=06a3o2ll5j1urph5t2a16aukm6; expires=Sat, 02-May-2015 04:23:01 GMT; path=/; domain=.omaha.playfree.org
Cache-Control: private, max-age=10800, pre-check=10800
Last-Modified: Tue, 27 Nov 2012 07:34:24 GMT15e..<?xml version="1.0"?>.<response protocol="3.0" server="p
rod"><daystart elapsed_seconds="84181"/><app appid="{00337
EA4-7B9A-44A6-B45B-B1722CD4343E}" status="ok"><updatecheck statu
s="noupdate"/><ping status="ok"/></app><app appid="{
2F0B3EEC-E5EE-47C1-829C-ADE0D31F2DFC}" status="ok"><updatecheck
status="noupdate"/><ping status="ok"/></app></respon
se>...0..HTTP/1.1 200 OK..Server: nginx/1.4.1..Date: Fri, 01 May 20
15 04:23:01 GMT..Content-Type: text/html..Transfer-Encoding: chunked..
Connection: keep-alive..X-Powered-By: PHP/5.4.15..Set-Cookie: pid=06a3
o2ll5j1urph5t2a16aukm6; expires=Sat, 02-May-2015 04:23:01 GMT; path=/;
domain=.omaha.playfree.org..Cache-Control: private, max-age=10800, pr
e-check=10800..Last-Modified: Tue, 27 Nov 2012 07:34:24 GMT..15e..<
?xml version="1.0"?>.<response protocol="3.0" server="prod">&
lt;daystart elapsed_seconds="84181"/><app appid="{00337EA4-7B9A-
44A6-B45B-B1722CD4343E}" status="ok"><updatecheck status="noupda
te"/><ping status="ok"/></app><app appid="{2F0B3EEC-
E5EE-47C1-829C-ADE0D31F2DFC}" status="ok"><updatecheck status="n
oupdate"/><ping status="ok"/></app></response>...
0..<<< skipped >>>
GET /chunks/goog-malware-shavar/LUPMCPyJrbw1OieLTkZuI4-fa9veuo2URB_xdN46leQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/LUPMCPyJrbw1OieLTkZuI4-fa9veuo2URB_xdN46leQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
HEAD /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?cms_redirect=yes&expire=1430468552&ip=37.57.16.189&ipbits=0&mm=28&mn=sn-ugpva5o-3c2e&ms=nvh&mt=1430454086&mv=u&pcm2cms=yes&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=26347A8AAAADD774630CF4C618EF0C0A5FC11F65.0E69BCDACB63B8EE5BFA7AE881E0B9EDF4DCB9C8&key=cms1 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: r2---sn-ugpva5o-3c2e.gvt1.com
HTTP/1.1 302 Found
Last-Modified: Wed, 02 May 2007 10:26:10 GMT
Date: Fri, 01 May 2015 04:22:33 GMT
Expires: Fri, 01 May 2015 04:22:33 GMT
Cache-Control: private, max-age=900
Location: hXXp://r7---sn-3c27ln7e.gvt1.com/edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?expire=1430468553&ip=193.138.244.231&ipbits=0&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=7D4079BF52C899D89F0F25202F13E9822AEE47BE.45C0FCFDFDF641CD52EB1EA40C5BBE6C203793A9&key=cms1&redirect_counter=1&req_id=b61242fb02047153&cms_redirect=yes&mm=30&mn=sn-3c27ln7e&ms=nxu&mt=1430454091&mv=m
Content-Length: 0
Connection: close
X-Content-Type-Options: nosniff
Content-Type: text/html
Server: gvs 1.0
GET /chunks/goog-phish-shavar/tsOoy7JAp7Lz5F39t4GNxgnXgvcVKsoLv9IDzQgKTp4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/tsOoy7JAp7Lz5F39t4GNxgnXgvcVKsoLv9IDzQgKTp4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/u_hXwLRpsoJeSOsazeFzQYvUWnjbcqzfxK5xvSHfm3c=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/u_hXwLRpsoJeSOsazeFzQYvUWnjbcqzfxK5xvSHfm3c=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/E34UBcOsmTNnqLeVWPOaryM0WWvyZOIzlDl7WR6cc80=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 1796
Connection: keep-alive
Last-Modified: Thu, 09 Apr 2015 03:00:07 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11876:4:1781........ ..)......$S.\...Q./s._.aa.*.. .A$>.,.(y.9..9
"}..<........TA.......).kM..)D....x.....|b.........~.q..bS........'
..d_M....' .$Y.w.6...xU..t|.B.....m.........i.h*......R.....f..*E!...
.k/....L...)Z...v.....~...............prF.y{...(..;...W.S....<.h.j.
G_..H[^A.Y...&3.N.....gE.m...........4".!N)..%.!.].l...XO6.H:.......R.
Z.HlFa?..s.s.s`............D.....f...T.x.o...t.j.ù.)..pd........d8..
j.?=.J.....j*....s3.u~......\y......>....A .8......g..[....#.Y..(..
.A...%..z.S....y..\..j..X.f.*i...........&......Bg{.....n...I........E
[email protected]./...m.#..m.#.1..s.. ..cc3^.gL.h%....G.....P...
3.kh..i.<t...=d.......S=X..".........g...E....3.. .W.=g..8.^.."r..W
..SLl.D.......2.....^{Hf..\..L.....c...@-.....$..v.J...b...qL.z.....R.
a.y..>gu...X..siu.u....2....%...).e C..Sw.97..U.#.e.y3.....C.e.....
....y.j..c..gm....f-...{...]..Z......Nm................%..%d).ia......
..y.<.V`..n..L...l.m.......9...GqQ.Z|.P...... 4.....s....Tn...D) M.
.....zdwg.e......Y...z...m..{`..q.q.. )....&.C..C@..\~....I..y;.O[...]
.7.]m.L...-8...9.G..............a^.L.~.S....S....gb...J.p...-.../.....
.nO^."..E....W..K........mC...mC..........f...$....K.d..$[@...q.k.v...
....c...O.......|g..o....B....b.g._J..e`."b.%...G.........v...]..3..;
<./<8.....FOzh>^y.......fn.O..t]..rr7..t>..../LR.Kh.>.B
.....H=.n.....u..0.U....^[G....._.a......HC.......m)!...i;..YL.[.y...k
A..$(t...2..EI....%.h...g...[]......tN.. ...`.<..]GY.V.....,....6&*
..uK..R.<......a.J....\z....d.*.........>f.1B..4...Q...?L...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/QFLQEh7X_zSIxjR1hvMBJtfwElFnYMMESeJW83KcD5I=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Content-Type: application/octet-stream
Content-Length: 5593
Connection: keep-alive
Last-Modified: Wed, 08 Apr 2015 03:00:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11874:4:5578..DMU.C8P@..\...._V...V....V.....k .U..j..-.>...2.Fa?
....?...........o.........xU...<... ....S......_s.C...v......V*..Qe
...m<I....r|.H...I...*.\..%.......h...j..k..x.aE.x".\"..7.L<....
...........ù.0...M.F.37Y.t...........I-..A.k7....?1.x.H... y..K..Ow0
Fz..'F....F......t......on..../~pJ..N|....Fl...A....RO..,.nU`......&b7
......5..P."...I....}.}......X....zR".7....7..?.L:..ha.q..'.q..'T....1
.. ".. .[K.....*......YR...w.r.if..?P.)n....Z...q`e..[..Qp..).$.3..>
;....:...~.....5..C@..~...z......a.2G.,#...~......{J.F......05>.H..
\1...C...J......#...........:.........a.y..S*..([email protected][email protected].....)kN7
......2......s..Dg....~.x.w..I.<..!<...'.JC....PBg,Y."}r.p......
'.......IG....k-E.........~.......5...fP...lK)0..~.>..`..1d......s.
..B..`R....1!..........[....<z'.....\.....dq]....)Y......R.c.}.5.{.
D."j...u.[~...$u/.'...Z...9=.8..||.m>&.....J...F.t|..O....xb..L....
..Q&..U..2s.v%.F..:.\..B...f..}..`...3..W.....eb.9....[....(t.Q.J..6].
_K.v:;[email protected]%[email protected]:.N..[C.1._bf`..I.H......h#.{V.@..
}.G.......5........"...o...w......OX......Z.Y.......RE..'..I.<e....
...5.R....3]o.......4s..r^...D1.L.....V.O.Y.......[`.#....R....L..Y..s
|D=.......F.C..{j&o.F...r.o..e9,%ow [email protected]..,....J..z
..........}(...}(i..i......u.&.<[email protected]..
..r-K....I..}..A...........M.?.N.. .#*.....y....]n.].x|..e|...i.......
...R....2^....|a...&.........L....Y.8.N.-.....5p.#.....^...........*P.
V.....Q..T...|..K..Du7..n.p.........`j.M.......(B .(.U...^......|.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/wE_jh56jwL0G3tMkWWfbENSe5bxNIfTAzlgY1brnafY=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 1382
Connection: keep-alive
Last-Modified: Tue, 07 Apr 2015 04:30:07 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11873:4:1367.la...mY?.C.....2_..Q...#.........`[email protected]^1S.
..........j...wt..Y.w.b]...Y.&.V.np._....y|.#.Am..3.S...9..(.iI..e.?Au
.$%.A../0..lU...9R.pw.....h.p...9?......X...7...'.Fa?......6k......<
;..R...,[email protected].....:_.......T.c..D.............w...w..
<..xk..'.(...qY..c].b....4-"}>.......1........F..\......U2.d....
..{.....N[..A..y......Z..[T..&....&WU. :y.d.y$(..........#...8.h.Z....
K..U".!...b......m...p..............P..?.6k)..".B.=....J......h....,..
.,..=...N.t$..'......S.T.S.\..[&.tn...(...C.......%..RF......4o...s..v
yh.....T...z..!.}$3D.....b.....7B..%......c..u...3/:......./..t}.A..td
.4..WR....u..T......]\9..wv..d.!U..{.c..)s.u..-U..5r.'&.j1`...L...x{.S
.,pd...(.uK.............O.......(5.......zg..F...UY# 9.....c...y.j.*..
.*.A..>4...9y..Y.$....l..,".R..........&...H..............4....Y...
..`..E...Bf... {..V..F.....;s.,.{[email protected]....[d36.....g.&.S..
.\d.w....|...r.....B.b..H...U..g.L..B. t..r^..f...}t...2:.............
....x....xx..].u....uD..?N4...6..Tx.c.PK.............;O.......s...K...
..[.6.#.,..&......L?...A..e.x...w7.O~%nfk.{.c.J2N.. ..S.X4.....h...n..
.g.k..u\......g.*._.>...vp|..P......n....2....w....q.N...-..%......
.Q......X.Q..i,...S:.iH....vU@*i....uu2..Z..7..U...T.El.T.Elv..b..-tLw
....6.C..#W.R528.*CQV...a.X.a-./h....mjw.....N..(`l...qPm.....He..0V.p
..Mn.../I.X.........,.!@.........;.B.......d.........=.K...lO|..68.ont>....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/AKhP51LP6RbILIOwncigFP531tS2Yb9D8jtiZVa6uoo=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 1480
Connection: keep-alive
Last-Modified: Mon, 06 Apr 2015 04:10:10 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11872:4:1465.h.W..h.W...B....B.Zm...^.:..`.......cc3^....;.,'K.....l
Z8.........L....{wF8..H...#.........F.......i*....p.......n.... .Qj.?=
...F.k....W....5.v..4"[email protected]:.<....(P..IV..7....Q..
....I@./..toJ..;...<.)....1..R|....|...#...j*[email protected]".
.....J..I.oB..3.J..g....P...j.K......D.....D.6.....`...~....C...J.%.*i
...r]..5!...W.M.5!.=.....{g.#....v.T.K.6.(....-.....qG..7.}...].K#.`h.
..Y.u....G...P..H...Q...].6.......e...#.:...i..%....X........S. C.....
1...!...N....h.j..h.j'.)..4.w.R..P....e.....VG..vyh...k.{V.....-..4..;
[email protected]>......R..6.s...|....Sp1#.o\....hFD\[email protected]..`.(..
.4...y..p..|.B.....bN.....ePq2..KH..)EN..}.p.U..{...^.$y.9. .kc.......
..E' ....!5s..p.iQ.KP........&.....W..n.A.kx...~......l....'../,......
...c...DG%.nR\...B.....F.H.eo..<......."P."..g.hy(.Zi.,A.P.,A.Pt.!.
.V.{/...6....6Bj.e..?P:.......w.O[....zb..=... ......Ve.l......#.....C
.....E.M..Q.E-..j....}t...".......e.z.'.4.........m.'%..z...... .....&
.- ...V..m...c....N...1m .O2g.......r.IR$:..]_W.&e...2.*.....e.......A
n................m.u.&....J..z<[email protected] ......I..z|...;
..z...I!...h.9Q.\...9...D8..B.......>.B...t.s.....k..Z..4.....qM.R.
.w7.(.d.......^6s9gf.........oN.. ..-.2T.....6...._..6&*..^P.N..d.s..$
^.^..m._.@C....&../.x#{3.r._ :_.>..$.7.[/Io..`............yw.......
&._..........WQ.R.&...P..]..A'F..o*.....A._h.....n.v..b.n........T)F.&
1...[|....]tB.5../h.... ....<..y...(B ..(B ..k`..j:_......x..v}....
..2.....V..,...2...S.1j.....=Gd.(\....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/k0cSSdexw9nzUo-SpJK5J2Fc6MX3OaEDyf9RhcxZqUM=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 1010
Connection: keep-alive
Last-Modified: Sun, 05 Apr 2015 03:00:02 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11871:4:996....,.e.].h.W.....yr.......&.`...K?S..{......#.W.....p.A.
..cc3^.g.O. ./..m............?.#9......^g....&.Ian..H.........X..&.l..
&5...........)[.-..u..\.x0.nKL.@./...X.....a..QA......Rt ....3.>...
.H8..4.........1..*..=./q...........>...........6.d%...d%..i...yr&l
t;w<....<........4M.R...........-..(....mx^.1..m.-....-.........
.....E.... mg...(.....N.....L&..3....v...A....A.."....oD.$.....ZA.H.u.
_s..'.)..a...S.\.....b/............&1...G]..s..u.).^..K....K..vyh.....
..kK...EL..0=..T.b..C@...$.p...#muJhL..P.\qJ.........$......d....5..tW
.~.*RU..f."g)17..U.`..0.......*.......r.z./.....G...........(...Y..."&
gt;...%.w....l.&$.C.(.}..e.#...P..-.>).t.!...'..u.......9..2..6..C.
..............^..........@%w.b.%}..'.4..[O...z6$..=..ow Q...........79
S.c....2.eX......[.I.KP.I.KP..<....h.D....]A.............g...6.T...
..<.AW..1.. .N;./j.m..]...5....B...].....r.yl.c.,....L. n..N.. .iM.
.L....L..._.>..^.is...8.S...^.....}[email protected]/..5p.i.IC...
g..{... ...1.U..K.......Z._..r...[r.<.....u.d...*^...d...S..
....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/HM7dZNDeI2vQqgLnnwJfkuP4fRmUKMAJ7bTbK1qJ4Ho=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 2866
Connection: keep-alive
Last-Modified: Sat, 04 Apr 2015 05:40:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11870:4:2851..9%...9%......\...S.\....&.....K.. bqR............n).{&
gt;.....e...aY.t.I.FY* ...M....}.EyI55.._..Su..J.....]."........;;....
...p.)....f...@.._Q!........5!."..Y.....L....=B_C...p!.....*....*2.6x.
.]..y....v/............K;B?N..e.G9)[email protected]..#....7 ....T.c....[F^4.yL
X..yLX.6....D.w9.(6.......(eQ..z.%|....[..:.....p.. .*d.....A.C. 0.|..
......r.._G..b...W..~il.j)[.-.o.kY.} .....x.f...*(.7.nv...=..&b7../..!
.l.$.yU......2)...\aH...t.3?.........R..k.,_]..9..R...lgX...r4L.....U.
.....u....q.Z...q..wz!.....W.^.W..)j. aj.$...u-d5....P....P...j*.m....
....I.... ...o...|. T.|. T.1.\....O.....q..[...<..~..o....9..i"..N.
.-B...2..L=........^.9Z...................bc....E$w....h=..1......2.d.
I...|.l...6qI..V6j..D.o...s.&P.E.P....P............)fd....u......io...
....=.fY..'....d...I.....{5..W%....fpX4.;.#jl.Le%.....s.mx^.Q...bs4.{.
=..I.....B..Cz.o.B....K.......~.)........$..P....aR..:f..v..._..w....j
.?=..T....i...B..H.^{..xU.uG'.4......|...P../?.8h...zy....(/..{..x....
|...'.)...5!.`7$..Sk'q>`.....?...........I.h.Oi..OE|.tJa...y....g.H
.(...l#...l(.h...Q...,..........F...o1.B00;..0IsN....$.......{Hf....).
n.....1..,.Yy.....L7.)......O.O..O.Ory.....%.vyh..pXt.a..,..c..].6..~.
....?....B....z....zc#.:..J\..`.7..`.7......f(^.K.d..]A...........r. .
..O........duU......_..yxv..5..y..p..8B....<.\..............\..'..[
.>.v.j..@)EN..W...Z....J..v.X./...E.-8.{.. .E..&X.."...5..C....%..x
...............g...9y.....P..ox..5.q.%d).k....|AP..|AP.[....[....... M
_Z...l...J.2^.C...Z_&C..H.j0W.]C.......|..Qf....X........%.G.. 9..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/7JE0yHlqxwcT2P3015xdKB--Hrdwr7-1wPzo1rfzEPM=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 754
Connection: keep-alive
Last-Modified: Fri, 03 Apr 2015 03:10:34 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11869:4:740..0........mQ..9...`..V.v...h.W.......>.B..=r1.j..a...
.A*.5b..o.p..^.O...vf..nP.X..Qb....~H......:CJ.........o....uZ#.....YM
-....K.#.....h...O.c...[.[.3....l...=67.........d..S...O...,..c.mGN..
.*D.d...\..6..vG9.9........yI..."..._C...LZyQF%....;i....A....iA.W*.A.
W*..`.....Zn&.'.......r^..&..Lj.....t......m63-Br...m.`..F.#.BX..^....
...oS.\....*R.H...E-...}.&!w.G.vX..R......... ..'.).....1J......>.-
[email protected].;.........ry...v..DV.M.. .&..!...o*..\...
.2..3.I/[email protected]....%.........~`.!.i..!X...2......^..K..z.'{..D.
...a....2.;./..{[email protected];..l.wf.*9..D...V1}...R.I:...s
>.4,...45........,.7..U.r.<|...M.......d..,[email protected]...
.....S.7.....M...Z....S...y.. .R.._..C......'.4....Lr.~l........K5nt>....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/lRebbZGau64hCEQVXoOFwZoCHsX1jFGWIfTr05I6p_E=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 3932
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 03:20:57 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40220:4:3917...9m..../..9m.................OS..........o.E.....do.E.
u.my.....u.my........m.....97.......97.........s^F.....q..MQ...s.C#...
.e6...s........s....[X.......[X...BN.......BNkaX...../kaX..7.n....$.7.
nj.k.....L".,.w}......&w}...[g.....P.[g.xC.......xC...............K...
....*K...q........q...y..R....-y..R........t.................Y........
..Z.................M........M...2|.......2|..@[email protected]/.....hN
d/..6.....].......^.Ab...._B......^......._.~G....^gX%.f.N......f.N.v.
.v.....v..v..N........N.H........H...mWN......mWN.. ........ ...9.....
.]<U.-x.A......x.A...!.....4..!...K".......K"w.......(w............
....0/.......0/..... ....,... A`$A.....A`$A........|....:.p......:.p.A
])8.....A])8.K........K................v........v...=........=....9...
.....9..d........d...S.O......S.OI.......SI...V._......V._.e.x*.....e.
x*...g........g..._....,..._........4....i^>......i^>..=........
=..T}......7T}..7.(....._...|..........._'F.....`..?....` =.....^_w.x.
..^.9b....^Gx...... .(.....)..K...].9...}........}....6XV...6..Dm...6.
..[...6^..C...65.?(...6k.a....6...A...6.#.....6Uj.J...6Y._....6`......
6...h...6.h.c...6...3...6.......6.jC....6&..p...6dS.'...6...!...6a/w:.
..6.......6..}I...62.M....63.x....6:[email protected]~'.
....6. .z...6?H.....6.......6..|....6.......6-.!....6..j....6.......6}
..X...6v......6.{.....6.Q. ...6i.02...6.......6z.$_...6..I=...6.-.....
6.c.....6l......6).C}...6w.C5...6I......6*......6.......6.3aR...6..V..
..6.`1....64......6.......6.c.....6..[L...6..%....6..s....6K.ig...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/fkpIIcjuujT2rH2P7HowLNvnV_wY3RESjlhYbwey-Ek=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 2801
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 01:30:40 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40219:4:2786....m........m..H-....z..H-...W....H...W...F....y...FX..
.....?X....7$.....L.7$...........................o.JJ.....o.JJ..V.....
...V..f......\ .w7..............b........b..........l............b....
~m98....>~m98.............a..&....ra..&s........s...J.:......J.:.B.
p......B.p..............P.......GP....s......^.s....oU....=..oU...b...
[email protected].............."........"..M........M..
[email protected][email protected].)%.......)%..........7.....pjo
........P....(.......P........h.!...o........oYjx.....5Yjx.<.M ....
=<.M 2c.......2c..\........\...X..l....dX..l.O.^......O.^...U....B.
..U.............[........[...`0.l.....`0.l=.......b=...w'......Yw'....
......a....g./......g./.5. H.....5. H{........{....`.-....p.`.-.!.....
...!..?..E.....?..Ea........a...Ae.$.....Ae.$sQT.....msQT.7.. .....7..
ZF.E....XZF.E........X......&.....a..&....c....=...cR\!......R\!.N.l.
....`N.l..N......{.N.....L........L.T.!......T.!Hg.......Hg..j.D......
j.D.T..<.....T..<!........!...!..!.....!..!..8........8...O.....
i..O.<N.B....><N.B6.vS.....6.vS..............J.r......J.r..`.
....-..`..............H........H...QN_......QN_..............`m.......
`m...y_8....J.y_82.......a2...(.\.....M(.\....H........H._........_...
.M.....#..M.*x.......*x................u......<.u....v........v.n..
#.....n..#..t........t...............H........H...`im....?.`im...[....
....[.w......K.w...|.H...._.|.H=y.......=y..>........>....'.....
...'.....?....1...?..n-.......n-0(.p.....0(.pWZ.......WZ....0e....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/oB-hUus1Xvl_1EQENOruhBHfNyDrwfBHGVPnkkgwHvc=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 1246
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 01:10:45 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40218:4:1231.c........c....|......M(......R*......U...k...Z.*.\...Sz
.RK...Rn.x....Mba.2...T..j....L].,....Z....M........M....6........6...
.6.....^..l...._z......].d.~...].3.....]..U....^...@...^C..1...^..H..-
......,.-...c........c...0.............%)....|..%)...]........]..St...
....St..].....4..].7.(....._G..d...a.y.....`.F.J....eT.yTh.......Th..x
r.].....xr.]v.O(.....v.O(..............7o..........9y.......9y..~.....
...~....x......y.x..Y.......J$[.....K...w...K.u.....K...M...J..Q....J.
......J.%....X........X.4.\...../4.\.;_{3....4;_{3...2........2...j...
. ...j......../............].n.....5........5........4....Y........t..
...?.....c..?...aN....m..aN..4......,....."L....M.."L^.:......^.:....&
gt;....-...>...a........a...-........-.e........e...Y........Y....&
lt;#.......<#.............uWhE.....uWhE..............!#.....hM.....
..................k.1........a......S............=Y1.3...z....f.f"C...
..........g........g...K.O6.....K.O6.D.Q......D.Q........$......9.....
...9..v.x....?.......<..P}..B.....akGS'...........^y.. ....[......a
..:....^.......`dN;...._.ni....`.......^..8...._. Z`..._...d..._....k\
.......k\..n..\....-n..\h.......Eh......P........P.}........}...3J....
.3.3J.e~ x.....e~ x.............$.!^.....$.!^.c........c..9........9..
.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/Ly1fy95I4zNghg2731CfD358KsWzHvU85o0EXH2g6OQ=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 1895
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 00:10:32 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40217:4:1880....(........(1A.......1A....k>....V..k>........|.
....-........-..i/o......i/o...........T..........q....6..4....G6..4..
>........>.Y.........Q.......`NQ.*......v.*...us.......us..K.x..
..4.K.x...]........]I.......KI.... ........ ..........................
....7.....#..7.............................?B....4..?BNA......NNA..{..
......{...7.(....._.......`.HF[...`.......`..v...._-......`.......`.l.
3..._v..{...]...0............... ........ .........<....V.......2V.
..4.*......4.*.........^KO.....].."....^.L.....^..Jr...^.L.'...`..\...
.]. .$..._}?.|...a........aW........W...8.c......8.c............W..~3.
......~3.........K.....<.(......<.(...............?........?..Li
~....:.Li~..X......?..v.|......,.|....*........*.R..W....DR..Wo.m.....
.o.m...[........[..p#\....A.p#\...7........7..r!.......r!.*x.......*x.
..............|..(...Q.(.....RK..\...Z..[....[.U.....T6 .....T..A....N
.......TL.N....Y.o.Q...Z.......Y.......O`..z...Q..U....THE.....NXQ....
.R"..^...M's.....Q.~.....N(......N. .....Y.0./...Z.......QQ......X...Y
...Vo......OYT.....O\PW....\...m...R..T....T.:{....Y...|...O.......X..
.U...OK..C...Y.kE....WPC.....M?.CY...Y..]....U.......Vk.m...6.....`J.n
....`.r.....^.../..._<P...0......_p2....nW.......nW.a......p.a..Y..
.....J.......J.x ....K...]...J.1p....J*......K.1.p...K:6#.............
...n}.......n}jp......4jp..8Zyq.....8Zyq.(M.......(M.@[email protected]..
......s..S}D.....8S}D..............m.>q.....m.>qg"......"g"..p1E
......p1E.._`.....u._`.eIUe.....eIUe.p.m....5.p.m.............".5.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/6uQWqaT1RCGblQ4ZpLsL58bVvNhg6v7DD891bikH8qM=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 3299
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 22:40:31 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40216:4:3284.>........>.....^3.... ..^3........&.....X.m......
X.m:h.......:h.......................2.]......2.].Mtj.....qMtj. p.Q...
./ p.Qx.sG.....x.sG:..N....]:..N........).....Vh.......Vh....A....C...
AY........>ay..............DJ......hDJ.....T........T...=....e...=8
?......<8?..C........C.............$.*q........q...IR.1.....IR.1m..
A.....m..A7.......47....'.v......'.v..G:.......G:U..:.....U..:..).!...
_..J....].......].ij(...]...3...^-......^v.........v....^......._..xG.
..]Q..m...].......^g..|...^.^.)...].S.....].JM5...^...h...]'......^F..
A...]$mG....^:.,<...]...Y...^..QI..._..TH..._k..$..._.!.....^..'A..
.^......._h......]..<....^...&..._.`.'..._.3P....]......j........j.
...............6........6._..j....._..j/..i...../..i........0......x..
......x..s........s..7.(.....] ..c...`A......_.~.....]......._.{7....^
..Y....^..iY...a-N....._W......f....z...f..E.....q..E...A.....-..A....
$........$........^3....WD.......WD..1........1...z........z...]0.....
E._.....q....8...q........=............`.......T........T..X..........
.a.z......a.z...w........wF........F...Z........Z...g.._....gg.._ .-z.
.... .-zp.......Zp...........T..................|......X.......Y. \v..
.L.%`....Z.:H....M.......M.O.....X...L...W(......N.{.4...Y.[.....[y...
..D........D.~].......~]..........1......6.....]vK.....`..?....^8.N...
.]...6...].d.....]P..S..._..n....^hq.....].....{....../.{..Th.n....BTh
.n..s........s.xO.n.....xO.n..uh....x..uh}..G.....}..G.|.F....495.....
K....]...z.....~.\...]..1}^.G......^.G..Yi|......Yi|h^&.....~h^&.Y<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/LUeHOOMCOB-pQlzdlFGCbhZE9V9kaVRt04KOCVaJC4Y=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 1079
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 21:30:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40215:4:1064.............._..p....6...{...6#[~*..Dw.......Dw..w.....
...w...K........K.v........v...J........J...5z.......5z..J........J...
[email protected]...@[email protected]
........j...G.;......G.;VNry.....VNry.}.{......}.{.*.b....R.*.b.i.i...
...i.i.".a....'.".a..1.....0..1.?.......,?...-.I$.....-.I$]........]..
.K:?(....;K:?(.3........3...zt.....8.zt.y~.y....<y~.yhveB.....hveB5
b......-5b..5.......05......(........(..u........u....[....g...[.8T...
....8T.F~k.....EF~k....m........m........7......X........X.$YFz....p$Y
Fz`.d......`.d./.y9...../.y9..v........v.%........%...........q.......
.......Se..i........i...1.g......1.g\#.......\#.... ........ ...?.....
...?..O......).O..u........u......F....|...F.N#N....,.N#N..E........E.
r|.......r|................b* ......b* ..z6....8..z6V........V...~.X..
....~.X...f........f....w........w...U........Ujo6.......@.$..........
...o..x....bo..x...............&........&..$.!....$.$.!.B;.......B;...
.,........,..............D......0.D..h..r.....h..r"S.M....."S.M:......
.=:....../......../.6......G.6......
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/nsXHQXzYI3AuGyYkuMQgRG7dxGi0A5Al7OIum9R-hyE=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 7437
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 21:10:43 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40214:4:7422...%*.......%*...........w>....I~.S....r.h....n7.[...
...........R.Z.....OR.Z.&w......V&w..i.......`l.:....`.......b&T.F...]
.`E*...a.x.....a#..k..._..)...._.......].......^..$g...^..d....`.u.d..
.^...H...^f......]...{...`.a.^...^..v....`.7*....a.......b.?.G..._...O
..._..}....^.`.....^.z./...a|.%...._...G...a...n...`"..'...`j......b(.
.O..... x....`pv....._f..p...a4......`H......].......aiF._...__.^....^
.......`.Z....._..?....^..).....c,.....`... ...^...K...ad.~....]}.....
.an].....`.t.....^<......^..&...._.:m?...^.W.'...`.......`.<....
.aC9.....a.6.....].B.&...b..*K...a.......^_......_4......]...x..._nn&g
t;...._.......`pLA....`.b-...._.y3b...^..a....].`.....].......a%..{...
`%0.O...........a.Hh....].ls....^...=...`.......^...b...^.8.V...`.r...
..].Z.3...a..v....bfGu....^.Nh...._GMn)...^;......a3.J....].^.....^.E.
N...b..._...^...w...].......^.lS....a..!...._..1G...`'......^.hX0...]%
......^#0.@...^..A.....n..#...b..<....a. .....^.LUO...b........m..&
lt;...a.z^....b.0....._.H.j....`<.....^>......]......._.L~b...].
.*[email protected]'...]......._h......ab..^...`Ru.....^..n)...
`.......].h ....`c......a3g.....^......._.......].2.c...`.(U...._;%...
..`%..s...`..ut...bL......_..4?...]*V{....bu.t....^..LA...`...]...a...
....`.s2....]..z.....%Hf....].Rn]...a4......_...t...]...U..._SSl....^.
]b....^.......`.......bA......]y......^.12 ..._V0.[...a.g.....a.`.f...
`.3|....`Q.bz....q-.....a.......`H.?r..._w..q...a'Q.....^..:=..._.....
.._8......^.......`.||...._.$.-...`..Q....`.Z.....^.......`.......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/uvvnQK5OYRoXYoWaTdJwqggbRc-DJ2gBOcXBNFFsliI=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 10374
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 19:00:50 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40213:4:10358.'yZ>.....'yZ>>~....../>~...........G F....
.cx...!.n....J.2.....J.'..i.......^...[...abp)...._.mcX...b:..!...]...
.....{).....`X.qC.dQU......dQU.9;.......9;.e........e....|......U.....
..[.[.....Z..Z....M..-....T..qQ...S]u.9...O.L.>...Lq..W...R.\. ...M
5......P.K.E...Vy..0...P.z.....\A{.....M.zq....X.......LU.]r...Z#.*...
.X...s...[SW.3...T.=..........r....M........M.... .Y...... .Y.i.:....{
.i.:p.g.....<p.g.X:.N.....X:.N.w.c......w.ccw<......cw<.'....
...&'...3_.D.....3_.D.(......).(....^........^.J..G....]4.D....^@j....
.aQ......]M3.....]Fj.....^.M.....^......._H9.....^[C#....]......._..x.
..._.%.....^.2.....].e.....]N9.....`4......`8..R..._...^...a.}@...._..
.y...ak......``......b..."..._;g.....].......`...X...]..(....`..N....^
.H.....]S.b....^. .....^<..v..._...?..._.5C....b...*..._Xjn....]4..
....].Z6$..._8......_.c.....]n..#...a..W....].......bw..;...]v.4....^.
..#.0......`b,..hEUr.....hEUrhl.......hl..!..V....}!..V..S........S.rM
*......rM*....Z........Z........r......I........I....!........!...s...
.....s..g........g....*........*...............>.....&..>.7.(...
.._. ....._.[.-..._.O.....a..|....^.m.....]!..!...a...%...`V($....^k..
....`......._o.e....a.?.....`f......_..\H...a../....^.......`O(t......
........l../.....l../.8........8..(f|......(f|..5b.......5b..B^ ....c.
B^ ...%........%(%F......(%F.........a......._P<.....].......`f....
..`.1.....]5..]..._(9....._.......]...l...`vd7...._.......]]......`..-
....]l......`_.X...._.#.....`W-j]...].}.K...`.......^......._tD=..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/qrBdq_vzXiEdm9iLCIY8GNMEvsBCJGveNQ3YWTzJMIM=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 2365
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 17:20:58 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40212:4:2350..".R......".R..4>.......4>.............i.......b.
<Jd.PlL......PlL..........7J......=......*......ez......q......]...
..)..].M.U......M.U..$A.......$A..f......\.k..:.o.....]:.o..>......
#.>....*........*...,?.......,?x........x...Z.<.............U...
.P...Ut..i.....t..i.r........r...co$......co$.yO.....i.yO.ILY......ILY
.Ip.......Ip..qZ.......qZ.....`....z...`..".....c..".eYl......eYl..y..
......y..:. ......:. ...c........c....E........E..#A.......#A...r....q
...r..............Eg.......Eg....!....)...!..b.....]..b..............|
.b.....'|.b..(........(..f..l.... f..li5.~.....i5.~...z....<...z..&
.....-..&.........P......F.....p..F.t........t..."".......""..p.F.....
.p.F....f....r...f...............&........&...!\....C..!\........x....
..uo....9..uo...T....{...Tq.......fq...tL.w....{tL.w...h........h..n..
[email protected][email protected]
.................. q....9.. q...;........;.6........6...n.......X..L..
..j..g....sbC.8..y....<8..y@........@....|........|...`......|.`..Q
|=......Q|=..5.}....%.5.}........c.....Hil......Hil.'........'...h....
....h..2R.|.....2R.|.............f.......-f...v.!......v.!............
...w........w....k5.......k5.|......S}......Z.......R&.M....R..}....M.
..t...N..)....N.......V.......@....;...@... .... ...%..5........5._xA^
....K_xA^IQ.......IQ.................]9....-..]9ZC.......ZC...r. ....-
.r. ..^.....q..^. ..l..... ..l..............6t.......6t.G.J.....wG.J..
.............(........(..fV.......fV..&..........Iv..$0.......$0_H<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/i5G2FM8_tLEjfy7aO0N4kmHdYf7-_pBv3JkZPz8emiA=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 957
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 15:50:34 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40211:4:943............................|......Q.iN....L...V...WCrMJ.
..U.......X}.h}...T..z....L.).....P.}...........a'.F..n .......n P1...
...;P1....6.....`.6......%.|....]^.................c........c.........
..<..\...7........7........'....5.7......5.7..B......>.B........
........._........_.........}......`........`..F......&.F...-e.....).-
e.Y........{\5.... ........ =R.......=R.....'....b...'..HR....E..HR..]
........]..\........\.../r......./r...RW....C..P..sMb......sMbY.......
....................f........f.........$.....o).....,.o)..............
.#L*......#L*96]!....&96]!..'.....x..'..).3....$....2Y.......2Y.......
[email protected][email protected].............
................x.D......x.D.. .z...... .z.J.Y......J.Y."G]......"G]..
Q>.......Q>l..7.....l..7..)....."..)..Tib......Tib.v.x.....'....
Y......).Y................m......q.m.....t....)...tg........g...S.k...
....9S....{........{l/a_.....l/a_H......."H...C.:......C.:.HTTP/1.1 20
0 OK..Server: nginx/1.6.2..Date: Fri, 01 May 2015 04:21:33 GMT..Conten
t-Type: application/octet-stream..Content-Length: 1700..Connection: ke
ep-alive..Last-Modified: Thu, 30 Apr 2015 15:10:36 GMT..Expires: Thu,
31 Dec 2037 23:55:55 GMT..Cache-Control: max-age=315360000..Strict-Tra
nsport-Security: max-age=3600; includeSubDomains..Accept-Ranges: bytes
..s:40210:4:1685.P%.^....)P%.^...:........:........q......RW.....5....
}(.......}(...............z*..... .z*..5.^....$.5.^..x.....-..x.Y.....
....".0..NQ...."..NQ........%......6.....`%t.y...].9X~..._.......x<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/QDOtk_76wVL3jPoaZs27-7533knjsMtnCdangZmx1Wo=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 1389
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 13:30:32 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40209:4:1374.{.8.....H{.8.2/.......2/...=........=...............e&l
t;Y......e<Y.........._.....m........m...Aq.....b6k..f......0.f....
......k.....X........X....c.....0..c.{.2;.....{.2;.. ........ ...)h...
....)h7/:......7/:...&J.......&J..l.....7..l................*.....q..*
..^........^..5.=......5.=.y..L.....y..L..T........T.R.$N....(R.$N..'.
....~..'.'........'...........C...................Y.....x..Y...u......
..u.B.Y,.....B.Y,.............,f......),f...wu.......wu.Q........Q...\
.. ....1\.. l..p.....l..p(.Y......(.Y.Z........Z...m.......5m...@.....
...@...$.......f$...B.......jB.....OS.......OS..P<.......P<M....
....M......a........a..j........j.e.W......e.W..VW.......VW.F@-......F
@-..]......<.]....XU.......XU`........`.../.y9....0/.y9OE.......OE.
....-..../...-S.Gl.....S.Gl7........7...q`f......q`f..6s.......6s.....
.....).T?Z._......Z._.y..C.....y..C........1.....].3......].3.Iw[....u
.Iw[X.9......X.9.G........G.....<.....5..<.S .'.....S .'_..p....
[email protected]..=A...1.5N....6.......6q.0.,.......n,....7.q
....".7.q.2.W......2.W..........................>i.U....o>i.U#,.
u....'#,.uQr.......Qr..T........T..................[.....$..[.>....
...">.....M.....$..M..............)cKE....5)cKE.C .......C ...!....
....!.A.}.....;A.}[email protected][email protected]............
...C.....M..C.#[email protected]#.@....{........{........l.....m........m..;.u.
....!;.u.&........&.......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/RoD_pMkmy2GVGX7YHD_unqfRObz58DE9_WPrAZIRyVA=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 3273
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 13:10:32 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40208:4:3258.............."#.C....."#.CZ..J.....Z..J.|......O-?E....
[email protected].........*.d.R.\~....nR.\~..!........!..f........f...H...
...;.H..,....... ,...[)CS.....[)CS..............`......).`..i**..... i
**.)..\.....)..\..!S....)..!S..o........o..!.n....J.u.J...J..._Y......
.._e.c{.......){......r........r.o6.....ao..f...a..M....].].Y...`R.X..
..`y......a.GV....]...|...`A.Z!...].*.'...`_.......%......_...F...]0.1
....].".:..._v..$..._.......].1<....]..B...._..q....aO..0..._:.....
.]24.F...a..>{..._nZ.....]m.3F...]pvC...._.tT....]SA.p...]...g...`.
......^"w.....a%......]=..q...`..._...`.g.....^.3y....]1.V....]...W...
_.{.0...].iF=...^E..:....-|.....` Cn....`p......a..z....a.h7v...`Xr...
.._.......`.......^......._bM.,...]"y.....`.......]$......`.,....._...
......).T...]/b.....a.......^..w....^.=.....^.{.....`.p.....`......._.
JF-...].r.....`jR.....a.K.=...^U......_ ......_.,A....]".T....`...F...
].r.....`M..|...^..*9...a/T.....`n.......$.g....^...M...`...s...^?.I..
..`#.~6...^.m[....`..E....`.`.K....~......_.0....._:>N....__..L....
..e!...`._)5...`...!...`.......`3..v......*:...^z(....._X`.....`,..o..
.`..e....`..s^...a].j......?.!..._~K.....`.Z.....^.i......T..8...^~..#
...^.3?"...a..3...._*......`...h....-ZuF...].~.J..._.Fe....^.O....._..
)Q..._K[.>...].......^.i.....a..0....`..dc...`.......`.x.6...`.....
..`:n=....ay./...._.`8-...^.......`..d....`.'....._.m.n...]O.*....^..Q
p..._Z......`.*'...._PQ....._@V....._U.K@...^..{....`?K?....a.G.....^.
.;.......|'...a.......]...X....b!.~...a.y}....]...Z...`...g...]...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/34hObcShEQV4s6ck7ExkGQwcoXdmdgRIKIqoNG8qAkc=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 2391
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 12:10:25 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40207:4:[email protected][email protected]|;.9.
.......9...O........O....zx....g..zx........q.................r ......
.r [email protected]..@..,........,.... ....R... .v7.....q.v7.
.e.1......e.1n}W.....<n}W.7.(.....]L.M^..._Z#.....`...}.r........r.
.S.{.....XS.{.~*......I~*.....I....r...I.kf.....:.kf.........p......&l
t;........<...Yf....)..YfH.......rH.....Wv.......Wv`.w.....q`.w._&l
t;E%....p_<E%.-O.....Z.-O..n....... [email protected].'P...E p/{...E..1 ...E
b.DF...C..AF...C.T.....C...4...C.=.....C...{..&.....q..&..............
9........9...."........"....W........W....u........u)`9H.....)`9H...;.
.......;..............|......Z..5%...[.a.....Y.2{....P9.x....O..Z...t8
....!..t8..6......#.......d.............):....4..):........G.....g.Z..
..'.g.Z..............|.F....)[email protected]..)........)....
....U..J.......kr...t........t........r.................vD......TvD..
j.......Lj....).3....qt/..........,....~/.P....v~/.P6.tf....x6.tfM7#6.
....M7#6X..N.....X..N,@.K.....,@.K.,&i......,&i! .q.....! .q_N......2_
N..w4.:.....%........l)6.....t.c.......E...C...3...C.D&b...C.C.&....9r
.....Cc.w#.......v...........C.Y...............e}...P........P.S.k....
..L.............h........h...{........{..&........&.....i..../...i.c..
....&.c......m..._.......`cZg....`..O....]...K...^.5.w..._..fK..._9B..
...`......._...b...`......._..Uj...`81.....]e..G..._..B....`......._0.
i.......9...._.gGJ...]|9s...._..$...._...J.......}...`.N.G...`Y}.5..._
.'.n..._.=.,...`Ry.1...].[........a....].b'....`.,?G.....4:...._I`<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/lDCWU4HFh7141Gk4nPtxKfqUBMi3DgioCNmziSQFSAY=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 907
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 10:40:37 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40206:4:893._..p....1.......1wgA....1.......1..0..i^.......i^...Ks..
.....Ks.V.M....K.V.M.Y........Y............q.....<1.U.)X{......)X{.
..o........o....!.... ...!................c........c..Nz.......Nz.7o..
...........K......L'.....V.\..P......-.P.../wb....../wb.|.F....)..s...
.-..{....z....r\O,...A0.......A0R.xl.....R.xl!h......)!h..............
..=.#......=.#Y......../{....n........n.0.......u0....C......).C..&...
[email protected]@..?.....U..?....S.....
...S...=........=.]M.......]M.'......./'......E........E..~M....)..~MS
Er......SEr..AXg......AXg'.G......'.G....S....L.L1....................
........f........f....~.....E..~..\........\..y........y.....{........
{.a.......La...k.......Vk..... {....... {b..3.....b..3mHdt.....mHdt.@.
[email protected]..}.p......}.p.0.Ca.....0.Ca.u!}....x.u!}.. .....
z.. .........)....3.......D3...%P.......%P...#........#...............
....
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/AML77lIHrfObviL_zBFRuLttbdLev1tq5-ORUTccdyA=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 3474
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 09:50:32 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40205:4:3459.i.......b...o....N.-....a;.C...._..o)...^. x.......ok..
.]..:.....|'...0............l........l................i........i..k..v
.....k..v..RW..............q.....F..l.Y.......J{.t.......,z..`.....~..
`.>pg......>pg..|......C.P>....C p.....C.}3....C.......C.e...
..C..1....C[..]...C..3q...C.v.....C{j.....C <P....C.7-....C. #....C
N_L?...C..i&...C.Q.....C...s...C0;o^cgp;.....cgp;.2......v.2..2;Ig....
^:<.....^......._.-.....]D.?;...^eG>]...^.......`[. /......kp...
`..e....a.j.X...`...3....tY.....`[`....._..s....a..Lw...^>.gM...`pq
.....^.#{s...]Q.......K)2,...`......._gJ.....]y.e\..._.o.2....u..0...`
...O...^.V.N...ac).D...a.F.....^...L...^.3.............a..*....^......
..........G_)....`M!......>.......S......]K..S...^.......a...d...a.
$....._..]X...`.. ....`E.v....`..U5...^7.Jn...^..:....]......._.......
].!.;...........^~..U...^..VI...a..pu...aL\.J.......\......=...._.1...
.._.......]k......a].=........t...a..5....].V.....]ph.....^.M.....`...
E..._.Q.....].'.....].f.....`...s...a#!....._........).c_..._..Ar...ay
........`.....`.".......H.....a..~....a........ Sh:..........._.......
`...5...]..o....]......._...............^......._.e)....^......._M....
..`...5...]...]...^.......a.5.....`.nf...._...F...^.......`.......`..-
'...^4Dk*...a.......^g.?....^...9.......C..._......._..eo...a..J...._M
1g........G..._...[..........._.t....._.......^........t.UD...]...!...
]@.t.....t.Q....]TP.....].L.....`... ..._..-...._F......^c$_....._.G~.
.._..:....]c.5L...`..50...^...i...^n......_~......]P.......^......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/l0NbfG_xC03kXPH0E5TtymYBrP3rti1X7kASdMQdDBc=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 7618
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 09:30:50 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40204:4:7603.f..;....:f..;.{......,.{..[.......&[............=......
.nk......M'.X........]....&..H.....^................n.Ub....-n.Ub..$..
[email protected]..@.~........~...h.V_....]...,..._UoO...._.2F....`.$.
[email protected]}....`.0#O...`.......^b..a...]. .5...` J9....a.
Na....bq.($..._*.T...._..f...._.......^..S....`R=....._.........f.....
]Q..,...a..Zc..._q c ...a.......^._.-...a..tn...]......._.......]Fg.9.
.._.......].i.P...]..9...._._.....a.......^..}....].......]ZZq....`.B.
$..._.......aS<x....^$V1...._5..P..._.u.}...^k.m....]..=....a......
.]...$...aJ]L5.....o;!...`..H....`.B....._s......]H`.6...a.h`....a.B..
...b..6....]lCD....a...1...a.{3....]~N;....^.U.....aH.$_...a-()....aIk
.....a ..]...^[email protected].......]G......`r......_p._N...]..eT...^
}X L..._.|.....b*.)....b..x....^fW.Y.....lF....aa......^..u|...^.(....
.`?.q...._45....._}......_.W/....a.......bIX.....^...D...b...h...]...v
...].!21...].B.E...].Ro....aIh.....].p.....^l .....]3f.....a...Z...^.h
Q....^.5.....`})E$...a.9.....a...A...`.(.^...].v.-...]#../..._.0.....^
.N....._..pz...a......._.......a..U....a ......]F. ....`.M.....]..;...
.^o^k....]~..:...^}......^......._.H.-...`G}.....as.d....`...b...]-.s.
...^..p....`.Y.w...].F.^...`..}....a..\....b......._.s!....a$......`q.
.....ai.S}...].......a.&.G...^...p..._.>.w...]H..B...^.p.....^(..P.
..^......._..b...._9......a.~D....].i;S...`.;.z...]..0....`.......a.*.
,...].......a.J.B...]..g ...a...|...^.......a^......a..W...._...e...^9
."D...]..D....`.~z....]./.....^.e.....`.uM...._..y4.... ......a.Kd<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/XJS8JhoQCLrHvoi2N1Ve_rg1LE7dFSX2zXDYKWc9FXQ=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 4457
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 09:00:48 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40203:4:4442.........'.....5........5..p5y.....'p5y...:-....y..:-.P.
v......P.v./......e./.......................q.8...m#`....z.m#`........
.......M.....(..M...U........U...{g....N..{g...v........v.............
.............%..^......&. .....-...NZ.....N.NZ.N..O.....N..O...3......
..3..0.....#..0....*........*9eH..... 9eH.#2P.....*#2P..D......).D...5
[email protected]@To......FTo..4........4...........#....2;Ig.....$.'....`X..
......=......'.|...............Y{...a2.........}.......JP.....(.....a.
.t.......H.....W.Wv....R.uE.0...............Yi. ...`.........<.n...
a.N....._...i...^<......^.d.e....Ce...?........?..9d......i9d...v.A
....].v.A^........^.....^K.......^K.o&.......o&...s........s...=]....(
..=]1.......M1...........2....v........v......y........yzc6.....>zc
6..(........(...U .......U ..h........h..........{.....A~.......A~.(..
s.....(..s.~......M.~..<..h.....<..h7.(....._=,.....]-..{...]eT.
y........ ....h.V_....].......].qW....^:&.x...`.N....._CZ.s..._o6.c...
].w!....^.OO....^i..%...`r7.....`.......^`.k....]...7...]e]0j.....T"..
..^..."...`.I.^...^.G.......,.....]...d...`q......^..4q..._...'...`...
....aL../...`...S...a^.X}....Y..[...`y....(........(....*........*..hg
.....).hg..4.o....".4.o...A........A{.C......{.C..!.n.......!.....L.j.
......._..>.....s..>...RW....D..DQ.F.[......F.[..9>....R..9&g
t;;v5......;v5....<........<...I....>...IY.........#.B....}`.
....J9.u.|........|...86.......86..>..p....,>..p.............[l.
......[l................}W.......}W..n......C............-........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/Y7Bbdz8_yw6v_bqO-aA6L91DCfbRovNLkVFMxneEoig=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 10839
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 06:01:23 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40202:4:10823.4h;p....$4h;p.0......`.XU/....u9............:.......)l
F.0.?....6.5..{........{....$.5......$.5._V ......_V \..:.....\..:....
....3..<....qh..m...........r2Z......&l..4..%.....4..%.............
.|.8......|.8..!..... ..!...RW....EN......C..}....DP.....'4.......'4lc
,......lc,.<. ......<. ..| .......| ...=.....8..=..7-f......7-fO
u.......Ou..).._.....).._.;........;..J!.W.....J!.WY.........4........
.......T........T...6.......p6....'n.......'n.........................
.....K........Kt.m.....'t.m..m........m...M......M.M..2;Ig....^.mUV...
`.Ea....`\b3t..._.......^...Y...^.H.....^.;O.t. ......t. ...3........3
..............G.......cG...;4;J....*;4;J.hb"....X.hb".'........'....k.
.......k....R....$...RF..x.....F..x.Z. ......Z. ................I....W
...I!.3.....&!.3..0.0....4.0.0.i.K......i.K.f.C......f.C..-........-.b
........b....y........y..7.K......7.K..............I.......nI...s;\\..
...s;\\i.......vi....'........'..~..Q.....~..Qk........k...........b..
...[B.....q.[B.X..5.....X..5.<........<..z.i4....6r.Ka..a.......
.a...w-.......w-7.(.....`...b..._.0.6,(.......,(....l.....L..l...*....
....*.b..j....!b..j.'........'.....X........XWt..........J.-o.......-o
.$........$....oY.......oY.%.......,%....!.n....JRP.-...J..I....J..eU.
..J...$...J...6..pn....i..pn2.......#2....c........c...E......u.E..f..
...../f...=........=....U.b......U.b.^........^...WB%......WB%a.......
.a....H.{......H.{..............,R~......,R~3N......v3N...............
d.[......d.[...]........]....Z....;...ZD.......(D...........,q'...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/vkJyaujmHBeBaeLUaJI7i6fATIaUv4Yw7YdKiZ5VZDg=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 15829
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 04:01:38 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40201:4:15813...Xp....4..XpV..}.....V..}.0......]...........[.......
.;.........n...........8RQ......8RQ'..s....&'..sT~G.....^c .....]3g.X.
..^..K....^.L.....^...e...^k.l....^.......].9.....].......^|..g...^...
W...]0.&W...].).....].......^..e....]5yD....]7.,....^.Dq....]{..[...],
f.....^.......^.t.....^C......]Wo.....].^.....^.......^.R."...]u#' ...
].......^.......].P.:...].Q.....].2gv...^.......].wY^...]A..@...]aW...
..^$.K....].-.....]=......^.e2....].......]Q.V....].......^..M....]..L
w...^...#...^j......^R......^.#)....]Th.=...]{>.....^.......].dH<
;...^s......]..p....^.......^.......^..\\...^D......^.D.....^j..1...^.
S.e...^..x$...^..m....][email protected]...].i.....]..6t...].......^J0b....^...p...
]..,*...].......]w>.....]?i.....^..x....^a.B....]p......].......]z*
.....].[=....]r......^.{.f...].%.....^.0.....]...4...].......]1.-....^
[..6...^_n.....^.......].......^.YB6...]../....].......]...f...]#1....
.].......]..>h...]>..$...].......^@-.....]Iy/E...].[.o...^......
.^p.R....]...;...^...>...]8:.....^7..\...^.......].Au....]..N....^.
{.7...]...g...],i."...].`.Z...^]......]E.C....^..Lg...^.Ri....]#......
^...D...].>Tq...^.7.....] ......]./.....^.......].......^.......^D.
.....]&.R....]..WW...^..[r...^.......]h......]\."....]Z.5!...^(.vw...^
v......].......]Gl.....].......^.......^.'.....^..|(...]SJW@...]u.....
.^,V.....^.......]_.w....^.......].e.....^3......]hYs....^JG(....^=...
...]g.|<...]l>.....]b.5X...].k.....^?.;`...]...5...].[."...]..C.
...^..h....^..9u...].tV....^.DC....^.%.....^.K]#...^.Pe....]".....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/vOZ7hV0kxCKHMixiB5_zjy6_Yc9TGBNyvnbfCylFdHo=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 15419
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 01:50:53 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40200:4:15403.....................#.?xK......?xKT~G.....]...~...]%.a
H...]U......^4bX\.ik.......ik...dA.......dA.........#.w!...........s..
......sr.%y.....r.%yD.>......D.>..|.!....>.|.!Y.......9U.....
.....,4.}.....;4.}..br.....].br.e".......e"..2;Ig....`.K....._......._
O......`0......];..b...^.......a`......^5. 1..._.K....._97F`...^&~.3..
.],Y.Q..._$.=.$........$......P........P`........`.....[n.......[n3CG.
.....3CG...Q{.......Q{..m'....a...g...`.i.....`.y.I...]zn.`...]_x>.
...].......]D......`s..'...`..X....].;/......%w^...`.......`..O`...a..
.a...`...,...b.u?....`.Tg...._.......].......biz.....^wb....._3......^
.P.....].`.....a.0t....a..F0..._.f.e...`CeG....]...,...^...y..._lv.W..
.]......._%......_r.~c...a...C...]R......^...Q...]...:...a.......a\..j
...`x..,...^..&....^...............^.nf...._.yn....].^....._.......`!.
.....]q..C...^...h...`.......^|..n...a..rx..._x./b...a.v.....`Tv....._
.%.....a.-....._..2....].o.............a..|...._;......a..Q....`......
.a...[..._..3....^.H.Y...^08.(...b$ .....`z?.....].-....._9esc...`.R.;
...^......._.......`.:....... .....`...k...a.V.....^9......^L.$...._.H
.....a.......a{..)...b..|C..._.......]..{....].x.....^.EWa...]1.6....`
. .....a(Z.>...........b604d...a........O..W...].......]U.@P...^.3.
...._......._o.b....]v$.....a.......a.?....._..C....a...T...^V......`i
......`.L.....a6.t....]......._f9p"...^._!...._G......_..g....a.Bk1...
aNC.....a...s...^...#...a`>,x...]..O9...a3]......L~.i...a.O.....^Y.
.....]`..H..._... ...^.......a...Q..._K]h............a.......^E...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/fUN4SJ-LG6yrIjmJB2RL0iC2b3UdNzVs5BMan6CE2JQ=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 24773
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 01:00:55 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40199:4:24757.t.X......t.X...*.....=..*..Fm.....-.Fm..).S......).S..
......J................................RW....E.rR....D.s.g...D..b.A.H.
....-A.H.498 .....498 ..,o.......,o~.......t~...o.-.....go.-.D..V.....
D..V.qnI......qnI...?........?I.xU.....I.xU........>.....B......<
;.B...x.|....G.x.|2;Ig....`...1..._..J2..._.KY....a[}~....a{PA....^...
B...]..K....]O......`.../...|....#...||........|....x.D......x.D\.....
...\...".,%.....".,%...Z........Z..m'.......................pjo.......
q.....Q.-.....^32I...;........;...]........]w.'?..../w.'?..]s.......]s
.. ........ .KpN......KpN...J........J..5......c.5.................W..
......W...D.....W..D.Qy......eQy...I.J......I.J%........%.............
...........;......E.....$..E....|........|R./H....rR./H........_...a.!
.n....J.M$....J.08....J..7.L.......LL...c*;#.....c*;#.h;_....e.......e
M......b4.*....t.......x.&P ...lw..U...oe..G...t.......sO.0....t......
.u.m.....i|......l7.] ...e.`;....a]0BO...o4cT....dM......p'K.....o.:..
...u6q.....]..N....o.Y.....u.i.....w6......uq.;U...f.4X....b..G....v.&
.....q?......m6.5q...]dJK....ca......r..%s...s.......d!......_.......u
...v...c., ,...`KX.6...v.|[email protected]%d...k.>.
....`u..$...n...v..._.......pND.....c.t.S...r .X....it|.....dV..K...fN
..s...r}!F....`v.s"...p...j...hVj.o...t..IQ...b.......`.t.....w.......
rh......f.g1%..._..P....t..f....s.!4....g.!.....g.......j.......c.(...
..^!......^. .....b.$.T...ea..8...q.......t.|F....`.d.p...ejO.....].5.
#...h%P.....aU.g....su.QL...u..O-...k.X.....b......._...D...a.....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/deP2PoX_aw5M32dEb99aAA1JFdH-yfSXVmSwGI6sQew=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 26327
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 00:10:54 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40198:4:26311....*........*.K;.......K;.........:@.Y.......1....CK..
\...<_!...1......t.1..........-.....W\$......W\$T~G.....].:{F...^H.
$....^.......]i....`.~......`.~..........................=nM...iA..q..
.s{...........,......Y........Y.z1......Lz1...m.p..../.XX..-[.......-[
................b........b..........05^.j..-....qj..-.................
....D............,....`B......C._.....E..1....Ed......E.......D.#]....
E.).....E.......FNX<....E.u.....Cwl,....E...b...D...l...C0.L0...C..
w....EE.9u...C.A.E...D...w...E.C2....E.rY-...E.8,....E}......F...R...C
.=.....Di......ET=.....F8.`....C.b.....E.......D...z...C..H....Dc.T...
[email protected]$.._...D.(.....D..4....D.......D...c
...C!......F?.\....E.......C.B.....D.Fb....Fq .....C.|4....D...h...F.7
|....D2..|...E?......E.z.....E.B.q...C.t.....F.w.....E.'.s...Cc.I....D
.YF....Dt......F.......E.@S}...D.YA....F..#....D<b.....C.m}....F..n
....D.......E...}...D .MD...D.......E.......C.......DNZ.{...E?......D.
t.....E.}.....CY..k...D.......D.......E.=G....D\.I....E\.&....EQXLX...
C..<....C...6...C..]X...F..,@...D.......C..!....E0..#...F].9j...D6.
.....C.H.f...C...-...F...s...C.G.`...D(>:k...C...3...E.......F..u..
..E.......D7.d....E..0t...C.......F..4A...F%......DQw.D...C..:....E...
....E ......F[}.....F.o.:...Fs......C.C.....Da......C.,.!...F.......Cm
T._...E!......DJHQ....D?......F.......E.2/,...E.......E.......F.......
D...C...D%......C{.Fl...D.J7....D.I9....C.......DG.n....E.-|....E.....
..DC......D..2....E.......F'.p....E.;Q....D.......C"[email protected].....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-malware-shavar/BewhhbJykgB1ha8-WMrSewfQIiANmgIGXucGjsl33Ks=.chunk HTTP/1.1
Host: cache-kiev11.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Content-Type: application/octet-stream
Content-Length: 70189
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 19:01:03 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:40195:4:70173..k8f....][email protected].$n....&y.$n......... D(..hvA......hvA.!
.n....J1.:....N^.]a...T........TT~G.....^.......].1.....^pn.....]...o.
..]..S.)("X....W)("X}..7.....}..7.Ei.......Ei..........t.. <.......
].......`.......`.Uu....^...~...`.F....._}Ms{...^.......`.RMG...a.Z...
..`...1..._.OBT...]s.C ...a>s}....^...E...`!pk....aN......``......]
...n...] .g....]...*...]...q..._.3.....^.......]c"s....^.x.)..._..#...
._.8.....^.......]$..g...`.r....._.......^.aDA...` l.....`.J.....]....
...`..3....^.Qe`...a..Y....a.".....^.x.~...a.......^.!.s..._.......^..
_...._.x.....]u.C....].)A9...`...o...^x.%....].<.....][.jx...^.....
..`0......_vP{....]...<..._.......^C......_...?...`...P...^e.:}...]
.-T....].rw....].2.....`...p...^x y....a.......^..z....aiQ.\...au.!/..
.^f(.....`...7...^.......^[.&...._..8....`..$;...`.t.....]..]S...]....
...a..Ev..._..8....`......._Q..i..._.#Cu...^l.{...._{$.....`3......`a!
.....`.......a.).....].j_....^.......a.......].3.....`E#&....`.e.....a
Q......]..q....^oqc....`.}.^...^E.1...._..8....a.i.2..._..b=...^/.....
._$4.....a.......a8@.~..._...P...^.......^.0.....].......af@`....`POHE
...]_.'?..._.e.7...]..w9...^...8...]..<....al......a.......]!1.p...
_.v.=...^CR....._..3....].jt....]......._.......^...#...aO5....._..d|.
..].Z:T...`...H...aJU.....^g.I....^.'o....]c.p)...^).0....]......._.^%
6...`.Kf0...^z.1f...`Nhp....`.}....._t.d....a.2....._'......]/K.....`.
......_..h....`.2.....`5U.h...`9.$....][email protected]....]...F...]O.E....
_...4..._.......^F.)2...`..$....`<`z\...^Fo.S...^.......]!0....<<< skipped >>>
GET /chunks/goog-malware-shavar/deP2PoX_aw5M32dEb99aAA1JFdH-yfSXVmSwGI6sQew=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/deP2PoX_aw5M32dEb99aAA1JFdH-yfSXVmSwGI6sQew=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /icons/product_logo_128.png HTTP/1.1
User-Agent: Game installer
Host: customisations.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:03 GMT
Content-Type: image/png
Content-Length: 24082
Last-Modified: Wed, 02 Oct 2013 08:03:29 GMT
Connection: keep-alive
ETag: "524bd351-5e12"
Accept-Ranges: bytes.PNG........IHDR..............>a.....pHYs...#...#.x.?v...OiCCPPhoto
shop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE......
.....Q,......!.........{.k........>...........H3Q5...B..........@..
$p....d!s.#...~<< ".....x.....M..0.....B.\[email protected]..@F.
...&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWf
H.............0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(
.I. [email protected]..._-...."[email protected]~..,/..
.;..m..%..h^[email protected].~<<E.........J.B[a.W}.g._.W.l.~<
;......$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,
..>.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..
?....D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/[email protected]..=
p..a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2
....G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,.
.c.."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b2
1.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!
.[[email protected].(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i.
.t.....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....
J.&..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.
._... .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....)
.)..4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....
Dw.n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC][email protected].
.....<..F.F..i.\.$.m.m..&.&!&KM...<<< skipped >>>
GET /chunks/goog-malware-shavar/cjyIJrK5F9M1n9xrACpzp-cw6OzC-MNqeGjrqaNgpCY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/cjyIJrK5F9M1n9xrACpzp-cw6OzC-MNqeGjrqaNgpCY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/CZ1HgPkzCwCBxfRKtpfyV_KRZan4m07k2DINWshHBs8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/CZ1HgPkzCwCBxfRKtpfyV_KRZan4m07k2DINWshHBs8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/p8jCP90AhLl5ufYMynxaluNFR688R-dqD2Twp15_Jiw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/p8jCP90AhLl5ufYMynxaluNFR688R-dqD2Twp15_Jiw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/qMClo-a6ikkoEk0PRMBOLlihKTwko6nmtbIePa4G6cE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/qMClo-a6ikkoEk0PRMBOLlihKTwko6nmtbIePa4G6cE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/fpYzgXlcgfr6ZD20Y8IItWMOIOC8C-p4aRguqTU9Ojc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/fpYzgXlcgfr6ZD20Y8IItWMOIOC8C-p4aRguqTU9Ojc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/mMTuPD16d8c2k64LffvorHqu_-6USXYtJeOhBI7MOOs=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/mMTuPD16d8c2k64LffvorHqu_-6USXYtJeOhBI7MOOs=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/pqIY_e0O3hSWRoJAeaHMgDfMFzzIEueabEuZVNkuFCQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/pqIY_e0O3hSWRoJAeaHMgDfMFzzIEueabEuZVNkuFCQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1762
content-transfer-encoding: binary
Cache-Control: max-age=594093, public, no-transform, must-revalidate
Last-Modified: Fri, 1 May 2015 01:20:24 GMT
Expires: Fri, 8 May 2015 01:20:24 GMT
Date: Fri, 01 May 2015 04:22:47 GMT
Connection: keep-alive0..........0..... .....0......0...0......;O}a.!..u...au..eUNp..2015050
1012024Z0s0q0I0... ...................B.>.I.$&.....e......0..C9...3
13..R...%V.......K3.....20150501012024Z....20150508012024Z0...*.H.....
........EF.........k......>}-.1C....|.....*..?.f,([.....2....yh..&.
..ez.g...v.e._<e..U..../...2....=-i...%.m.X../.....c......s...p..~B
...oB....j#Z.D..i.I2........ M..M>.d...-.l..G.L@?.xkP...(I.........
....].r.?b&b=...6M....d..............!x.|j....6ux..@.{7.lM6........0..
.0...0...........2...'U.BM...g.B0...*.H........0..1.0...U....US1.0...U
....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006
VeriSign, Inc. - For authorized use only1E0C..U...<VeriSign Class
3 Public Primary Certification Authority - G50...141202000000Z..151216
235959Z0..1.0...U....US1.0...U....Symantec Corporation1.0...U....Syman
tec Trust Network1?0=..U...6Symantec Class 3 PCA - G5 OCSP Responder C
ertificate 30.."0...*.H.............0...............2&..PL...,..2....:
..tH...`JG.%..*...s.c%[email protected]"1.5?..
s.....3[...u......]...R0..Z}....l..I.Y.....j\H.q...#.uw.4qz.#.J.....@2
$"..$l.B.......D.ye..(..2.........@...... ...."... E..0M,..b{.^..s'...
.f.6.pr4.J........'j..........0...0...U.......0.0l..U. .e0c0a..`.H...E
....0R0&.. .........hXXp://VVV.symauth.com/cps0(.. .......0...hXXp://w
ww.symauth.com/rpa0...U.%..0... .......0...U...........0... .....0....
..0!..U....0...0.1.0...U....TGV-B-2760...U......;O}a.!..u...au..eUNp0.
..U.#..0.....e......0..C9...3130...*.H.............(.&..Dgr.Ve..#.<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEALa8SdwQh28+NjkQGqVhx8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=543162, public, no-transform, must-revalidate
Last-Modified: Thu, 30 Apr 2015 11:15:29 GMT
Expires: Thu, 7 May 2015 11:15:29 GMT
Date: Fri, 01 May 2015 04:22:47 GMT
Connection: keep-alive0..........0..... .....0......0...0......N$p...v....1.;..vn....2015043
0111529Z0s0q0I0... ...................F....0.yV......{&.K......&......
....'[email protected]...*.H........
......9K....i...{.-.?j.L...Y{:.;G<Xq>a.........p..f..N...F.Ki>
;*.l...FzN...*JT...YJ]...2.K.....\.=.Y.LG....L..@.;..^.PS.Gs....'KJ...
8......jE#U1}._.HV...)q_Y<}'t........f(.l .W$....#U....G...q.D...2.
K...L.../...m.t....,.gHk~y..$X.....RH7|.^..h=...uV)..".............0..
.0...0............F...I]A([email protected]...*.H........0..1.0...U....US1.0...U
....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of
use at hXXps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3
Code Signing 2010 CA0...150225000000Z..150526235959Z0..1.0...U....US1.
0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1Ver
iSign Class 3 Code Signing 2010 OCSP Responder0.."0...*.H.............
0.........q<...A...#......A...u..Lz.............o..D.vQ%..s.......f
....e../jI.d.W.....|K;.j5...#.B%.]..~S.... .|;S.&.....N..`...5.....!D.
p....M/.. ..;j...q..`6...2.Ck..BnLHvCZn%....,.w.Ooi..z'...\.Yx......b.
.L...5.o..o..{..}.........%e.....N..._i........*Bc....:yQg.........0..
.0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://www
.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS
incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0.
..U........0... .....0......0"..U....0...0.1.0...U....TGV-B-31830...*.
H..............-..^.........f.P`...s.....8.....V.......... .... B.<<< skipped >>>
GET /en/acts.js HTTP/1.1
Host: home.playfree.org
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: utm_source_channel_id=gs_en
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: application/x-javascript
Content-Length: 9897
Last-Modified: Thu, 16 Jan 2014 07:34:43 GMT
Connection: keep-alive
Accept-Ranges: bytesvar debugMode = true;..function showAlert(str){...showAlert(str);..}..
function SetCookie( cookieName,cookieValue,nDays ) {...try{....var tod
ay = new Date();.... var expire = new Date();.... if (nDays==null || n
Days==0) nDays=1;.... expire.setTime(today.getTime() 3600000*24*nDay
s);.... document.cookie = cookieName "=" escape(cookieValue)....
";expires=" expire.toGMTString();...}catch(e){showAlert(e
.message);}..}..function getCookie( c_name ) {...try{....if( document.
cookie.length > 0 ) {.... c_start = document.cookie.indexOf(c_name
"=");.... if( c_start != -1 ) {.... c_start = c_start c_name.le
ngth 1;.... c_end.= document.cookie.indexOf(";",c_start);.... if
( c_end == -1 ) c_end = document.cookie.length;.... return unescape
( document.cookie.substring( c_start,c_end ) );.... }....}....return
"";...}catch(e){showAlert(e.message);}..}..function pageLoad_land() {.
..try{....urlObj = parseUrl( window.location.href );....var url_parsed
= urlObj;....// category handiling....//alert("here");....if( typeof
url_parsed != 'undefined' && url_parsed.category && url_parsed.categor
y!="" ){.....var elm = document.getElementById( url_parsed.category );
.....if( elm ) catClick( elm );....}........if( document.getElementByI
d('srchCrt') ) {.....document.getElementById('srchCrt').focus();....}.
...var placeHolder = document.getElementById("728x90ad");....if(placeH
older).{.....var aflttag = document.getElementsByTagName('head');.....
var aflt = aflttag[0].getAttribute("a");.....if (aflt!='openceu'<<< skipped >>>
GET /en/i/s_button.png HTTP/1.1
Host: home.playfree.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: utm_source_channel_id=gs_en
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: image/png
Content-Length: 3051
Last-Modified: Thu, 16 Jan 2014 07:34:43 GMT
Connection: keep-alive
Accept-Ranges: bytesM..RM..).;L;L........5.=1.2........`ZxZ,....eI..Z.Y...n.Z9Y.XUZ].F...%
........N.N...g................m.}agb.g........}.}..=.......Z.~s.r.:V:
.....?}..../gX....3....).i.S..Gg.g.s.....K....>........Jt.q].z.....
.......6.i.....4.).Y3s...C.Q..?...0k..~OCO.g..#/c/.W.....w..a..>.&g
t;r..>.<7.2.Y_.7.....O.o._..C.#.d.z.....%.g...A.[...z|!..?:.e...
.A...A.A.......!h....!......i..P~....a.a..~.'...W.?.p.X..1.5w..Cs.D.D.
D..g1O9.-J5*>..j<.7.4.?..fY..X.XIlK.9.*.6nl...........{../.]py..
........,:[email protected].*...%..w%..y...g"/.6...C\*.N.H*Mz....5y$.3.,...'..
.L.L..:...v m2=:.1....qB.!M..g.g.fv..e....n../....k....Y-..B..TZ(.*..g
eWf....9... .......7.............KW-.X...j9.<qy..... .V..<...*m.
O..W..~.&zMk.^......k..U...}....]OX/Y..a....>...........(.x...o....
......d.f.f...-.[.......n......V....E./..(....C...<..e....;?T.T.T.T
6....a..n...{..4...[...>...U.UM.f.e.I...?.......m].Nmq.......#.....
...=TR.. .G.......w-.6.U....#pDy........:.v.{.....v.g./jB...F.S..[b[.O
.>....z.G....4<YyJ.T.i.....g......}~...`...{.c..j.o...t..E...;.;
.\..t.....W.W..:_m.t.<...O.......\k..z..{f....7....y......9=...zo..
.....~r'.....w'[email protected]...?[......j.w....G..........C..........8&g
t;99.?r....C.d.&........./~..............m|..............x31^.V...w.w.
....O.| .(.h...S.............c3-.... cHRM..z%..............u0...`..:..
..o._.F....IDATx....N.P............A@.. Hf..z..c......@x.^...A p.P..Y.
.6...A.La...3......OU....{.vzs?..*D...........x.:......Aw3I.i.........
.......86Q....4PV..l.t....)&..K..u.4S........c..'....'..'..'..'..'<<< skipped >>>
GET /chunks/goog-malware-shavar/7giqbAFh2S33m9VF3lXAepQAHn28qzEmckcfXXCSNJE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/7giqbAFh2S33m9VF3lXAepQAHn28qzEmckcfXXCSNJE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/ueUlg7RwaptET2592qwxtihIaGM0Zy7pKwY5E8kERZE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ueUlg7RwaptET2592qwxtihIaGM0Zy7pKwY5E8kERZE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/Ns_Bo4UvBU6hqyUFEDzll7JPYJ-SQwlpuXzX7KRxY_Y=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Ns_Bo4UvBU6hqyUFEDzll7JPYJ-SQwlpuXzX7KRxY_Y=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/8S0Q5rtA7KAKeU4Ehrg5Xv9EYVh3XYLrjsc_I2yPkxg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/8S0Q5rtA7KAKeU4Ehrg5Xv9EYVh3XYLrjsc_I2yPkxg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/QWJEMg5X_Yrd4iTgGTm7iFacTsiaurN1LIdYeVk8r3Y=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/QWJEMg5X_Yrd4iTgGTm7iFacTsiaurN1LIdYeVk8r3Y=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/QrQXYdikSjRrXy_HcAZXyWr6KLoxu5WFidPMEx_OalQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/QrQXYdikSjRrXy_HcAZXyWr6KLoxu5WFidPMEx_OalQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/F1IyfhgOm8mRwbTEWMWMuzVHUuC8Hgp5YQrngFJrcHk=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/F1IyfhgOm8mRwbTEWMWMuzVHUuC8Hgp5YQrngFJrcHk=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/U8XthtUjP3fHyhoWlkwxuCvAK1rcLrnp4IlOMe4QvKA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/U8XthtUjP3fHyhoWlkwxuCvAK1rcLrnp4IlOMe4QvKA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/zPBY_ZsUBv6JGy4o-VialmS3BxJzABATPHbco1wNs3g=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/zPBY_ZsUBv6JGy4o-VialmS3BxJzABATPHbco1wNs3g=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/77vHetNOt1hRHVuAH52FbCdQTJwqEgpbxZiNw8Hf92g=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/77vHetNOt1hRHVuAH52FbCdQTJwqEgpbxZiNw8Hf92g=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/NneCNSI4ljllFsoAbEr4y8E1cx5_ihkhoIBbRdfJ6J0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/NneCNSI4ljllFsoAbEr4y8E1cx5_ihkhoIBbRdfJ6J0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/LkU_PzHi470rWlFlDx6vPOMdSCxN46QTXhBcM_R_KXc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/LkU_PzHi470rWlFlDx6vPOMdSCxN46QTXhBcM_R_KXc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/F0fpy84reqUnQmBQSuHR2vNOoa14FpI-dzipR4EF1LQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/F0fpy84reqUnQmBQSuHR2vNOoa14FpI-dzipR4EF1LQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/VR8x-VIlD9su8cKntNAkoMX85wo3_9pJu8jiDHcZtHE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/VR8x-VIlD9su8cKntNAkoMX85wo3_9pJu8jiDHcZtHE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/tcGKeAaBBZVoTuDyPdwzKOYsyfhYjDXJQJGBQURKxGw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/tcGKeAaBBZVoTuDyPdwzKOYsyfhYjDXJQJGBQURKxGw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/cnGzzgLWGwIcOtVgK2IvD7uAdng1hM9iLWbSHDXzFZ0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/cnGzzgLWGwIcOtVgK2IvD7uAdng1hM9iLWbSHDXzFZ0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /ThawtePremiumServerCA.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.thawte.com
HTTP/1.1 200 OK
Server: Apache
ETag: "03772009e1780058ece5d08a5c74e513:1430428243"
Last-Modified: Thu, 30 Apr 2015 21:10:43 GMT
Date: Fri, 01 May 2015 04:22:54 GMT
Content-Length: 7587
Connection: keep-alive
Content-Type: application/pkix-crl0...0...0...*.H........0..1.0...U....ZA1.0...U....Western Cape1.0...U.
...Cape Town1.0...U....Thawte Consulting cc1(0&..U....Certification Se
rvices Division1!0...U....Thawte Premium Server CA1(0&..*.H........pre
[email protected]!....T..W...p
.[..%...100322161038Z0!....hx.....k...7....130919164724Z0!...!P..6{.lS
[email protected]!...Da\v..........%..130920062728Z0!...>.e..-
...s[.2I...140418142220Z0!....dU...(...=...*..140801114607Z0!........d
.{#E..9`...130926061856Z0!....6..q.'tT..1.Q...130926062249Z0!.........
...>..i....130528164218Z0!..........#.P.......130716072254Z0!.....%
.......R......100801221434Z0!.....M..HK.....x....130926060355Z0!....k.
"..z......64..130919082450Z0!...W..._....%..I....130926063253Z0!..._._
~gq.I.)[email protected]!.....=X>...][email protected]!...
.(........n.S...130923202627Z0!.....:...B..=]Hsx_..130920011556Z0!...
.>.ITt.Aw%*I.....130918091937Z0!....-.U.BC{#...x....120301162056Z0!
...U...z7.....UK.n..150330151829Z0!..........1S..Pp....130925105017Z0!
.......x.G.....=....130926064912Z0!....d....... ..=....130911111649Z0!
.....|...x._....wH..100510135256Z0!.....f.....F."E.....100527143439Z0!
.......B...Y..;..S..130925185558Z0!..........G.1.......100624153158Z0!
...3...$o~...w.t3...140304192649Z0!...=.;...........`..130924105544Z0!
....e..8..3...h1[|..130905162920Z0!...d.[,tpLq..o.; ...100528183707Z0!
...c.$.?.._..4..O...130905193529Z0!......V..T].Y..:|...130304224528Z0!
....Xy..MnW.G..f.t..130810133109Z0!.....c.8..vX....ue..13093018594<<< skipped >>>
GET /chunks/goog-phish-shavar/Sl6kTbztAG7gh4K9-UWT83pEpeufQD16QOSbGOMH940=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Sl6kTbztAG7gh4K9-UWT83pEpeufQD16QOSbGOMH940=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/JfMelIF4lIIljMS8fg5WquzqYqSh-C6DIxDq6ByNvqo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/JfMelIF4lIIljMS8fg5WquzqYqSh-C6DIxDq6ByNvqo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/1qFV-RFKQ9Yksu28tM2AZeyfzp7v91bWYWwMI7_MNic=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/1qFV-RFKQ9Yksu28tM2AZeyfzp7v91bWYWwMI7_MNic=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?73c63149da3361dd HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 24 Mar 2015 16:17:41 GMT
If-None-Match: "804047d4e66d01:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ctldl.windowsupdate.com
HTTP/1.1 304 Not Modified
Content-Type: application/octet-stream
Last-Modified: Tue, 24 Mar 2015 16:17:41 GMT
ETag: "804047d4e66d01:0"
Cache-Control: max-age=86400
Date: Fri, 01 May 2015 04:22:10 GMT
Connection: keep-aliveHTTP/1.1 304 Not Modified..Content-Type: application/octet-stream..Las
t-Modified: Tue, 24 Mar 2015 16:17:41 GMT..ETag: "804047d4e66d01:0"..C
ache-Control: max-age=86400..Date: Fri, 01 May 2015 04:22:10 GMT..Conn
ection: keep-alive..
GET /chunks/goog-phish-shavar/3Tj0bVUpKpSFrZPgfwQzX2xTELkpN6SDPWBdFeZ82hg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/3Tj0bVUpKpSFrZPgfwQzX2xTELkpN6SDPWBdFeZ82hg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/Btt71EDwI8tUxpLjIa52nMtiSPr0jPATp90kyoijHJ0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Btt71EDwI8tUxpLjIa52nMtiSPr0jPATp90kyoijHJ0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/wcDPbWwJTE2PtmVwcgnQhhl6hkrs-T-aO8g8Itcyd-U=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wcDPbWwJTE2PtmVwcgnQhhl6hkrs-T-aO8g8Itcyd-U=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/XJS8JhoQCLrHvoi2N1Ve_rg1LE7dFSX2zXDYKWc9FXQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/XJS8JhoQCLrHvoi2N1Ve_rg1LE7dFSX2zXDYKWc9FXQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /i/mmo_banners.js HTTP/1.1
Host: mpcstatic.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: application/x-javascript
Last-Modified: Wed, 22 Apr 2015 11:08:21 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Fri, 01 May 2015 05:18:23 GMT
Cache-Control: max-age=3600
Access-Control-Allow-Origin: *
Content-Encoding: gzip63e.............WmO.H.....a.UI..v...6...}..8...t.F.{c.b.Z..B...ovm.v.-
.*E..;....<.;.. .K.s>..M..W.......D..............(....D...?O.Sv.
b...#.tF.w.i.46.[.7_.....v.F..Ic......./...w.....]..G..3..rm9..j.F/:M.
.......u...D.... j.........rq6<.I.....7.:..z..M......t..%Qy.*q.Z...
...J.....{.}..l..5..`...A..#.m.w....L......6../.=..q].Y}.......K.pk...
`.$Fg.x...(.*..>..`.<[o.....M. .(i.l./>.. AY..*......L.L....l
.u.)..#......1.`Oc.E..fX.j.....=.j.......MSZ|r.... .N.......?!b.....xi
..y.Y....~..DP|[email protected]$........%:.k..|F.......e.x..H.8..s..../>A
.d.sL.HA..8..G"8.5.>.\[email protected]{$.H....,..{.c....J"q..:....^...
..._..r.l.,1......1..d.....Z6..3....u.;[email protected]....~.}
._. &..PH.I<C>4....1.t......0G........o:.g..C..............[.Wr.
...\.......K......}........-a{... ..:>.8..........k..z...n....6|.:.
8..5.*.K>.>[email protected]..=....tl.O.. ..:.W._;.(G"..^.f
.t....$....AC.hL<.w^i..'4 @K.,.2..Rt..R...!.B9.)17\\........6\.....
.3F.,;. [.{w......h.:%..?.'.z ....klXb<.a..Y"<.....DxzO..\....\S
[email protected]....)....L..b7..,5`...P..#[email protected]=S.....
...i...%....C.J,]qD.d.)..z...].#.g.......6...6M.....p.......`P!.$...Fx
...I./.h........?.].E..b\!.o.[(.NDV...^.\......M.m..L.C.PN.M..K.bM3.j.
....*Q.._.............mC>...v..Q7o.f..a.)...}4.'.[2e.n.x.hGX.,....s
j.}D....., .'..KC...)d7V9....2.~.e..m.....u.v.......F$&z.....zV..A.]&q
...&o....R.Uh..P.d.......sI.RB..g....|9d..e...[5}.|...m...Y~2.o..X....
..j...@E.`W.......#P. .R[......{..Z..5..`.....?"fR....[FM.....&-..<<< skipped >>>
GET /gn/111x83/1817_111x83.jpg HTTP/1.1
Host: mpcstatic.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: image/jpeg
Content-Length: 12343
Last-Modified: Wed, 29 Jan 2014 19:32:54 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:23 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes......Exif..II*.................Ducky.......P..... hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmp
MM:InstanceID="xmp.iid:5A4DF84188E011E38A3BC0B2CF7B94AF" xmpMM:Documen
tID="xmp.did:5A4DF84288E011E38A3BC0B2CF7B94AF"> <xmpMM:DerivedFr
om stRef:instanceID="xmp.iid:5A4DF83F88E011E38A3BC0B2CF7B94AF" stRef:d
ocumentID="xmp.did:5A4DF84088E011E38A3BC0B2CF7B94AF"/> </rdf:Des
cription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?
>...&Adobe.d.......................!...05..........................
......................................................................
............................................S.o.......................
......................................................................
".!..20#.@1A3........................!..1A".Q2.aq#....BRb3..r..$..0...
..CScs.4%....................!1..AQ. .aq...."[email protected]...............
......!.1AQaq..........0................S.y.>}.....8.!...G.f..$9...
.....5.\....:.M-.`..5.V....Y.....i.7_*..f...`F.t.....z..>........T.
.;kT.FE.....T..7...J-.1..~....X.K..../.......t..*P,E....w..*..j...<<< skipped >>>
GET /PlayFreeBrowser/VERSION HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:04 GMT
Content-Type: application/octet-stream
Content-Length: 32
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-20"
Expires: Fri, 01 May 2015 04:55:04 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytesMAJOR=3.MINOR=0.BUILD=0.PATCH=4...
GET /chunks/goog-phish-shavar/qDo5pwKwKj9YxZJyWqEiDvFdZDuI5PahFwZOoPI4-7A=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qDo5pwKwKj9YxZJyWqEiDvFdZDuI5PahFwZOoPI4-7A=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/8pHhQz9xknZc2CVxwA-g54bDE_T_5LY6xJIORyAqCv4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/8pHhQz9xknZc2CVxwA-g54bDE_T_5LY6xJIORyAqCv4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/UDsJW951ls6hXgbEvhwDLWhn1cuoWuX5hKld43jlNko=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/UDsJW951ls6hXgbEvhwDLWhn1cuoWuX5hKld43jlNko=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/0_r7h7C_8wmcDtCoyZDTlAyHpqloSAKBngEZmJkLijc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/0_r7h7C_8wmcDtCoyZDTlAyHpqloSAKBngEZmJkLijc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/mW94EcunmakWRnLV-MS5hq-LjJaiSXJCzVFzlQt6-NY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/mW94EcunmakWRnLV-MS5hq-LjJaiSXJCzVFzlQt6-NY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/vkJyaujmHBeBaeLUaJI7i6fATIaUv4Yw7YdKiZ5VZDg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/vkJyaujmHBeBaeLUaJI7i6fATIaUv4Yw7YdKiZ5VZDg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/pNLUb43N-OFdIP7mjo2tzPuDNjNF2ERBwUeIMlDCOF4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/pNLUb43N-OFdIP7mjo2tzPuDNjNF2ERBwUeIMlDCOF4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/1K9aDMnPxpkE2R2aBK4b2E3IagxTFurTWM6YCJFB54g=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/1K9aDMnPxpkE2R2aBK4b2E3IagxTFurTWM6YCJFB54g=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/k79kxi7KCBnYOCQAy1vwtvAw8-UsxI05yt5LtYK6gi8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/k79kxi7KCBnYOCQAy1vwtvAw8-UsxI05yt5LtYK6gi8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=460561, public, no-transform, must-revalidate
Last-Modified: Wed, 29 Apr 2015 12:15:02 GMT
Expires: Wed, 6 May 2015 12:15:02 GMT
Date: Fri, 01 May 2015 04:23:07 GMT
Connection: keep-alive0..........0..... .....0......0...0......'.V.8.F.V....H....JW..2015042
9121502Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
....^[email protected]...*.H........
.......d...W.P".....!..%.p..0....e."..<.\l&.. zl%ln@{.Sc.....l....;
R....@).(E.D...c.\.Q.L&...;]A$:.o1.(>.l..G#Db.!....bO..T=&}?.`.....
w.}1[.1.P.{[.%..Lji..`H...............Z...9M\\du8.X.N..c.A.:j$.p.2...0
.....7.2x....C"."...1(.LA6...&....SH,..../[email protected].....#0...0...0
..........r..?.*......y"..0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use a
t hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code S
igning 2009-2 CA0...150226000000Z..150527235959Z0..1.0...U....US1.0...
U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms o
f use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Clas
s 3 Code Signing 2009-2 OCSP Responder0.."0...*.H.............0.......
......m5*R........2....>...yU4..L.. ...........u..Hez..Pn.....d...n
z(...V7.}^...d!RX...bl..[..a...L.. .~..Ij......%..%p.-...u..:..i..F*].
..*....{NH..|0...gHX.Q.r....S..........._.9.(w...suC...N..s.....&."...
:.C.Q.i~rl..<..krS..8.B..o][email protected]...
U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.veri
sign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS inco
rp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U..
......0... .....0......0"..U....0...0.1.0...U....TGV-B-32010...*.H<<< skipped >>>
GET /chunks/goog-malware-shavar/LUeHOOMCOB-pQlzdlFGCbhZE9V9kaVRt04KOCVaJC4Y=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/LUeHOOMCOB-pQlzdlFGCbhZE9V9kaVRt04KOCVaJC4Y=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/yJ1ZF2okVJs_Cd8LPf5zbMQMveBa1SReufVugI1TKTY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/yJ1ZF2okVJs_Cd8LPf5zbMQMveBa1SReufVugI1TKTY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/-UtvLBU64lZsXS6mufZK4XOCHgYcH3F3q8TmeiT9jS4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/-UtvLBU64lZsXS6mufZK4XOCHgYcH3F3q8TmeiT9jS4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/AKhP51LP6RbILIOwncigFP531tS2Yb9D8jtiZVa6uoo=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/AKhP51LP6RbILIOwncigFP531tS2Yb9D8jtiZVa6uoo=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/S0qM3gmmlTfjfU09iNPuDLKQ-EcgLa4CykvNbVwOWz0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/S0qM3gmmlTfjfU09iNPuDLKQ-EcgLa4CykvNbVwOWz0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/wE_jh56jwL0G3tMkWWfbENSe5bxNIfTAzlgY1brnafY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wE_jh56jwL0G3tMkWWfbENSe5bxNIfTAzlgY1brnafY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/Ccn3RlRn-KWmMNIgKEOIrNd9c9KzqusM19c-qz1fg1A=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Ccn3RlRn-KWmMNIgKEOIrNd9c9KzqusM19c-qz1fg1A=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/bV86Zyzwrz-XuBUsX9if0otATsDvqxKW9-y0KqjYYzA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/bV86Zyzwrz-XuBUsX9if0otATsDvqxKW9-y0KqjYYzA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/FfNH48w7DUHj48hUCP8YmqTLg961wKPqU4prBE4tEFY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/FfNH48w7DUHj48hUCP8YmqTLg961wKPqU4prBE4tEFY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/5QoMmAuV8US3Ysur3PVelYvOwlVagaglfaAafQ9_Yig=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/5QoMmAuV8US3Ysur3PVelYvOwlVagaglfaAafQ9_Yig=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/htfrrZFnqTgSC2mR0kmzYfL1_FCaDvtToyAQP0dl3VM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/htfrrZFnqTgSC2mR0kmzYfL1_FCaDvtToyAQP0dl3VM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/YGfxA6S0Iv-jWOp8V1Su16gcyiJwlNoX7fjo0kbnqn8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/YGfxA6S0Iv-jWOp8V1Su16gcyiJwlNoX7fjo0kbnqn8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/BewhhbJykgB1ha8-WMrSewfQIiANmgIGXucGjsl33Ks=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/BewhhbJykgB1ha8-WMrSewfQIiANmgIGXucGjsl33Ks=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /icons/product_logo_128.png HTTP/1.1
User-Agent: Game installer
Host: customisations.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:03 GMT
Content-Type: image/png
Content-Length: 24082
Last-Modified: Wed, 02 Oct 2013 08:03:29 GMT
Connection: keep-alive
ETag: "524bd351-5e12"
Accept-Ranges: bytes.PNG........IHDR..............>a.....pHYs...#...#.x.?v...OiCCPPhoto
shop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE......
.....Q,......!.........{.k........>...........H3Q5...B..........@..
$p....d!s.#...~<< ".....x.....M..0.....B.\[email protected]..@F.
...&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWf
H.............0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(
.I. [email protected]..._-...."[email protected]~..,/..
.;..m..%..h^[email protected].~<<E.........J.B[a.W}.g._.W.l.~<
;......$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,
..>.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..
?....D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/[email protected]..=
p..a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2
....G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,.
.c.."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b2
1.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!
.[[email protected].(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i.
.t.....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....
J.&..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.
._... .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....)
.)..4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....
Dw.n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC][email protected].
.....<..F.F..i.\.$.m.m..&.&!&KM.M..RM..).;L;L........5.=1.2....<<< skipped >>>
GET /chunks/goog-phish-shavar/nB0tjQFotnc6cc-qs7MVBADJ66-XV6kfwDsAr-8FW9E=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/nB0tjQFotnc6cc-qs7MVBADJ66-XV6kfwDsAr-8FW9E=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/IJvxhg70GV20xTBQnxkJq9p6uz0Gge8MXTeEu5AhP78=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/IJvxhg70GV20xTBQnxkJq9p6uz0Gge8MXTeEu5AhP78=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/HKF3fPwAJeRm13miXe-4vI1FaGTPCwlI5utMJctwl8k=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/HKF3fPwAJeRm13miXe-4vI1FaGTPCwlI5utMJctwl8k=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
POST /service/update2 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: MPCBrowser Update/1.3.27.0;winhttp
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Content-Length: 520
Host: omaha.playfree.org
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" version="1.3.27.0" ismachine="0" sessionid="{17D31739-CE97-41F0-B418-534DA8AFFCEB}" installsource="otherinstallcmd" testsource="auto" requestid="{05B60A1A-A2A5-42A7-A321-A54CE5786079}"><os platform="win" version="6.1" sp="Service Pack 1" arch="x64"/><app appid="{2F0B3EEC-E5EE-47C1-829C-ADE0D31F2DFC}" version="" nextversion="" lang="en" brand="" client=""><event eventtype="2" eventresult="0" errorcode="-2147219447" extracode1="268435459"/></app></request>
HTTP/1.1 200 OK
Server: nginx/1.4.1
Date: Fri, 01 May 2015 04:18:19 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.15
Set-Cookie: pid=fm67v4umv9ufcpj9f9k15iii72; expires=Sat, 02-May-2015 04:18:19 GMT; path=/; domain=.omaha.playfree.org
Cache-Control: private, max-age=10800, pre-check=10800
Last-Modified: Tue, 27 Nov 2012 07:34:24 GMTc6..<?xml version="1.0"?>.<response protocol="3.0" server="pr
od"><daystart elapsed_seconds="83899"/><app appid="{2F0B3E
EC-E5EE-47C1-829C-ADE0D31F2DFC}" status="ok"><event status="ok"/
></app></response>...0..
GET /chunks/goog-phish-shavar/7qBdfHoJ3SU-MMdqwyhr_IzMeAwQHON2YMpt_zQv5fI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/7qBdfHoJ3SU-MMdqwyhr_IzMeAwQHON2YMpt_zQv5fI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/kM4mzd_BuL56ZUjvvtfFU4OlLoZ0tcQBXhFE43FTkn4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/kM4mzd_BuL56ZUjvvtfFU4OlLoZ0tcQBXhFE43FTkn4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/ituihT2nIuOO6K7aEfwTkyN_MxBmCcdyz-1vcd_m2wE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ituihT2nIuOO6K7aEfwTkyN_MxBmCcdyz-1vcd_m2wE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/fkpIIcjuujT2rH2P7HowLNvnV_wY3RESjlhYbwey-Ek=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/fkpIIcjuujT2rH2P7HowLNvnV_wY3RESjlhYbwey-Ek=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/KlYWl0YjuqklZ6Kr-iE6JwkoD1lGRDSYV3y1xtUJ6vE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/KlYWl0YjuqklZ6Kr-iE6JwkoD1lGRDSYV3y1xtUJ6vE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /service/check2?appid={00337EA4-7B9A-44A6-B45B-B1722CD4343E}&appversion=1.3.27.0&applang=&machine=0&version=0.0.0.0&osversion=6.1&servicepack=Service Pack 1 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: MPCBrowser Update/1.3.27.0;winhttp
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: omaha.playfree.org
HTTP/1.1 200 OK
Server: nginx/1.4.1
Date: Fri, 01 May 2015 04:23:01 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.15
Set-Cookie: pid=vri10eco1r0t1cabva0po5le76; expires=Sat, 02-May-2015 04:23:01 GMT; path=/; domain=.omaha.playfree.org
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Last-Modified: Fri, 01 May 2015 04:23:01GMT0..
GET /gn/111x83/1813_111x83.jpg HTTP/1.1
Host: mpcstatic.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: image/jpeg
Content-Length: 11009
Last-Modified: Fri, 24 Jan 2014 16:23:36 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:23 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes......Exif..II*.................Ducky.......P..... hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmp
MM:InstanceID="xmp.iid:EF46A74484E611E38036836E479D677F" xmpMM:Documen
tID="xmp.did:EF46A74584E611E38036836E479D677F"> <xmpMM:DerivedFr
om stRef:instanceID="xmp.iid:EF46A74284E611E38036836E479D677F" stRef:d
ocumentID="xmp.did:EF46A74384E611E38036836E479D677F"/> </rdf:Des
cription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?
>...&Adobe.d................e..........*...........................
......................................................................
............................................S.o.......................
......................................................................
..!.01"A..2B#34.......................!.1AQ"..a2.q..B....Rb#..r3C$..0.
....45......................!. 1A"[email protected]..................
..!.1AQaq..........0................./?,.....3i.."..kMk......r)....\..
^.h..5K>Z..nXr!0......!...J.....9.q.%.G..!e.7...PL.!..i.Y.N..M.02..
5L9.}J.....a.yk..,k..L..Z.)92.?E*7...J.......k n.B....E.....m.#.\=<<< skipped >>>
GET /chunks/goog-phish-shavar/FHvKorYRa9bSJlD4xPUO7BZe3gbwe7hXGscMWGeHqIw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/FHvKorYRa9bSJlD4xPUO7BZe3gbwe7hXGscMWGeHqIw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/NOmm6qIJGzLneEHWSVjp5adubXmIgV9QvN8DqpIxpMg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/NOmm6qIJGzLneEHWSVjp5adubXmIgV9QvN8DqpIxpMg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/8TrlR6tjVYIn5nOzkeYe9TWzQniXkQUFt-m-_y4jm7A=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/8TrlR6tjVYIn5nOzkeYe9TWzQniXkQUFt-m-_y4jm7A=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/8x86bntNswBvF8StUDkyBYJScNTywKW-WxR6azPXUFs=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/8x86bntNswBvF8StUDkyBYJScNTywKW-WxR6azPXUFs=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/CiVhTt28sFS93rXevnsokT4ntD6_q3CDbxSad31QNu0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/CiVhTt28sFS93rXevnsokT4ntD6_q3CDbxSad31QNu0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/EvqzcZp4bVd4cfZLC8AKSI9VMn_dz4QLBIdq4T2EPUs=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/EvqzcZp4bVd4cfZLC8AKSI9VMn_dz4QLBIdq4T2EPUs=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/bP9cwuh_axs0J-Nbuo42kmwnhgt4rWNfe0gHrOFh0Mk=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 39
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 07:00:36 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11318:4:26..\\?......\\?z:.......z:......
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/qDo5pwKwKj9YxZJyWqEiDvFdZDuI5PahFwZOoPI4-7A=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 6761
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 02:10:39 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11317:4:6746.Vmo"........1LW.......l{.r......#.*.a........U.MSJ]....
.$u9.\..........{X.........|U..`.gW.....6"..&3.N........#j..k......x.a
\K.......\K...M.i......M.i..........H..3..d.....B|{[email protected].....#.
.....l..'.(.......<~.`..........Gh.:g.......:g...........p.....?...
.....?...7.....V.]h.s.........s......./.,1........V..U...........h....
.......}........';>........=O.n..........I.z. ......R...G.........V
.Wq.a...........J.........&...Qv.......p..a.........\.%3.............!
.......5...F.......UY# I..,.....>z.....1......,..&$.......&$.....lG
.....!.9.......B....v.......j..v.......s..............E...............
.).....v:;....\.\.....dq]......r:......*......A.......!..F............
.w........H.....ro.......K.........-....e<......C.........I&......T
.....}.G.......(.....8.~,.............. .....NO.7............8..v....9
...............4_.d.....O.G....]._K..............i......I_F.....h.....
...J.....Y..........C...............e....dvX.....GqQ......J.n......N..
....=5.....'.JX....................=.8................k.....M[.....'..
.......}......Ao*....C.Q%....M&|[email protected]_4l......\....}.
|.......6/..F~............dx.....b@....".......o.../.......:..d.......
...x.7....}.2y.Bx......B....:.......%@... .........2...r^........H....
a.............a....G............mC........i...{............~.....i..n.
r.L...........k......S.Th.......WD........]s..b.........0.7:f.~.......
.r...............p......,0...............&.=......z.{.8..'.....N^#..A.
.........,*ft......!.kC/W............~y.........$...m.....V.m.w.T.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/tFrZWBGYzrmSIkQD08neZlV3aJoQfKyKFZgZSg7ts88=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 8808
Connection: keep-alive
Last-Modified: Tue, 28 Apr 2015 01:01:08 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11316:4:8793..........!<.q............Zo.F....)........0%.....w..
.P.................;Gk......8..........M..)LW........2.|....-..S....!.
..l2........OV.=.MB......<B..D.U......0..........._.}&.....z.][....
....E21..........O!.^..S.......wu..T.......z.......D..x....!.........Q
..... FA..........pXC.`.gW.........&3.N..........".........Y..X.Z.....
..r..".5.......(}.ywF........U.,........J..(.k......b.....uN.....T..6.
......]J..I.....oB...........Rt ....B......'.....?............D......1
..........V...o/.......'...hP.......hP....N....................0/....
.j....=D.........h.....................W.......a,c.... X.^mnb.........
L...j.........u}H.........SE.#?..........t...........fR.......xw......
........s.........iN_...L......C/........4L2.!H......O.<...........
..8<........v..G........./1...`?......./....C.......Zr..........#.N
q........L5....47......-?...........i............1...............2....
....8.sU..............r..........-C...............'.....*1..$..m.....v
.FD...lJ....z.U.............|..Q......g\.....w......Y...............).
.......,.......c.......[[.....d.].............*.........'.............
...u.....kg...F.......k/.SH[^A.......FB............s......u&....)`{...
...S....Pd.........*]/B........-=./......)...5.W0.....5.W0.]KT.......*
bj.?=.......F....J........./.R......... .#.......|..bI.........E.*....
.....^:..........')...................9..F........1..X `!......\V...JG
........C..........uj..\.?z......L...U.......(sxC.1.\........O-.......
. .h.e.V.......~........a........... ..b.Y......4........RE...*...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/8TrlR6tjVYIn5nOzkeYe9TWzQniXkQUFt-m-_y4jm7A=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 3057
Connection: keep-alive
Last-Modified: Mon, 27 Apr 2015 01:01:00 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11315:4:3042....I.....J........=.............1....f............N....
w...O...a......$...6A......=.f....A.....;.2...C......5............N...
.o........uZ#..4.............@......_Q!..El.......~....e........e...X.
.................Wk......T....................CMU....u........@..T....
..S..............4R..x......)M.d.!..........Y..........K........_.....
...............s..i..........`.m.......>..i......e.....b..4....>
.......qcm.......8.............Pc.........(..u.......tK5...........u..
..!......Y....?1.....e.^;..........M.E.&.?.....uDM..B.......:s......./
m..........3c1....'..........0.......].`..hs......$d...W........;7....
......A......D...........N.........V......9...\........LR.....J.[.....
....a............f..D. .......ZV...KA7.......=4............S..........
..~.X..........q....>z............}.4..................E...........
4.kO....Am.*.*1......]U.^.mN.............F........O...'......m......A^
....5i.....[..E..........).'.~.......TW.h.#.:..........17...........5(
......z%Y............j....,.....UK.....\.....7.d....`.....B..U....#...
..1.......4.h......CC...b.......b[.................._... ............m
............Vh>...........O......o9... .......d.Z...........a$..rB.
........~...H.....AE........9o.p........vT...O(......n...N.*......S$..
........\..............a..........oYp)..............%d).....ia......Dx
.;...........oL.M$.........x..h......,.-...*.......a.......Ub.....j.I.
.....6........?F....y..Z.......:....q..U....5.k..............r*.......
......YD.....lB.......y.....=B.....B..2...............'....O......<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/6REFNUxyRF2vLNuQD5eV-JDP4re7A_YwPBkbPa1JkfE=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 8435
Connection: keep-alive
Last-Modified: Mon, 27 Apr 2015 01:01:00 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11314:4:8420..bI......ml......h.)!.mPS......i.....a.......a.........
.D.%b....D.............../;.!LW.........M=....M..:....LW......j'..{x..
.........*.a........;......7..?".e.....O..T..............)..........J.
.........}0T...T.....$...`.v......x\8.U......../....%.!......jx...T...
.....4m7.L<[email protected].....`..@....^,.-9q?X.....l..V7.2......||sg
=.........|.}.Y.......2...3..d.......].%........dXgC(.k..........E.s..
........-.b......b./.)h.......T.>T.........!"....N......BC.......4t
&X..........L.....h;...2.R.....h=..#G.1.....>....=D......5.4i....c.
$c].]b.....m....j.......]#..\.............).......u[.[.....D-.(,......
..Md..#.......B.|..m.......p.....nB.....`f.c!.:.................#;>
.......;%.*............hn........t.#.ji8{.....Hc.W=v..........?.....z.
.'.........(.aS{._.....K.(8.....8v ............1.....q.......?..,`....
....,.....u......|. }..`.....4g7U.`p......m.._Ba.......'.#.?.X.......~
z<a.........A....3.........MH3.......H3...[c.......v.....H......a
C........W.2O....qe.l'.........7}......J..G...............v...........
..v.0.........o^J......... $..m.......6.....$......|........|..2......
)...~........P..2..IT..........@|.........8...........E..:........y...
......$.........J.........'J.. ........36..r^........1....}v.........X
....D..o....!.......{.......\....R./.....*P......<}.k....@.!{....~.
......@.........{.......T......0.e....R.........B.......)K......y.....
.<......(#A.....b.......&.R!......~T....................}.^.....t&;
......s.......C......=SB......n.G.......F....v.........]......Ul..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/tsOoy7JAp7Lz5F39t4GNxgnXgvcVKsoLv9IDzQgKTp4=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 4929
Connection: keep-alive
Last-Modified: Sun, 26 Apr 2015 01:10:41 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11313:4:4914..U............bI.........h.;.(.....2....o\{.....n"&..GH
Z..... .............,E....N..........#......................Os..w.....
.-:.&....,.q...D......f....&.l........p..D......................`.-, .
....3,RW.KA7......Gb...........aR....._....R.<..........D.U.....>
;.3H.X........zR"........._.P.....jx.8.............y......Ir;........a
.........q....a........(t..........k..7........._..!......m...........
.pr...........?z.F..............5.....h.....T........Hd...........0C..
....\...x.......{....................\2........:....|Hb...N.......wR..
u.&.....(.i....7.....u....B........b.g..............5.t......\v..Ig...
..................<..A.......%..z.m........o.o.....'C......9.k....%
.........F...w............aR......:f..G]......(P...5C.........l.u.....
..t.....?1........[......0;....x.H..........*.....I.......2S....i.....
\....L.......E..x.U.......Oz...&.?.....&.y'..7&.....y.............i...
...R.}....'........o.0.......F.........?p....l.c!...........|.....=.TH
.....;{...fM......O ..JG.......C.3...g.......E..-Q;......c.D.......a..
......./W...........zY...........i..............".....v(....(......$.?
g.>.B............5.......|P. ............(.2..........27.......u)o.
-[..............*0=....J........)................ ......VO.......... .
[email protected]...... Ewv........{|....$V.......A.x........
..aBw...._..%.........O......=.....d&.z.....].........C.....H.........
6....2Y..............z.......T..........)......6.f..............-.....
Y......w...M............Z.........W....F.....1..............Fo..7.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Jj0fDeTYdxpkeaiXNqK7Ypwod0ePmqChmJPwBCFVIQk=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 8987
Connection: keep-alive
Last-Modified: Sun, 26 Apr 2015 01:10:43 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11312:4:8972.Qz.........H......|..r(.-.....i.M.P........$..Q....)O..
....6............k .U.............).k.1.]......tv..............b..*.a.
.....B. .......4.=.MB....... .8L.L.....Qa..?".e.....'...........|\H...
....'d..D.......C;.y).GM.........{...........KZ..........5.;{.5......z
...%.!.....Q..-E.x".....\"......2m(}@..w.....t..M....p...........9q?X.
......>....g..........".5.......2.x.o.......t.j-..A....._.p.....1.1
.n........q......8.....U...(.k.......R......3.j.,/a.......v.......%.T.
..?.....l/...................Bj4........FM6[...................6^v.:.{
..........&b7........\aX.........N.C.}.}.........._I........8$....1.`.
.j.........X.Z/............)........V..(,.......k.1......X..fR........
.............H.B.6{.......,.X].Av.........S.\......rG..{Hf......\4Vf..
........d.K......`...........O..n.........c 8.....1..`...........6N...
.............i/O...|....................~......<.I..Rd......N~..qr.
"..... 2..e...........QZ..H......'..a........<...)EN.......b[,?*Tv.
..........."...........!.........v.......3......tw.[c..........'......
......~........=..............|......wq...B........3%u".......u"..C.&I
..........x....................'..][email protected]..~...
.FP.?....C.......v.1_.....Y.......d5g.......~....5.......Zu......c^...
......o.....F..ow Q........l...e..........J6..........j.`......<...
./..........g.p.)........f...7.....$...K.k......(NVA:f.~........beb.^.
.....~.lF....................8e.......S.\..........].....G.........k..
.....4.S............)........)...r.........n..Q_.........*]n.]....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/m8zTXWVYnt2StqmNe4n0gx7bH32b0Uex1h36Ocbxmp0=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 186
Connection: keep-alive
Last-Modified: Sat, 25 Apr 2015 04:00:43 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11311:4:172.........D....H..h....;H..h........6.....?...............
X.....S........S.....F,?P..J|....s...P........s,"....z.....s..........
........\........\................is%......is%....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/rHqFII0PWn-x5sL4llxzm8PrL_k6RDogkhqBV80h3JU=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 4562
Connection: keep-alive
Last-Modified: Sat, 25 Apr 2015 01:00:34 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11310:4:4547....L........'.....6u..bI........._....t.........L.x..4.
....."..P..........`..GUs.....x3..6.........<..zKV......X.0....|...
...9x.LW..................)...............5....!.]...*................
...Mu7.......r.*.a.......K..=.MB..............7I8.............D.q8....
..A.....p........).m<I........r..aR..........R.<.....\.(4W. 0...
..q....../......%..!........%.o...;}.......Q...El......;U......:...a..
.....~x....h........Z.t.^........_..[c..............V....;J.......;J.%
...........Q~..Q......=h.....f....o[8.......G....b........b.........D.
.............}.Z...........M......_:...D.....q.....<.........>..
...........b...........eeG.;.....8...r.6........5.m~S..............6..
O............3gp..b........J}......aL......#>.......{......4.......
zx...bo.....[?j......(..1Y.......$.b..M.@.....}.2^6k........Bl..M A...
....\..........m....... j...............q.......{......%.........k....
...........e;.............?].............\=./......zLb..Q..........I..
....q...........yK.F.........nWp..S .......S ...a......QA.v1i........0
....1...........S.......M.{.M$......U...5..y........6.........*P.V...3
.....[U|....B..........$Y........'.>........v1..|./m...............
.........]..,E.....R....S7.........bYC.B........KC...........;..N.....
...t>L.S$.....P....................qk.}.>.B......].c.....#.r....
.5.........#....8U.^......d.......... q......S..^[email protected]&b7.......2).
'.4......lD.......\.:....U..d.....?2...A............$T......r.[e.V....
..5.2......B...D;......J/...8(......g.....rF.....F...............d<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Y0cCKitNdebmBGg2qVxMow9PkJ5C5cS4IunvOy1sG4I=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 7021
Connection: keep-alive
Last-Modified: Fri, 24 Apr 2015 01:00:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11309:4:7006..bI.......u...DMU........F...I.......^0...N.......=R..8
.............h.....f"...o.......~.."..........si......R.f..1......:...
...........-u..................:/....Y......l.....F.....HS...;.`......
7....D......?$U......,!...?1..............n<.......~....c.....c-.*.
...........~...?......Hxy....^eE..W.M.......Ut............i..........r
....f.......!...vvK........7..%1.....G.....3L.....{dD{...'......Ek|...
d.......|...N.........L..L............A......r.M.............O.g......
.*..J.O.O......O.O..........<@...........<:K.f.......0.&.....J..
............K]..................\3..T&...........r......._.!..........
.zg...2........2..........[.q............i.......... M_Z...lq.........
....9.......QF.......R.....A}.G..... k~....P5.......wiS....p0.7.....8.
.......7.......fV......KD....J.1.....N..[.......'............Fr.......
P..............~.>......QCv.....<. ....F.t|......J.....;........
.......R........A.`...v.z.X......R.....P%.......A:....................
...1}.....(.}......:........P.............V.l.............x}o.......P.
....(.H.....l........@y......=\....3.|$.......1.....n.,.....Z.[....%-E
f.....Rm.....C.1......Z.3......J....m.Uf.....u/.'....&"........7......
. 4....j......{...m.....A.H.....".G.....o......U.~.......jb.....Q.....
.........c..S......\.......O......6......y U.......:......V....../x.S.
...........2^.C....c.(J...}.m..............u.[~....>Yo6...........}
2dsk.....n.H.....@.......<.......v.............rh3.........m....&J.
v.....nR\.....xbT.....s.....{...a.............).........k.........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/HTljzKj4oCu9PHBzGXK_dMaJUzy_2N0eWMp9W7Zt6QI=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 8531
Connection: keep-alive
Last-Modified: Fri, 24 Apr 2015 01:00:24 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11308:4:8516.r(.-.....>..lP...........&....&f.i....#.......[T.$E.
.0......;..G.r......;\.KH;#H.........?".e.......*`............vUjW....
.Yu9.D.......J.n..........dKLy#.......................9m....6.d.......
...H".)b.........!h{[email protected].;.....A....%.!........!...
3......3...........".5.......M........C......n--..A......._7\-,O.....Z
..3....=6. ......[....l......yk)(.k........F...uN..............$.lO.._
......j ..........VG..W.D......].Q.....v.F.........&b7......M..3.....y
U...........9.P.}.}.......x*g........Q.IG..........58O>.K.......C.$
k.c......ZT.......d..!.:.......P.8W!4........g.Y..o..............s..].
6.......e....................OMG.......A....(j.b[GC......].4Kn........
Z.........h...........&|~....Q.........2J....y...JH(......JH(...|.....
....y.......a.........Uh..,`.......|>....R......\..=@..............
...`.\}..`........#=.-........k.Ba........$..............(......w.....
.<.(1........<{..~.._........cxl.......xl..]. ......?...'.......
..&......n.f......b.=">.......w./.).GM......i9JE..\......j......m..
..3JK..........=...........3.26......x.u"..G......z".A.W*......:p.~...
......J ....d...../:a..@|......;...c........4h..E..'......I.<C.&I..
....x..gH.k.....]].5............U.......a.............I.G....f.m......
..=.....[`...............o........a....x%S......W...............]6(...
..A......m.V5.....r......{..Z....a.t.....8OZ.....s..I.......x.......)\
.OK.....<...ow Q......c..................p.B......^.{[email protected]...
..K..................b.......................XPy.........\.Qeb.^..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Bo9JfyHVL7b5NSgfR8eXJuvq1Sz1--op2i8kfamuRcI=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 371
Connection: keep-alive
Last-Modified: Thu, 23 Apr 2015 03:00:17 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11307:4:357..GQ.........<I........I.................K.d......$[@.
....]A........9<SER......3...........-........-....=<........U..
@[email protected]?........f.............8..W......?..............v.O......
........m#....W..8....v>q..............c.[.....t.n.....g...........
.................R..B......n............rk.....1p...........pZ.Z......
.......4.Z ..........}.........J.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/Ccn3RlRn-KWmMNIgKEOIrNd9c9KzqusM19c-qz1fg1A=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 3192
Connection: keep-alive
Last-Modified: Thu, 23 Apr 2015 00:40:22 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11306:4:3177..9.v......9.v~R........!."P........w.]......j....... .)
......Ea....4.......0........L.......O.!.J...........I......../v.....b
.....M..w=.MB.....Y....zO......u...K........K...R=/4........v.........
..Fb...7.....@~....XO.........a..8.....tJ.a.........%o&..C.l....../I.r
.........>3..........e..L.D.......9...5.b....................1.....
.K...q(........n..j..........[.ew.........'................)C.........
..#.....#.............l]./........d.\../t......J....Y.I..........G(6.
....'.C..........O...6k.......&....3bQ......8Z..`.......O3..7r.0.....~
.e6...........2 ..".......................'..........$...........Fl.aj
.$.....d5..gAw.......!.R.V6j......D.o.\y......'...-..........C........
...|:.|./m......*..............<,.h...........v...k......e[.....x..
.....6m..;O.....ZqO............WK@q..........}.............&b7........
......./d..........<..)'[email protected].....)
CW...........ag............e....g......`.xL{z........'.~.w......!.T...
........X..d..........."..d......2......F......}V......u.RW........W..
...........a..Y.u........G..........'.\.I5za......kJ.Zh.......^..P.F.#
.......6c3..........k..E........KE..h........W.[....q=n8.....PE..$PS..
.................M.....O......HZ.'.)......a...)~ep.....lb.7S.\......3.
.;..........Y.c........................1O......{...&.......qw .~v.....
..............x..e.....,#(%.Pd......[..*L........~.>. .}.......P.SD
........-.{~............,.. .......GT...B.........-c@p.........}<..
.....V..b.O.y......4.`...j.....P.62..'8...........vW........_m.,..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/olMNSrIv3_9-5Zz2qU3JZv0ECEq0RlY7SE12jovxqOc=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Content-Type: application/octet-stream
Content-Length: 9003
Connection: keep-alive
Last-Modified: Wed, 22 Apr 2015 01:10:25 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11303:4:8988.P.........a.)...N.....bn)`LW.......gc)..1.].....!.~G...
h......b.$=.MB.....j....o.x......|.4[qKY......d.......[w...........;oj
..w........T.......u.#.........x7...1...........2.$.......6\%.........
[email protected]......\.j..........c/.I.KP.....I.KP...s...
....{)n.........q.7"..........v.............7....J1(...7&.....}.2,....
.....{..........S....9=.......^.9.......L....?.1L.....4..*..=...../q..
.f.R............b......z........qLI^.........dDU........>.. W.D....
..W.D..........X..Q.)[email protected]/..
......d..)6.......\....vvK...........!.......Z^...k`......j:_k.c......
..B....d.....D..1............*..q.......n.Z.........(.......P.x!.."...
...a(..O................}x..V.=.........!].6......~...z.!......].>c
q`e......[..Q..`?.......W....C.......g........_......Yv....-$>g....
AO.X..R........s:w./............/W........C.m........Rx.1............2
........{......O........O...Y.....<G.....H.....=z..v.........Z.R...
...............g..G........k-E.=om.......v.=I..,.....................~
$..m.........iw.......!AYN.........m..]..V......y;.h.]6@....../..Y....
.......R.:.......H..........(...q........w..r^......$FI..W........K!..
[email protected]...............`........M.......
. ......-{....<........R......=*..~.........=P...mC.......9.ow Q...
...Dfo...e...... |....~.....:..]..K..........e........U.2....7.....c..
[email protected]......<....T......e^_....V.....O.
t..........>.B.....e..{......P"......Jh...."..........0....<<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/sJEvZc18T-F36DdkfLn5DgD2i3J2L2_5jaZ89QVBmvg=.chunk HTTP/1.1
Host: cache-kiev06.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 192
Connection: keep-alive
Last-Modified: Mon, 20 Apr 2015 19:00:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytess:11301:4:178....0....s..C...0...........7......<}x..$.l.....s..U..
.f.....| 0...............Ag......*Ag....#.....s...].f......|${. .?....
..|.1.X...|........<'7#.......g....$.......6*.g......5.HTTP/1.1 200
OK..Server: nginx/1.6.2..Date: Fri, 01 May 2015 04:21:30 GMT..Content
-Type: application/octet-stream..Content-Length: 192..Connection: keep
-alive..Last-Modified: Mon, 20 Apr 2015 19:00:26 GMT..Expires: Thu, 31
Dec 2037 23:55:55 GMT..Cache-Control: max-age=315360000..Strict-Trans
port-Security: max-age=3600; includeSubDomains..Accept-Ranges: bytes..
s:11301:4:178....0....s..C...0...........7......<}x..$.l.....s..U..
.f.....| 0...............Ag......*Ag....#.....s...].f......|${. .?....
..|.1.X...|........<'7#.......g....$.......6*.g......5...
GET /browser/updatechecker/?uid=PFBrowser&contract=C132BADE-00A8-4386-BB5A-D30720EBAB87&date=1430427600&version=3.0.0.4&build=gs_en&action=run HTTP/1.1
User-Agent: PFB Update
Host: update.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.4.1
Date: Fri, 01 May 2015 04:18:22 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.151..1..0..HTTP/1.1 200 OK..Server: nginx/1.4.1..Date: Fri, 01 May 2015
04:18:22 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Con
nection: keep-alive..X-Powered-By: PHP/5.4.15..1..1..0..
GET /chunks/goog-phish-shavar/iux_0kYqwLpBad2nO9MehhPZp_IurAi8AdwiLiyyVyY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/iux_0kYqwLpBad2nO9MehhPZp_IurAi8AdwiLiyyVyY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/Jj0fDeTYdxpkeaiXNqK7Ypwod0ePmqChmJPwBCFVIQk=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Jj0fDeTYdxpkeaiXNqK7Ypwod0ePmqChmJPwBCFVIQk=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/7k0BpIfoAfdNOp4XXRDJ3lpFbLKfBQF4dcG9tVcjVgE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/7k0BpIfoAfdNOp4XXRDJ3lpFbLKfBQF4dcG9tVcjVgE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab?3957b92ea85f63c5 HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 24 Feb 2015 00:37:01 GMT
If-None-Match: "80b4d90ca4fd01:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ctldl.windowsupdate.com
HTTP/1.1 304 Not Modified
Content-Type: application/octet-stream
Last-Modified: Tue, 24 Feb 2015 00:37:01 GMT
ETag: "80b4d90ca4fd01:0"
Cache-Control: max-age=604800
Date: Fri, 01 May 2015 04:18:17 GMT
Connection: keep-aliveHTTP/1.1 304 Not Modified..Content-Type: application/octet-stream..Las
t-Modified: Tue, 24 Feb 2015 00:37:01 GMT..ETag: "80b4d90ca4fd01:0"..C
ache-Control: max-age=604800..Date: Fri, 01 May 2015 04:18:17 GMT..Con
nection: keep-alive..
GET /chunks/goog-malware-shavar/uvvnQK5OYRoXYoWaTdJwqggbRc-DJ2gBOcXBNFFsliI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/uvvnQK5OYRoXYoWaTdJwqggbRc-DJ2gBOcXBNFFsliI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/RoD_pMkmy2GVGX7YHD_unqfRObz58DE9_WPrAZIRyVA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/RoD_pMkmy2GVGX7YHD_unqfRObz58DE9_WPrAZIRyVA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/8XiZtdDw1DowEM1tM0Tx3-7Fu0YDRjcZv3cZUNkgNEI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/8XiZtdDw1DowEM1tM0Tx3-7Fu0YDRjcZv3cZUNkgNEI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo/X8AUm7+PSp50CEEhJyjx2Kj7S0x8cjJXTloQ= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1725
content-transfer-encoding: binary
Cache-Control: max-age=530524, public, no-transform, must-revalidate
Last-Modified: Thu, 30 Apr 2015 07:40:26 GMT
Expires: Thu, 7 May 2015 07:40:26 GMT
Date: Fri, 01 May 2015 04:22:53 GMT
Connection: keep-alive0..........0..... .....0......0...0......N$p...v....1.;..vn....2015043
0074026Z0s0q0I0... ...................F....0.yV......{&.K......&......
.HI.<v*>.............20150430074026Z....20150507074026Z0...*.H..
...........S.~zg......y..... t.5...f..d....c..d]..0 ....7.oUTu)..;....
.H.."..K:<.*e..!.c..;{RY0..P8..!d...w...D.....7a..R..T..y....%5.vY.
=..fQ..`...g\*~f......I..-"1...E ..XQ.Y....YdB>\.....[._..R..]...X_
...z.i..m1jh..?t.3...Y..x..J...GVt..$.<.E{.,6....."..^.Q.....x.....
0...0...0............F...I]A([email protected]...*.H........0..1.0...U....US1.0.
..U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms
of use at hXXps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class
3 Code Signing 2010 CA0...150225000000Z..150526235959Z0..1.0...U....U
S1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1
VeriSign Class 3 Code Signing 2010 OCSP Responder0.."0...*.H..........
...0.........q<...A...#......A...u..Lz.............o..D.vQ%..s.....
..f....e../jI.d.W.....|K;.j5...#.B%.]..~S.... .|;S.&.....N..`...5.....
!D.p....M/.. ..;j...q..`6...2.Ck..BnLHvCZn%....,.w.Ooi..z'...\.Yx.....
.b..L...5.o..o..{..}.........%e.....N..._i........*Bc....:yQg.........
0...0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://
VVV.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's
CPS incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... ......
.0...U........0... .....0......0"..U....0...0.1.0...U....TGV-B-31830..
.*.H..............-..^.........f.P`...s.....8.....V.......... ....<<< skipped >>>
GET /chunks/goog-phish-shavar/ua4zZ337Cq0_RFw8igoS2bdlDOvEwayBRDquwRRN0LQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ua4zZ337Cq0_RFw8igoS2bdlDOvEwayBRDquwRRN0LQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/qnZ2HvzM37H8A8rLm-gJ0ujA5quc_OP3jtgBUBXCJmk=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Content-Type: application/octet-stream
Content-Length: 2849
Connection: keep-alive
Last-Modified: Sat, 18 Apr 2015 00:50:28 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11937:4:2834..bI....._..L.t....Z....mD)x..4.."..P......`..../..%....
..............w.LW..........5...)....!.].#.Am..3.Sx..s.h.L..Mu7...r.*.
a...K....S ...S %....'.........a.,..aR.....yWY7..LN@W. 0.q....GUs.x3..
!....%.o...;}...Q...El..;U..:...a...~x..t.^...._.en.|.*W...;J...;J....
..n..e~..Q..=h..o[8...G......D..........}.Z.......M.._:.D;..J/....<
.....>......s.....m.f.s.b.......eeG.;.8............r.6....5...zi...
j..b....4...aL...{..#>..zx..J}..RO..G...:f.~...oE...21Y...$.b..M.@.
}.2^..=#...=#.m....?]...k.....%....q........e;.{...... j..........\&b7
...2).=./..zLb....y......Q.....q....I......yK..Y.......F.....nWp=.MB..
7I8.......a..QA.v1i....0...S...M.{5..y....6...3.[U|..$Y....'....|..9x.
|./m........]....T.N...,E.R...,....;'.x...g.q..D.^9T.2.....N....t>J
..Z..5}......qk.}.>.B.8U.^.].c...#.#[email protected] q.
.S..^D.q8..A....so.......A........$T..r.[...1......j.....X...rF.F...]|
1.....]Le%...W..p....\.....*.............L....'.6u."..a......t./.0....
X....<.0).........F.........T....1.. .m...F.. ......k[.k.c...0.f8..
?.vRy.......a....q....q.x....|...;>........u.z.v.GQm~S..........6..
O3gp..F.#.M\.dBX.#...hm.....~/..........."....oD<.t.......h....1...
=g..8.^.........d..G....G.} ...3...>....v1...;.=...Z.&1..../......k
S2...7R"5_5..>....:....d.....XX......W...3......^G... F.......6....
6....d .p.......zKV..X.0..5.S.w.q/.>....j..C.......;N.......z......
.."y3...5.CQL.S$.P........>[email protected]...../E.~.u..&z..-y....
ZbZ.......c......h_^..........[.......=.\.$..54.[c..V.......!.W...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/47t5dK4QAJ1BiKhFGh-dfr0-SMJdePVognk64vffMd4=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 1627
Connection: keep-alive
Last-Modified: Fri, 17 Apr 2015 01:30:24 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11936:4:1612.r(.-.>..lP....&f.i...&[T.$#........f..*.....#8...^.G
..&y:.....1p..?".e.......*`vUjWr.Z.......:}...b'..........]F."..9.....
..6.d...9mh.W..S..?..]............3.5........g...T.....>W.Cb....1..
.]&:...I...b...t..:....A&Z..<u..Fa?...c.[......'e... }...2..Q......
.YT.......o!/........y*.L."......|...@...\.....D...,!.3.L,.......?1...
~..n<.O..L....x...l..yk)Z.[...UE.............c..Co......v...[IBK=.m
[email protected].=....u.kF.....o...&b7..M..3.yU.'.
4....^.`........?,~'.4..(9..9|.....4=.{ ..{...4z.....mm&t..A.Y...nI...
...Dh....Q..v-.9..3L.{dD{8.....(.T.................~.-...9.:B.tJa...b.
.....q....5(.........E.j.hf.5....8..;....&..IJH(..JH(.h..G...j........
...8....8.......&.- .yxv..5...K....(.(......a..xl...xl..V....)..#.9y..
b0"E,H....I.....o......v.<....>...y.sHw......e4X.1....*....=....
J..,G.I. 9...$....$.=.......Z........p.#....Nw..z .*Q`.< ..........
%..E..=........u....v..U#.6{.BM...Bx..%.2.f....J..9.....yH.(-.`..w.W=.
R#...j.$...a.GU...w.k....f.._..<..C:5e..a...}..`....#9*'.........[.
..}2k....G{)...........u.&.g...[GC..].4K.B.......eb.^..P6v.;.R.Sm....o
^.\....>.B.....=.v...^..T.x.....~.N.t.~....:..."....(..'.....w.WQtO
.%.. .....HC..E......J`.!...R....r.....,0GU...n.....'..HGJ.fO...-L....
....._.B....v..%.9m.Vh..p.U....w.A<...........g.*..a.J....\%......R
./.|......a4....i%J...R....2.7?.#.<...m....d....=...(...|...[..}.C3
HHS1T.7.Y...R.....e:M...G=...8...z`....Fr6M.......'.e.n?...".B..$i....
!6.. ....T..[.......S.v........~.foJ....B..B..5i....r....(B ..(B .<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/fhv1pKXYMHqded8rPqy-jx4dzaITAE7VPyaCqcXmEPI=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5691
Connection: keep-alive
Last-Modified: Fri, 17 Apr 2015 01:30:26 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11935:4:5676..bI...u...DMU....F...N...=RE..0..;..8-.........8......H
;#H......o...~.."[email protected].&3.N
....A...F.HS..G.r..;\.K...3..3.......".5...n-...C..M..;.`..7..\-,O...[
.Z..3=6. (.k....F.C.....;.....c.c-.*'.(...2.....?..Hxy.....VG..u.5..u.
5.W.D......].Q.v.F.......r..g....Q.IG..f...!...vvK....7..%1.G....(....
......'..Ek|k.c..ZT.....d...|...N.....L..L......Y..o......s........ ..
l6r<..A..r.M.].6.......e..........O.....y...Q...N..........|.....a.
.....<:K,`...|>...f...J....`p....]..kBuBa....$........<.(..w.
1....<{....*....*.......\3..T&......~.._....c.r..._.!.'.....&..n.f.
.b.=">...w./.........~..i...... M_Z...lT...B.xbT.`..P5...>hH.`..
........c.(J&"..P%.....m.s......2^.C...1.o....GT...P>Yo6.Rm.p< .
dq]..V.l..J...R..n.,...._&C...KD.V..#...-...F.t|.Z.[...k.o....:...7...
...A.HA}.G.n.H3.|$R.............:.c..S~.>..QCv.Q...v...........A:..
.J.y U...... k~.l...).....P...m.x}[email protected]........".G..R.U.~....
'....j....8...4 c.6...<. J.1...1}...e..O.........'E..\..j..........
g3.26..x.uA.W*..:p.~.....J ..M...&.T....d./:a.c....4h....1..G^B.E..'..
I.<.:.....0.x..N....T* [email protected]]....V.u.........[`...o.s..Ia.t.....
...=.A..m.V5.]6(...).......x.r.......W..x%S....a...a~.....=P...mC.F.1.
p.B..^.{[email protected].....\
.QF........'..M..X.L.....d.i[a].p.K?nk..L.....h.....Ux/....&..4.....K.
w.#....h.w.#.gg.._}R....H..d.........lEk2....a.i.s...[..u.........cu..
.eEJ>...*7..gv..AK6F^.Ca...;...................(.ic..PTk(`l..-.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/2GIB_v116SbEk07Zs-UKwNZth2eBtM7lJtrdsWr_ITI=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 2097
Connection: keep-alive
Last-Modified: Thu, 16 Apr 2015 00:41:15 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11934:4:2082..9.v..9.v~R....!."P.....O.!..Ea.j...L... .)4...w.].0...
.J.......I..../v..=.MB.Y....zO..u............R=/4....v.......Fb.......
v...XO.....a..8.tJ.a~..........'8......C.l../I.r.....>3......e..L.D
...9...5.b...........K....1..q(....n..j......[.ew.....'...)C..... ..#.
#...I5za..kJ.......l]./....d.\../t..J........J.`.Zh...^..P.....O...6k.
..&....3bQ..8Z.7r.0.~.e6.......2 .."...............'......$.......Fl.a
j.$.d5..iv...,.E.gAw...!.R.V6j..D.o.\y..'...-......C.......|:.|./m.I..
.<,.h.....*..q?.L....8}<...V..bK....K..........WK@q......}.h...q
=n8.PE..W.[.lA.&b7......./d.$..\...i7'[email protected].)CW...
....ag........e.d^.9..W..L{z....'..x"..4(D.......X...~...[...d......."
..d..2......F..u.R.}V.W....W.........a..Y.u....G......'.\....7.@~...G(
6.'.C...}....#..F.#...6c3......k...........$PS........g..`.x......M...
..O..HZ.'.)..a...)~ep.lb.7S.\..3..;......Y.c................1O..{.....
.x..e.,#(%.Pd..[..*L....~.>.L....T..SD....-.{.....%o&..n...W..F...B
[email protected].`..|..k.&L..;O.ZqO..E....KE...vW...._m.
,...e.X...b.r......... '.........V..<.....s.~v.......<r..ZD.J..v
....j(..*....O5...l.c..$...<..1...x.~Py.*.7$......P...e..H.j.0c;v%.
F.3.......H..S.cP.....`........5...m........_..P..%v=..AOk...&...qw ..
.<.YP.....3...{.Im....b....P.......f''.g.e.>..L.....i....$g...)a
....R<..#........\......<..).....'c...&._v...(..NNpP|._R.!...X*K
r.!.....{.u..m..-x.v.4..<......t..mC..p.T*..8..].U...e. ..E}U.....#
...u......3....a.4.-;.....O!..k..e[..k......60.B....n...8.N.7.\..`<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/FfNH48w7DUHj48hUCP8YmqTLg961wKPqU4prBE4tEFY=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 1597
Connection: keep-alive
Last-Modified: Wed, 15 Apr 2015 01:20:34 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11933:4:1582.P.....a.)...[...-....a.[]..Z..|...=.v=.1.v=.1..]T...n5.
nr..z4.m.;.(..;.(..E.....ua..8.M..._.>.................jw...*....*.
..#..1......%.....!.B..,g...c...mC...9.LW...gc)........j......)...=O..
....q.m...z.....$....$.#.h....`<j.?=.J.../*/...E..8..W.B........3..
..rw...]$...\..IV.W.......n...Sg.....o....9..i6.g....0.8yK......|./m.{
.d7...../.....6.ab.`....r./zI^.....dD..;O................\...U..TMY...
_..W.D..W.D.. ....}^L.M$..g.....M..`M.H...n...8#..3...J......e.V..{...
d.....j&......F9..#...b..a...T...*..>.K_.U...&M4....Z..!...Z^..l...
..'..R.<.-._..."..a(..cN.$..X}...q...n.Z6..s........|..........$...
[email protected]....,......V.=.....!...?.....S.\..&.e..Kz...Eir.p..6....~.X
......2_.....Y.U.....b...qL..c8....G.......L..mCc..rr...5..p.a87..U.`.
.0.?....K. .........Lxx..Lxx.2....{...Pq2..KH.......!e)...x....O....O&
.O.."?..v.....Z.R..........9y...........^.@......$P....hI..,......G...
.B..M..q..x..)P....Ak....l.!..... ..[....<z..Zq....=.g*..}... q....
..@|.F.....<.....MKB.T...l.Qrbr....;?.|.N..[.....cP....-6u.B....5o.
..u....c._J..e`."l.......r4..o.U.{.#J.....F..'....td..>...9..|.....
.@D.=*....M..`...R......... ..-{.x....$-..|>.R..?.R..?..t!...b.|...
..E...!....!...c....2.e"..Y.....I.KP.I.KP"......v....[.P.V........M...
.7.c..-mjx..Tb.(*..=./q...5(..>......J..I.?.>.B......m.)..P""...
>|...[. ..,e...U.E.5j5.z..W/.N..H...S.J..4....6.....%.|_..~.)h..N@.
...=.....Y.x...|..D......1...>....V.O.Y.T.El.T.El..d...YSOt9.4.<
.d..%..r..Sx&.O..t..&1.......$........CVU...1.-1jM.`.Uh.....u ).j<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/0eYbR7AY1kV5MF7bqScyKku40te-z1-r0eu-Er90fgM=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 2810
Connection: keep-alive
Last-Modified: Tue, 14 Apr 2015 01:21:00 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11932:4:2795.Qz....b..C].4.....%3.......J9.........d........q&LW...l
{.r..#...w..~0....M....Ke*.a....U...D..l/....uN...bR.C4..wF8....3..A..
.~>.&.=..z.{.a&......G...M..M.DP%m...F...8...(.r.....q2w........MZ.
...rS..`....._.>..u..w\......{X.....|U.....>../..uD.....u....h.Z
(".$..)..%Y.~..Q...Fz).....A...*......y>.>....8.M.#..,g..~.z...u
...).=.........6A...J.t..a..m2..j..k..x.a.........u.8Y.%.!..[.C.=...].
..T=..6k...ZZyX6..s..c...m........*j......^..Q2...X=....%p.RM.....8'.4
........;......U...3..d.B|{Q=L.X."75..`.#......r.L......L......Te..p..
-......0.5E.....;..P...#..l.....$.1.RU$tW...R..>....t.....}....=.|.
/m.>.....[e.T.h...$X........D...d$.7.H...d.%....%...'Nu#.7r...[.X..
...V..../O..........$..;O..k. ...*[email protected]@...._.,.})
wC.{.wC.{...7.V.]hCHV.....R.R.|,1....V.......M;....*....R....Oe....>
;....U.....7j /G.mP..j.3CU.......h.....7..X..d......DP.........{...&`.
......mE....l.]._K..X.4_.d.......C\..B'.JX...$C.Q%.`........N....ER.^.
;>....=O..<t...j0,.......A....A.F.#....JR........17......_..9..~
Ff..KR.5(..,x.9...E...2`...p.G..Hp:.....N(>.K....a.=Xa.'.)..4.w..$.
...G)n.z;...z;..Tn..g&........ip.W.{@.. ...Gs.W....t...M/a.....7..R...
.R...!...5...Ds..B..e......'..ykR........1....=..n...wS3.r...Kv.....z.
.!.}......}..........6Oj....4].e#/.sM....$<..c......[M.Q..,s...jfi.
.jfiwg.e...k.. ....VS..'.e...........r.z.i....i..y3....@..#'...jk...p.
...........}.2yA;.@.....$.....?6EW.1....S.............e.l>...m.....
...9y..V.t.w.........3.1.%d).}...%....Z...^..L...`........1..,....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/InCnLK-Y8LZ6JG7r-6OZj7o4DrW6iCbFTv3xbble6yQ=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 2845
Connection: keep-alive
Last-Modified: Mon, 13 Apr 2015 01:40:37 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11931:4:2830......Zo.F.....0%.)...w...!<.ql.Z...nM!l2....OV.=R...
..LW'q.^P......8....3.4.{.LW....2.|-..S!....X.Z...r.........!.......4.
=.MB..<B...uN....].D.y.B)...F.#.....V$....1q.h .I ..W....i4..bM....
.F......_.}&.z.][....E21......O!.^.(.r.L~.)-Q;....n..4G.....i.i......3
_C...p!....1.."H...Y.&..E....I.g.......7P8i...EV..B....e$ljc0..w>:.
x..A..$.sS..G.S..G.....:.....r...&.....u.kg...r.......k.*....p.F.$....
.....q.k.v.']....z.(.".....Y..=.....V..bI.....E.m...4..........(..vF..
.f...T....].".....2..N.&.*....&1v.5.W0.5.W0.....g.\..]KT...*bj.?=../.R
V......s.{.....p\..........=.........WM.........w..%..{.)l.4cY..q..@9.
..SG..J..I.oB..3.J......4|YE.a>....S....'..9.x.........E......?....
..uD..?N4.......4.. `!..\V.."......;.$w....h=......V...j.........5(...
.....4...-........BjZ.-..S....N................e(D..E..g..m...........
[email protected].......=D.......p.@.*d.....'.*1...4...a...A.Q.$.L.b.Y..4....
.>j.RE.^.57../.......$X..L>.qE.#?.......h....h!<SER.Y..$.<
..p.F..p.F.DP...DP.............7...M.S..P....&...W;H...Q......l.....3z
....w9....j.......m.M........y-.B....%.w....."...Z..}..&.....?.^.|.j..
...%..........5..L..C/....4LF.. .W...i....i....17..EW.N.h...,...,.....
...(.5k.93..'.)..4.cI{'/I.......~.S.\.......<.p...IG.....FQ..t..x..
..b..]$....~...M/a..A.e#...`.g.N..~.X..*...8.....=..O....x.......9%...
9%...1....t.V.~.......q...&......q.'.?.{|[email protected](
A.Y...4._.R6...2.).>....~....GU...... ...&.T.._y..._y.8<....v..K
.]..N..M.?......zm..n..........x.^..0..............]...W.......(B<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/S7ivwxHcennvSEQHDpfGAO5hLoKWJSnvokyqYRJyLx4=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 1100
Connection: keep-alive
Last-Modified: Sun, 12 Apr 2015 01:20:47 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11930:4:1085..[.z..k%........f.....x ........J...r......f.b..1?".e.O
..T..p..L...P......Z..o.K%.B....v......O.Y...v........X..........7>
.N.'.e..8F G......16...R.Z.Hl...<.I..bFa?..........8..W.t.n.%....%.
..Q...V.....2v.x=.'....}.....8....z...?1.e.^;.{.....<.a.v..a.v...Iv
.,.*..e2..8mOw;<j......!"....N...4t&&b7... d.D'......G#G.1.>....
.,.......j...]#...)...u[.['..p... .1..s.. ..l..O.I..0.#...B.|.c%...c%.
.Zh......H........._..9...al}...;...~ 4..Ngp.......$(un....t.#..A.v...
.n'.....(.a. 2...3.....u..|. ......["b.9y....2.T.c.......G....B..?.:o.
.#...>..........|....|.$>..g...k.8~..\...B.4......i.i. 6.....O.&
lt;.....z.... `.0......1.R9.#.6{.83(.._V>..k...2_.....I..\.......L.
...u.-:5e.....b>9z...<..#.h..C....<....<..=v....z...\[email protected]
=.4 .E...x....h.u...D9.op#.2..'.ueb.^.Q..<(.5k..M........e.fx......
...BV....I52..,.....~..\.>.B..zl...t.w.]..j...[3.....ijf%.... .d...
.... %.9m..........v.W.0....t...d..y.W...be.........u......k.,.]&:..D.
R0.`.#.(.>.&tZ*.;./.S.............DR..t.%.z.)...Y.....v.K.h..,.#...
..*L.......=......BM..d....D..)&Fi...]...0...M6..8..d....Q.}..H..V=...
.4.q.'...x. L..?=c..mN..........
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/YGfxA6S0Iv-jWOp8V1Su16gcyiJwlNoX7fjo0kbnqn8=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5479
Connection: keep-alive
Last-Modified: Sun, 12 Apr 2015 01:20:57 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11929:4:[email protected]'..LW..{x.......8....?...=.MB..
F.......o.........xU............4sb.....I.e`.v..x\8...aY.t.I..%.!..jx.
..T....4m.=........;.....F.u!.......90 .).....uH#....m.wE...s...{).Y..
.2....8.|.~....%.....=.(.k........,"..u..'.(...c]....?.'u...)s.)h...T.
>T...b...b[..... .g]A....8B.....<.5(..z%Y...$....l.........j.=D.
.c.$c5.4imnb.....L.X...>z.....qU....l.....^......q..'.q..'..nB.`f.c
........h]|1.....]ji8{.Hc.W......E^..X........Kh....e.G.....V.W.d....B
.U......q..,`....,.......#...w./..w./....N...... ........`p... .......
6Y.m.._Ba...'.#.U...............*.a.....A..T..G.d..P.r...RIj.C........
qe.l.4`..#~>.....">...F..........oLC........o^J..... &$...&$..$.
.m...6....l%..S3....n....`...eo.'.........eb3.V.....k..~..M."..g...Dm&
gt;&.77^E.N.W..c..[[..E..^/../.9.yuwT."P.X~L.R.^....;.v..|BiC.....l.TI
[email protected]..}...hy(T0X.]B...s.....y..C.n.~..............%..{s.........
.....E..:............. ....36.........v..:[email protected].#j...4......
...&m.V5. y.=SB...]..g..(..gcBa.R./...y..Ul.d..H.s.....[...8~...{jv.e.
z...dlnO^...~T<}.k..d.{j&o.F...... .e.x.x..@.$..[.W:D....ow Q..$.?.
.z....~._88.X.....H....K...........q.Q.-......3...p.....VfW.....O.....
...e.{f....IS...ZA....}s.L..o.#.[..s..A..e.x.Tv...Tv..;....M..T.:....#
...b^>.b.K.I.........p}q.w..... .T......x..&...f.n..j.......7.L<
.....Du7..1..,../...{5..h.............~....|.KLok...?.......mR.VK...f.
..!H.M)"...%...0........U.E....*1.N...a......Q...........8[u...A.;.2.b
M.....g.}x.Y..z. ......(..A..x..lJ.E!....k/[email protected].........<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/0CUhV4Pw6226fhXk7ayz0zEcPuXwbi30h1RwoGHxmII=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 3022
Connection: keep-alive
Last-Modified: Sat, 11 Apr 2015 00:51:09 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11928:4:3007..U.......Qz....|....H.........EP....)O..6.....1i$..Q...
.......).kk .U..A/.1..w..w..-:.&...|..wq.I<'V..U.`....... ....(.5..
..3{....F...aR._...?".e.'........&...t.,tW. 0.....4i/..Ja....*K..{suV.
...lER.....;{g.:}..]Q..{.......K[."..O.tQ%.....}..<..c..q.}.A.v....
,...p....5......g1.......l....eY.j.........4so....|L.;{.5..z..G....|..
,.....pR....;..".HMFa?..s.s.......m#.2W....d.....B.M:.. }...b.... ....
..aR..:f..Q.......K8..-..A._.p.1.1.......[..lK......n....q...CE......
...=......WN..\..h..?1.x.H....[..0;.....J1(.......[}....".v(...M...&}.
k.....=|.......!...a..f.a..f.........Bj4....F`....}G.vV.u......M6[....
....a.... ..zY.......[.X..U .4&....v).."J0...5...|P...g.'X..'.4..>.
.....:..t.j~.'C...9s._..t...2.......Z..i....8$.i.d%.|r......\*G.6T}5..
.......B.3..9..?s.$........c.4.-._P^.,.^......~...1.t....D..........3f
...=Q._:.~\.uIC.....e....Ts....*.c.c...q...!.or....0z.E.e.....1....n.#
.n.&...>BHn...UgHD........P...S....._$....o..........$..9.Ba...V..L
...n....V.....>..B.C....8........_....../[..BY.N....G........}..v..
Lr.Y...k.$..a?,.........&.M.O)..;...fy.3.xq|;j.b..Kd.Zl.....>.S.`(#
nj.K..X..w>..z.!;..;...`.C..V..7.a...&<...3........... |[..~CbS.
Y8...#../. _.....`....~E.CU.,j.-s.,S5....R..A....^.._................~
kzK......a....' .H@.... .U......n..(.(w.oD'...>........>n.R...l.
....b..a..h...'T(..&.^...i.8&..1..s.~.b2..w..a[.....?..f........`e!..'
.....u...$.Q...|[email protected]{...,.Xb.............9J.6u..0.-3..$..(_.
.9.|.'r...[.....5(.....^.....Z.....E.6YQ.S.\....*R..t...9..'..i.).<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/CBZSVliJ3jUTEovyUiGBSNmHnvKYhm043-gh-uvUrbg=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5627
Connection: keep-alive
Last-Modified: Sat, 11 Apr 2015 00:50:52 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11927:4:5612....../"B..,E...s..]..........N......;.(.2....1.]..b...t
v.=.MB... .8L.L.Qa....xU...qE.D...C;.y.Y.....e..............6.........
...._..!..m...F...x#>.%.!.,[email protected].....
.....<..".5...2..L...E..x(.k..3.j...7&.y......?.l/...17.......^..u.
5..~W..........FU....>.. ..Ho.....X.....N.C.}.}.....nwn..3T.D._I..1
.`.Z/.......[F....#n.(,...k.1...~.......YPZ.......N...wR.B00;.3...._?.
.....].Av.....:9`..]y1y2.!H..O.<.......`..d.K......O.......S.J...|.
..........<.I..~....`?....Lq....!.jZ.....Sa...X.f.)....a.y.u>..C
....~i..2....8.sUa....<........................".....d....|..v.....
0....r......-.By..|..Ax.&..h.wf..fM..O ../W..............a_.P.Ir;..y..
....jx.8~....=......l<.*..m.......7.....c...d.zs...K6;.....a.....F.
..h...-.......A.k...=...-...m:.....KA.i.0.'.Zi...r...?...u`.%.q..E.*..
......H.3K.{....qh........b.?..k.#..f ..F.F.H.v.G....e<..I.,!.^....
..$.\M...)..O..h..s...Ry..jiZEE.v._bf`...&...@#.{V....i.Ib......$ti.S=
X.........."...o........x.7.>[email protected]..{....@2.:....h......
..M$...b.p.....r^...#..x............5....F......c^..FP.?C......4.k.4.j
..Zu..W!.Y1..~|..G~....A.....!....twow Q....l..S..2OI.j.`..<.....%?
..C&..o......T...7.$...K.k..(NVA..T....Hd`..V.v.....i^...S......].....
A........s..)...l~.Z.:......u.gg...:U.E.x".2m(}.o...m.........;nl...%.
mT.....<.q; ..q; .gv...: .P|U....x...uX....".....*P.VDu7..n.p.../..
..!.(`l..T..z..^..0t.z..^......c...6k....v..S.P..f.r.c...a.T.n.:bq2w..
OS..{....L....4.....K[[email protected],..k`...Z$......}X..q........ ..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/kM4mzd_BuL56ZUjvvtfFU4OlLoZ0tcQBXhFE43FTkn4=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 2769
Connection: keep-alive
Last-Modified: Fri, 10 Apr 2015 02:21:03 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11926:4:2754.../.....IP.....~.C.GUs.M5..o./..f..........R...A/.!P...
Tl...(6Y.Dg....~.FO.Vg..GR.2..l{..|.$..?.....7,.J...:..K...t.lZ8......
.. ....S....*....*......5..............5...T..H`O..j.N..<.....x.''.
.r..@|H..E.,)}.W.X{Kqx...O...}..?.......,........b...:2.y.Q^<..c.nB
...A.v....;.j.....2t.....e.@..."u............T...3{.;<.......Y.I...
.....R.f.GU.07..d...Fa?....?.........yI..."........[.q.<.6...p...*J
P.....xW.x.Q.......-..A..._7k7.........u.G......f...?.CE......K.....J.
...J....D..?$U...?1... y...........i.\....Ip....BD........y.....q...M.
...Z........ZDQ9....W%#.......k..L.I.......^.9.....\...T./...A.~..`...
~... @... @..[.X..._,.Q./..u4.jZ.-.|].I.. .........-&b7......'.4.0.Aj.
.C.......>..:..*.UZ.....q%.Y.MBG.L.......... Ge;.....wef.]..~nm...X
]w............k......,.5Ny.;*$.........u.RJI|2h.k.W.}$.p.nS..].{K...0.
.M.ej7.`.q..Ee...._..gM.................*.{.*.N..GKA.Y...m...>...I.
.sX,...M....pSx.........F.....l..v.(w........pM.X..5....`.........M./.
.................Q...g.T.,.Y.P...?".e..ZG..Yu9oJ...O.....:...'...@..*.
[email protected]!4....g.b......&....s.....@.....}.._..9..?;.x.G...^..
..K...E......-.".R..)..'z...4.'{........|...|[email protected].
........n.......CS.\...l7CK.. z...L....k/.7.b.s......QJ.4.}i.J?<...
...s......{a<..#...n....Z.....h.......?...\.@.]..Qh..G..]\.s.....(x
.O..h.&.KZ..-...X..{s.....y..........`..]@.........`.\.f.........s...M
j.u.&.,.. ..1v.......!.Y........(-..E..J.T......n...".h...|.4.Z ...L22
.Il..ASU........&}...b...}.H....o.......o^.Q..s9....t8:r'.....J..V<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/qZC_0gz5QY5TFOHvTQ0KoWe5B3G87JxkyA8cg5HkIiM=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5695
Connection: keep-alive
Last-Modified: Fri, 10 Apr 2015 02:21:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11925:4:5680.......TA....N.bn)`......;!.eAM....1.=x.")......S..(.u.;
..I..............st.]x.S..1r.1.].....!.~G...h..b.%f"..=.MB.oq/&.......
F......D......,#..........:1....~.2.$...6\.^g....&......j.Q......R...\
PNQ."..).u^j0..M...p.\K...\K...%.!.Q..-..3p.[bK.?....\.E.x".\".....~..
..}@..w.^,.-.\.j(.k..t.8i.R....7&.}.2,...?.^eE...N...\...G.U. ....f.R.
...T.W.M...Ut...:..e........9.P."...I....}.}...x*..C..A.b'b........Z/.
...d....L..U.............58O...\...[....[k.c...d..!.:...P.8......H.B..
.s%.Q...=R......P.x!].Av..x...=S..%..P.....lG........OMG(j.b...A......
.2J.&|~..%....%..O.O..O.O..|.....y.....Uh...i43..p.tq....L5....R..\..=
w./......../W....C\....hFD\C......M..f...0.&.=.-....k..7Ho..7Ho..1..:.
...........$...$y.9..... .kci.j...{..r..... ....B..........g........zg
.R..B..n....2....2...fM.R."../[email protected]=...TJ..Jc.mG....s......Z.D..
>..a.'...4..Fr............\..,.....R..T...I......./,...........s..y
.J...p.6%.(.H)...vDKS/x.Sb..L.P.......O.Gv......e.r:..~..U.%DQ.r..q...
*..c....J.nA.......u.[~8.?..@._..].."..8..z.1!......Z.3M&|G.P.. .'_&J.
v.u..Y.........5..E..\[email protected].....
K..1....d.[].....Gq../....0.i.?M.F..u..T.. .#.......:/.....c....[F^4..
....:*.7..9..\}.......G...{.....*.A....5v.....-|S. ..>.>x.g...].
$..R..C............t.jp..!\.../I...l.c.QJ....<6.....a.S.q........-Q
;..'.>,.....VD].5j5...}....2.. .L?.!........sM...sM/......!...6....
....=.......zW........d.r...`b..3..2...... .6..........aY...z.4a_y....
.fP.n..uN......KA7.U...}.(t.V..6q........8-...../s...2\.a... .II..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/gGlRwSx8Dzo1uJ0yLqn9uPHpLoXJEVWw4QTefK6Bsn0=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 225
Connection: keep-alive
Last-Modified: Thu, 09 Apr 2015 11:20:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11924:4:211..|.................4.S..t..w......e4M.....I....'..HGJ..)
....V...D-...........#K....B..-3.....hH~......^*W...U.mY...E.j.hf.. }.
..2.JH(..JH(.n_D#.kH.....[...}2..Co........=....J#.<...m.....9.0..&
[email protected].....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/TehQ2ixiUtxEpr0ycrxRN_kCJgW6Bhwks3x4Q93OUW8=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5591
Connection: keep-alive
Last-Modified: Thu, 09 Apr 2015 11:20:44 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11923:4:5576.P....[T.$...N...=RE..0..;..G.r..;\.KFa?...c.[H;#H......
.xU...<[email protected]..
..F.HS...".5...n-...C..M..;.`..7....D...,!...?1...~..n<.(.k....F.C.
....;.....c.c-.*,/a...%.T...?..Hxy.GE....d......VG..u.5..u.5....x.(...
.d.I...|.*..A}..:..q....1(.....m..W.D..v.F.&b7..M..3.yU.......r...vvK.
...7(,....X..>.K...C.$..3L.{dD{k.c..ZT....9....M...P..dC.k..N.....L
.JW.....0Y..o......s........ ....A..r.M.].6.......e.........e.D.......
....O.....y...;....&..I..|.....a,`...|>.......-1.L}..`....#.f...J..
..`p....]..kBuBa....$........<.(..w.1....<{....*....*.......\3..
.w..(..a.T&......xl...xl...r..._.!.'.....&..n.f..b.=">...w./.......
..~...5..{.}...lB...B%-Ef.&2t...mC.1..s.............1dq].p< ..V.l2^
.C..R..n.,A}.G!...u/.'..KD.V...Z.[#...;........!.9.o....:...7..8...A.H
.n.Hs.._.."f..........:.c..S.QCv.Q..&"......3.|$y U.. k~..[..l...)....
jb...P.x}o..fV......fCo........".GU.~..QF...7.p0.7.6...<. J.1...1}.
..e..O.........'..V..o.2.........g3.26..x.u~.....J ...1..G^B.E..'..I.&
lt;.Bx..%.2..:.....0.x..N....F.fR.k..:...........~A.o-....f.......r^.l
c.a......[`...o..W..a.t........=.A...]6(...)1..~.r..s..Ix%S.~.....=P..
....&.- p.B..^.{[email protected].%.. .u.&....
.....g..........XPeb.^..P6v~.._....c.....d.i[[email protected]
.....&....K.w.#....h.gg.._}R..a.J....\%......R....H..d..T....*..O.>
.ja4....i%J...R....2.7?..gv..AK6F..$]...$]^.Ca...;.M....2...(.ic..PTk(
`l..-..[.(B ..(B ..^..>_b..,.kJ..x-/.......{....e\....:.q2w....<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/ttESbMYCl0F1zsR55cKlwxZJYMsyLjORkbBoc7Zm5gY=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 4197
Connection: keep-alive
Last-Modified: Wed, 08 Apr 2015 03:00:57 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11922:4:4182.P.............M..)D....N....y=.Z$G....H^.... .i...k!...
..K.C.-.D.........||.....?wlZ.9.g.....N.A.hn{3ACc.....6x.G.K...b.P.{..
.........(%|l8Pc...b.m...r;....5E.r <...4...Q....R.s..... .)PY.O.j
4.........)T%d. .m..U.}..;{.5..\.gFa?.......1.....I._.R?-...?-.....g..
...*F.~?.i.0..n...t.=.....|.}.....M...3.L,.......?1....[e....>...1.
...Z...].{.1........I.gr.....)q..........,/a...v.....Y..).e........S.4
...Tn...D) ....._......x.P...o/...'........ ..R........iX..Q&b7../..!.
[email protected].....)6...\....vvK..........0..*"HD.
..'....."..P..O..S.~Bq j.y:;z...,.......(....JW.....;.......I<\.!..
MR."...}. ..p].6..~....z...].....xx.bP"...-..D....;..4..;...u.c...e...
..{v(c.FM.>[email protected]~..1h.....2...H..a=z..*..u.....C].4.....
.]6@../..g.......7......eB..94m.N......%.."Z.X......Z.Y.......R.Bx..B.
....r^..$FI...X.,.Kt0.}.9....mC...mCC.?......... .x.........p.....nb..
...0.7.u.z..<...u.&.#..........z..'.7......W.....Y....#'..M.'d.W.&g
t;.B..m.)H=.n<...@..>.*NJs...;]Y}WU[..s9....1.5...j....Jh...0...
.B..j0.Q......_y.....e..{.....].c..2..#.r......jw..d...r..^I5.YF..@7G.
..I..j..k..x.a.w.#..w.#..........a.J........1...>....2.Ay8W[.......
....R. ..>.&....&WU......L..H....H..S..........uX....".g.t....b.a.T
.....n.:b.Ag...Ag..B....G\`......Z...rT....6.U.E..3x_.#3A..... .n.....
.....[.....3.... ......A.!W......m.C&}........I`P(7....k...R.<.\.(4
."{..........~.q..bS...S...r...C.....B-...z..Px...R...Cl....L;.K.NP(H.
r......2W....d......BDh/..... 7;.J.S.......=}......\...9.........a<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/ueUlg7RwaptET2592qwxtihIaGM0Zy7pKwY5E8kERZE=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5843
Connection: keep-alive
Last-Modified: Wed, 08 Apr 2015 03:00:08 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11921:4:5828.3..6.3..6h.W.....yZ..N.z......{..w..[qKY..d...[w.......
;oj.D....Y....w....u...T.#.....x7..=...t...%....f.dl...$t.^..-.'..(^..
.7<.T.."..z.@Z......_:F.$..P..neG.;.8....%.!.].l.6.H:.....[.C...F.u
[email protected];......c/......y1..R..k..9....7.....d|. [email protected]
.dy[...&O..P\....t..$.......nr..z4.m.f.R.....<....O./.....]}.......
,..}..<..... .g]..q..)[[email protected].......".f.q.`{.)fd....u5..
-.A9=....p..K3.......R..x.....k`..j:_k.c....B....d.D..1........*..q...
n.Z..;..E.....L..R..y-.....F..lc..{Hf....).......H..q`e..[..Q..`?...W.
.}...n"n_,`...:.....R....s:..47...N..f.....Nd.} .....x.a.....j.U......
m{1..................2.$...6\gm....f-....Y.<[email protected]
g.">...`...=om...v.=......Bc....5.1)q.$..m........lHC.9.N..$..I&..f
cH....<..........b...........0W.]FFc..M[....y.y|........;...-K.FY.R
m.NO.7....r......?.A:....$...O..B..".xC.Q%..ud.K...2...3...../. k..[[.
.......4.P*..S.].(.}dvX...b.F......@....*....N....uzMI.....,..1$..Q...
..........R..:[email protected]........ 4w.r..l.T~..h....
.m..]..V..y;.h.......Fo..2..)....:.....w.H....c......f...>..B.]..W.
.c.j.........}..y.=.2..`..I.w.<...P. Gt&;........9..V.M...T... .v.,
........C..=*...5~..2.......4.....{..ow [email protected]...~.:.
.]........I..K........k..e[... [email protected]
....D(D. .....V.O.t.....<....<.....i^...J.......(.i/.B.......Nm.
.7._..~....~.......PF..vh....^...o.......>....So...gv....j.C.2o.6.C
..#W.M........:.O..i..}........`!.p.(`l..d...9.t..,*g..|!...^..q2w<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/lRSiPs_nDoWaue8Z9Qu4rVd7SFCZjV2jZ7ug0nBaMDc=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 74
Connection: keep-alive
Last-Modified: Tue, 07 Apr 2015 05:20:02 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11920:4:61...0.........A....A.?......g..5.6*.g<'7#$....is%..is%..
...M.'.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/ituihT2nIuOO6K7aEfwTkyN_MxBmCcdyz-1vcd_m2wE=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 769
Connection: keep-alive
Last-Modified: Mon, 06 Apr 2015 00:50:06 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11919:4:755..[.X.....P.....O.!.j........m........>Sj...........0)
.{t.......P.._2..,.j,..D'.... ;Az......w..DB\o...... .. {..$^7..i.i. 6
....Su..J...>....H....5....M.."G....s;....'wLe...7....{z.....$b....
[email protected].'..p...l.y..p..L............O.Y7X.#..
...bm.l..(Q.ja.....k.........:......'e..a.J....m...%.T5.z%........'...
Y\(..*...-.`.........[....[g..y.z.V.o.%....V....H~...;....6.#..t7..>
;...$........_."[email protected]..,G.I. [email protected]|.A'\..z....1..8n6....M
....MFa?..,A\_s.s.v>q..BV....I5?v.3...............T.x.v........\...
)..&..........O....8 ..#/..Q...}. ....I.Q.}..Q..e.l...XN.CE.....p....u
....c.....9..w{..,Cm_.$tW......-F0L..?%..........P.....=.^4..W.1.\....
OR......... ...l.)...9pY.j.....4...3..;..\...6.E~.....4.Z ...ASfO....6
Efeb.^.:%."....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/mW94EcunmakWRnLV-MS5hq-LjJaiSXJCzVFzlQt6-NY=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 6083
Connection: keep-alive
Last-Modified: Mon, 06 Apr 2015 00:50:07 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11918:4:6068........O~.xj..b'........).k..xU.%..7.-.....*......oU...
8o..%.!.Q..-..XO...@[email protected].,_].R.....
...g.\....A....A\-,O...[.=6. @./...r.W........7.L...p..b(.k..b...O.W..
O.W.......|10..,"..u.......Rt .......rk.'.(...qY.i1.....:.......1...D.
....D..1 .$w....h=...^...Mt.N.Af.N.Af..Ho......*i....../`.MS^.{w."...2
.Z.......X....h;...=D.....h.a,c.... X.^.W.....j.....u}H.....S._I....8$
.....c..D.....Z..W...\.t.......(,....Md..~x`..]#...P..._.........J.~..
.TW.h.....iN_.'.)..a...4.w....e.."...........6E.%..`?.../....L,`....,.
.\[email protected]}... .......zh...N..>.a.....\.Ba....$..;..l.wf.
*Mq.....33..............x.^.$......../W..&...$..m.v.FD...l^.....Hs..Y.
c...F}.G........B-.B.....-..\.....^[email protected]=....]
._K..I.P..-.....w...`.....k"..|......P.Rz.g......U.....vDKS-.....}..J.
....$...[v9:....(.^..B..2O.....e.J..6..x.Q)q_-... ..u.. ..v:;..(..(.Hd
.]........... 2W...rbr.7.&......d.._bf`_..zi>m\Y...)0....g\...r.0c;
z.U....E..@y|..Qd........j.e..Zq......u`.2.9.%.k:...&$.C..uf.d`..&..N.
.[......|.....]`U...........s l.b ...3JK.......y..C.n...._. ...A.W*.A.
W*.@|... ....{......x.Zu.nX[Z..~A.cp../3{......;L.h.U.. F........r^..
. KKW......f....#...s<......W...`.....H..*.vs.......3...o..:c..-{..
B...T.....'[email protected]....>.C.~D..&.R!.....qH.5A.22
.(.X.d......!...g....g..d5gv.1_..P......;t.@....@[email protected]:.0.e!..
..kr6v....qD..........x.....a.. .....R...@.!{...C:.R.{j&o.f..? 9.C...V
.*2.>...k7...c.....c..G....lo....o............s....s.....8...k.<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/3Tj0bVUpKpSFrZPgfwQzX2xTELkpN6SDPWBdFeZ82hg=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 5413
Connection: keep-alive
Last-Modified: Sun, 05 Apr 2015 11:50:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11917:4:5398........S.P......J.~<)..mPS..i.......D.%b/;.!.....M..
......%Q...)......J.5o..Y0W.......fO.....|.H......^.1...%..*LQ..%.!...
.!.=...na...)[email protected].`[email protected]...#.*R..k
.....YT.......\-,O.Z..33..d...].b........(.k..C.w}...=......\y.....N..
...?.1LhP...hP..X....d/..8\.....vIX......L..2.R.h=..].]b.m......l....1
r........F.O7.......%1.G..."..a.....k.c...0.f!.:.....#Rs8........P..az
..(.....P.].# E....."...,..S.\...s.B..a./.....hY...).LG..Na!(...yy...N
.Pg..........8[&.t.B..%....if.......".1...|gS{._..8v K.(8......wir..k.
.....h_^.w.?....Y..e.,.ZhM....C...C.........P... .!....,....91H......Q
(.U....(........M...2......s.hsq....s......3.)..T&...C2'J....[.w.C....
W.2Ov.....Z.R.F...UY# .......i....1..tm....Y$..m.$......l4..v.......B`
.9..e..*.A.`.....o.....). ..=.8.-.p_.D."..J.j..v.Wmc.........S.....x..
.i.h....lb.;[email protected]..`E..iF(...v.....[!..F.R5....P6P...`..........
.h.0m@t../........R.../....'gk^.b..h.~.c.I_F..*B...Q.3.........>..C
..~....P..2x.Zu...?.g.L..g.L......\..8..~A....OS..?..f..gH.k..wl...r^.
..U..v...L:..&..P....P...................J..K...<.........a.2/~....
..)K.)#...{.Z~..(#A....{........xe1O.q..}.^.V.O.......9..W...`.{b.....
..*P.....x.V...(/..]j...r....v.......mC.ZS..F.1..y...e[E"c..G.......K.
....0.vI...n...z...(.b..r...u.z.W.u.v.GQ.L....G....Af....$.MD.../((.J.
....'J.R6.....,/W..........&.Q..^/P....v...W........gg...-..\....fw.Q.
a.J..l.....2..@s........_..K..>.....D0q.&...y..&-1jM.`.Uh(`l...qPmv
..1.."...g...j|........=..j .......q2w.....a..{[email protected]`<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/QWJEMg5X_Yrd4iTgGTm7iFacTsiaurN1LIdYeVk8r3Y=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 4183
Connection: keep-alive
Last-Modified: Sat, 04 Apr 2015 01:10:08 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11916:4:[email protected]%.B....v...I.J.Ki=.MB..F........x
U.....[."...J .b.....I.e.%.!..jx...T....4m.=........;..Fa?..........8.
.W.t.n.<....(P.#....m.wE...s...{).%.....=.........w'.(...c]....?.'u
....K...........A....8B.....<..$....l.&b7... d.........j.=D..c.$c5.
4i.ML...ML..X......q...........^......q..'.q..'.#...B.|..|...5.aa]|1..
...]...E..p..-......3..X........4o...s...F...m....d....B.U.e.,.(;.....
..#...w./..w./....N.....Ba...'.#.U........T..G.d..P9B.v.z...C....qe.lG
...............oLo^J..... &$...&$..$..m...6.V....WW26...l......`...eo.
T0X.g.\.9...k..~.......Dm>&.77^E.N.W..c..E....../.9...S3..l-."P.X~L
.R.^..v..|[email protected]..}..'......|....|..z.... `......%.... ....36.
w#.....1..W....d.T.#j...4..........R./.{jv.e.z.(..g<}.k...&cBa.. y.
..~T..y.d..H=SB.m.V5...s~...nO^...d.... .e.x.x..@.$..[.W:D....ow Q..$.
?..z.X.....H..]B...s...D....]s........E^.eb.^.Q..<...C....CfW.....O
.p........s.L..o.#.[..sk.......2Tv...Tv...:....#...b^>.b.K..p}q.w..
... .T......x..&...f.n..Wh..33.a.(.5..5p..<..S.........j.......Du7.
.1..,../...{5..h.............~....|.KLok...?.z.)...Y........-F..f...!H
.M......f.........~..,.#........u..|. U.E....*1.N...a....Q....x=.bM...
..g.......(.......2.~S...O..@5c..^.........-.............X.9y..Y.$...2
.a.v..a.v..v....w.g........D..!..2..|J..Z....>[~Y.........../.g....
..6...j.o.....m......Na...,......Q.........t./....p.}......0...W.4^Yjc
%...c%..|.h....Y,6..s.ME.Q.J'..q...N/.n...C....'..|..k.&L-.b..b./....:
.j.mC....._..W..........)@.&Oz..! b....../h....[....q......2ay.x..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/WNYAEB6kHQLqH03rTAKlV4BJxP2z0dd2ogHtOf7kFoU=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 1712
Connection: keep-alive
Last-Modified: Fri, 03 Apr 2015 03:40:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11915:4:1697.......,E...s...6.....DP....)O...#.......aTi....."......
.Q..$k%.?....=....G.1.]..b..Wr.... %vO3qh?..\u....^.....xU...qE.....lK
..............5.....k..7x.&..h.wf[."..O.tQ........:^..2.7.....A/.1..w.
.w..-:.&..;..".HMFa?....m#6k....c... ....u..3.L.. ........].........b.
..5C.....l......;.;[email protected]
.......a..f.a..fM6[.......i........ 4... 4.]n.].x|[email protected]}..'.4......
_$....8$j~.'...Vs...%.|rD'...>....E.\...O......L...l%....Z4......o.
...)..[F....#[email protected].....\e..o./q........w2...F%..
..;i....$.Q...|...c{.u...h. `!.........x....|].Av.....:9`..]y1y...4.".
P....?.ene..N..S.\....*RRN..rG....xx...O.d....|..v...l..*..m...KA.i...
.7.........O..b.?.%.q.....h.......F.H.k.........q..E...?..-.......H.3L
7.).....G0...?(....!....tw..-...de..../..../......7...;.(.2.....bY....
. :...x.L.......&5...s..&658..=..o.W.suV....lE........EI:.0...5;......
......Q...5....V5..............'..R.8....".......|...........0W.k..bd!
e)..........'.......I.7}.....iv...,.E...&|.j.H.e.i..h%..U....u.%:...|.
[email protected]..`%.............H?..L...........[AW...x.......^.h
.qR.o._J.....,.......0....,.....z>....cq...Q..3.U?"..../X0.....W!.Y
|..G..fb.g.&>.=e`[email protected].)...O..n.......B.....d.V*..Qe...I,R.
E.W.j.`..<.....M..z..:........F.......).nwn..3T.D.u.&.(.i....J.R.U.
.....I.~.eb.^..~.l`..V.v...;..z...I!.....]...h}|......]....]1h2(.5k...
[email protected]...,z.(.|.3. b......o.b.9c#..d.n.
`. .w..}7..O..Br......,c":Y.b.HCK..HCK..0.(..........|....o...m...<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/ua4zZ337Cq0_RFw8igoS2bdlDOvEwayBRDquwRRN0LQ=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 2555
Connection: keep-alive
Last-Modified: Thu, 02 Apr 2015 03:40:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11914:4:2540.../.....I..6........=.......zW....d.r.P.....~.C...W....
2.....u-....'............;!.eAM...(....1.=x.")..........S..(.u.;..I...
...........st.]x.S..1r.1.].....!.~GN..q.s..6.j.L.1..'.,8...uN......Dg.
...~.FO.Vq........>...........z...%.xq..-Q;...uK..#.:..`:.1.......p
=.-....k.......TA. g9..)]........5.....&.....#.G.%.O.E.,.r...>o..&l
t;..`O..7...5....''...|..X{K.?O.....D...T..H....=7..j.N....x@|H.)}.Wqx
...O...~..Q.f....j.....2t..b.....XE.j3...7.&}[email protected].;
..2..w:..9..F.$........hh...b.M....|k........5PU.E...t...$....$...07..
[email protected].^,.-\.Y8.[_.oyI..."........xW.x..... ..\CE......Kd.......ej.?
=.J....k....k....P....P.=.MB......Ip....BD..7...^.......^dD.9....W%#..
..........I._..EP..Q......f.R....T8.}..1..#T./...A.~..a...*....q..Og.=
(.k..t.8i.R..:.{......'.4...Ee..........>........R.nS....GK."...I..
.A.Y...m...=S..%..P........1b..a.#xv....R.!...P.....-j.=>^....X..g.
T.P.....d..V..Hi.}uk.c...d..I....7>.........-u*.L..e..g.....P.x!...
..................s....._..9...^...%...X........|...|.=...[....['.)..4
.cI.........R..P......F"...3/dn....Z....q"........|.....y..)..X(K..i43
..p.tuD...*.W..2_.....Yw./......../W....C.......:.@.........`.\\....hF
D\%.Pd.6J..*o,....X.R.......... ....S.j.....1.lS.\...l7C .d......G..d.
~.r.-..E..J.T.7Ho..7Ho.1......).}.9..yNyUU...UU...X./...y.-8.{.. .Es..
...(x.......a.P..x.$y.9.i.j..r......B...;.'...'.....J.....h...NY.k=.X.
...s......B./[email protected]......*....a..,..c...[.X..._,..*...a...M....
..Z...l.....c.mG.q.es...8s..1....*LJ..y..J.nA...ro...aux)...M&|G&J<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/GUm2SD84TFLXUY9w5Ml6upZqTjz35cgyPrGvWrBgYeI=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 2993
Connection: keep-alive
Last-Modified: Wed, 01 Apr 2015 03:40:05 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11913:4:2978......Y....;.(.....P....[T.$S.\..2{e."k...'.S..&.......U
...1.f.(.'.r.G...e.NG.r..;\.KFa?...c.[.8...n..xH;#H............ ..c...
.a....P#.......Ca.B......p..u.&..V...\BG&...M.....I..z.a...xU...<..
.....si..R.f......L."!."..Y............uJ!....z.w...."k..!......-.....
.....4!...9...'.4....^....4......>ZHK......LV$.#.~..Q.......]......
...0.:)u...b.....2..,[email protected]}....jv...f......Z...q..w.....&l
t;:......'.]..rm.\......j=.^..2.o~..*......F.HS....R..t.a....m....m.".
5...n-...C.JW.....0.Q........;.`..7......./.c..~x`....V...........;.7.
....S?.a4....i%J.$.....A......5..o...R..7?.G..:.z....U...Oz..(.k....F.
.v...[IBK...c.c-.*,/a...%.T..~....8./@v0P..Q....e3....l>m(.JG..t.p.
Z....S...^.?_.3 ..K......@j<.6.... ...q....1(.....m........S..W.D..
v.F...K..7*........%R'&b7..M..3.:4b.q.........$........r.......4M.R...
...I..`..t.......xxS.Z.....X............_...m.C3.vvK....7.I.n....Q...d
V.s.....8.t./.X..Tj.?=..j...}.......8.....(.Tk.c..ZT..}<...}<...
.9....M......M.o._s.Cn&.'.J.:.....Q:.....)...=....)..N.....L.<t..@.
......._.T......xs.O.tJa...b..u.&.........g....h.......Y..o......s....
.... ...5....8..n_D#.kH.........e.D............&1......5kS2........7..
$.N.{....5e...(2*..p..,`...|>...8....8....1..G^B...c8....G...c.a..&
lt;~....Y.K\..~.R...........m......yQ...l..L......;.JH(..JH(.K.]...9c@
...H.AE....9o..... ;.]R.....p4....&....K..w..(..a;....&..I.X./.._...dx
..c.Jz.......XP.......^u........]..$.xl...xl........X....D...,!..9'...
.}...^..>_b..,.kJ..x-/.....1.....OU.......nq...nq..s..p.iQ.K..,<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/1K9aDMnPxpkE2R2aBK4b2E3IagxTFurTWM6YCJFB54g=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 2339
Connection: keep-alive
Last-Modified: Fri, 01 May 2015 03:21:23 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11912:4:2324.3..6.3..6P.............%......b.M..w......IwM.nr..z4.m.
.P#....x...o....!...z........zN......a....n.F^1S..L....=B.I.b..'>.3
\.g.-..7t.^..-.'....M....M.(^...7<...b...r.?Z......_:F.$..P..nH[^A.
..Y].E....E...R...Cl..eG.;.8..........pS..Qz.....^..2.,.....A/.9.}.c..
[email protected];.........&b7../..!..&..qa..d....h.....7...
...8..W..}....7.....d..7...;=Q.........$T...J..;.B...;fx..f.R.....<
....O./.....]}.......... .g]..y..;......x.P.....\......>.....\..>
;.....q..)[[email protected]...>[email protected].\..t.q...E.M
..Q'.4........!3d............U. .[l.D'...V.v....5.1)q.|K...Dw.....K...
[email protected]..\...
....."q7.s....>K.!.:....D:......P..O..S j.yV.....O=.'.]..q4v1q>`
.. ....JW.....;...8.U......g..f.y_..9.......w....w.0.fM.=g..8.^....p.A
.\.(.5k..7....Y...h.On_D#.....O....9k..S.\..)E... ...Kz....=.......g..
T...e.y/......H....)....).c..I.I.....-..4..;uD.....2.\=..._t7...47...N
..f.....Nd#.....x7...s...,/..x..UqQ;........{f....... .d...o..e|...-..
....L.....]X1N.XU....c.........4.Z .}.'.A;.@.[....X./...{....Gp....~._
..!y(......a........(<Z.1h.....2..p[.9.J.OU.........e...B..Z....Q..
.8....cR........i...k!.l8Pc4...||..d. .hn{3..W.N.A......K...{.......(%
|...b.m...r;....5<...........PY.O.....)T%m..U.}.........U...zZ...k.
5......l.C.9.NO.7~..hw....Rm....4...........'C.Q%.. 4M.... k..=B......
.Q...V..y;.hA.{..X../..M....m=la.e.e...T.LQ............Fo...W.xh.. e..
...Q...=.8O...SI.@...%.."Z.ow Q..c.....F...:X...F/.....d...U...W..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/BN_fefG7YqPXI2wavBHdY_Gcg-YkjI4hH8Z1sED-s8s=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 3721
Connection: keep-alive
Last-Modified: Thu, 30 Apr 2015 02:30:29 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11911:4:3706.......;2).........3jXM.].0.h.W.....y.23....R......Q.5..
....M..)D.....aY.4a_y......H....OsZ..N.z.....r2......Tl...(6YC.....2_.
.....2............^....g....gO..I.u.k.c....B..g...r.M...xU...E/.D$-.t|
..D....Y....nO.dY.[..... v.... ...Gs...,..w39..=...t...\2...ICB.......
...K.C.-.D.6x.G...?wlZ.9.g.....ACc..b.P.......6Y.mC....E.r Q....R.s. .
).j 4....WLQ............>...P...~Bq.Q....h..3.}..A..........I<.6
...9.(6al}.....X.q....D(D..........6.#.,..&......uv.H..;...."eG.;.A...
.F....@.._P.....P..q.M^..2.._.}........U-m..........F.u!....xx.bP"..2W
....d...R...,89..u......=.....|.}...........@:.g.4...?1....[.......a.G
........M........L..I.l.....'.">...`....F.#.U..2.....\...e....>.
.......3...1....1.....DI....UZ.:P....r..&O..P\..v...[IBK.u.z..<..W.
........0.....1....t..$../.][email protected].
o/...'......o...\.>....So....k.....%'L.)..H...)fd....u...j._.U.yA..
Ah..A.Y..)-d,.9.....1y.....*........ L....43...'ib.....0.7..j&..q.....
...r....rF.F......K.&...4.Z .....M..!..||..0....0..Qp.C......vvK......
.........g.t....b. r..N.K..^..J..g.!.j.MlH....F.9A*..3-QM..P...OMH8..
..!.HR......n..l;.M..L%....G.............)q.S....#.U......(....<t..
2......q....w..L..-........I....E........r.W..r.W...g..BN< ...mm...
.j...h.........P..,.... .,/...#..'_.c..^..L.H.`H.//2.........;..E...S.
\...Q./r.e.n...L...A$>.v..O.<[email protected].*Y....2.e..d%.&1........`.
O$....3>.....IF.2..j..........S.O.!..pJ......7.....!..5a.P|./m...$.
{.....)..`(}3,`...:...E2.J..R....R....s:P.M.....).........zh...F..<<< skipped >>>
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/YG__nsDShaQvw9cK8iRvgEwVjCEJcjecHox6seWUdLQ=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 94
Connection: keep-alive
Last-Modified: Wed, 29 Apr 2015 03:30:36 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11910:4:81.............M....M....._."zo...... ...8 ..#/..JG....C..h.
[email protected]....{@Sr..0uZ.HTTP/1.1 200 OK..Server: nginx/1.6.2..Date: Fr
i, 01 May 2015 04:21:31 GMT..Content-Type: application/octet-stream..C
ontent-Length: 94..Connection: keep-alive..Last-Modified: Wed, 29 Apr
2015 03:30:36 GMT..Expires: Thu, 31 Dec 2037 23:55:55 GMT..Cache-Contr
ol: max-age=315360000..Strict-Transport-Security: max-age=3600; includ
eSubDomains..Accept-Ranges: bytes..a:11910:4:81.............M....M....
._."zo...... ...8 ..#/[email protected]....{@Sr..0uZ.....
GET /sba.cdn.yandex.net/chunks/goog-phish-shavar/qzgYzW75oibJa6fwVg4hubmLlvrDL4ZEYWL5JJvg_H4=.chunk HTTP/1.1
Host: cache-kiev12.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Content-Type: application/octet-stream
Content-Length: 21
Connection: keep-alive
Last-Modified: Mon, 27 Apr 2015 16:00:28 GMT
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Strict-Transport-Security: max-age=3600; includeSubDomains
Accept-Ranges: bytesa:11907:4:9.7....7...HTTP/1.1 200 OK..Server: nginx/1.6.2..Date: Fri,
01 May 2015 04:21:31 GMT..Content-Type: application/octet-stream..Cont
ent-Length: 21..Connection: keep-alive..Last-Modified: Mon, 27 Apr 201
5 16:00:28 GMT..Expires: Thu, 31 Dec 2037 23:55:55 GMT..Cache-Control:
max-age=315360000..Strict-Transport-Security: max-age=3600; includeSu
bDomains..Accept-Ranges: bytes..a:11907:4:9.7....7.....
GET /PlayFreeBrowser/VERSION HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/octet-stream
Content-Length: 32
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-20"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytesMAJOR=3.MINOR=0.BUILD=0.PATCH=4.....
GET /PlayFreeBrowser/GUID HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/octet-stream
Content-Length: 647
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-287"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytes// Copyright (c) 2012 The Chromium Authors. All rights reserved..// Us
e of this source code is governed by a BSD-style license that can be./
/ found in the LICENSE file...#include "chrome/installer/mini_installe
r/appid.h"..namespace google_update {.const wchar_t kAppGuid[] = L"{2F
0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}";.const wchar_t kChromeAppHostAppG
uid[] =. L"{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}";.const wchar_t k
ChromeFrameAppGuid[] = L"{8BA986DA-5100-405E-AA35-86F34A02ACBF}";.cons
t wchar_t kMultiInstallAppGuid[] =. L"{E91D0BB9-0D56-46e5-BEC7-F01D
89F9CF3F}";.const wchar_t kSxSAppGuid[] = L"{4ea16ac7-fd5a-47c3-875b-d
bf4a2008c20}";.}.....
GET /PlayFreeBrowser/setup.exe HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/octet-stream
Content-Length: 1663784
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-196328"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytesMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......f/.B"N.."N..
"N....L.!N..9.J..N..9.~.!O..M8..!N...9h. N...9j.#N.."N..pO...9m.?N..9.
..wO..9.N.#N.."NC.#N..9.I.#N..Rich"N..........PE..L.....UR............
.....h........................@.................................@.....
@..................................N.......0...............J..(....0..
............................. .......*[email protected]..@.....
...............text....g.......h.................. ..`.rdata..........
.....l..............@[email protected][email protected]..
....... [email protected].......|..............
@[email protected][email protected]..........................
......................................................................
......................................................................
......................................................................
.............................................A...u....N........S.V....
t.V........P.....j.j.j.j.j..3.........U...E..V......N.t.V.w........^].
................j.j.j.j.j.......U...E..U.....E.QRP........].....U..QV.
[email protected]..^..].......U..QVW..j..M...t...G...t....
s.H.G..w........M.#...t.._..^..]........R...........U..QW.9..t;j..M...
t...G...t....s.H.G.V.w......M.....t..#.t.....j.....^_..]......U..V..V.
...R...y......E..t.V.>........^].........A..H..Q..D....R.P....R...y
..Y.....x..r..........A$.8.t..I4....3...................x..r......<<< skipped >>>
GET /icons/product_logo_128.png HTTP/1.1
Host: customisations.playfree.org
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:26 GMT
Content-Type: image/png
Content-Length: 24082
Last-Modified: Wed, 02 Oct 2013 08:03:29 GMT
Connection: keep-alive
ETag: "524bd351-5e12"
Accept-Ranges: bytes.PNG........IHDR..............>a.....pHYs...#...#.x.?v...OiCCPPhoto
shop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE......
.....Q,......!.........{.k........>...........H3Q5...B..........@..
$p....d!s.#...~<< ".....x.....M..0.....B.\[email protected]..@F.
...&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWf
H.............0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(
.I. [email protected]..._-...."[email protected]~..,/..
.;..m..%..h^[email protected].~<<E.........J.B[a.W}.g._.W.l.~<
;......$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,
..>.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..
?....D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/[email protected]..=
p..a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2
....G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,.
.c.."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b2
1.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!
.[[email protected].(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i.
.t.....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....
J.&..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.
._... .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....)
.)..4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....
Dw.n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC][email protected].
.....<..F.F..i.\.$.m.m..&.&!&KM.M..RM..).;L;L........5.=1.2....<<< skipped >>>
GET /chunks/goog-malware-shavar/9eJHkKBM28o-0xZBdcbLTRTKn5i6bdxKBD16b5XNtEg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/9eJHkKBM28o-0xZBdcbLTRTKn5i6bdxKBD16b5XNtEg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /PlayFreeBrowser/MPCBrowserUpdater.exe HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/octet-stream
Content-Length: 619568
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-97430"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytesMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$...........@...@...
@...[S..O...[S2.....[S3.]...[S7.F...I...I...@...$...[[email protected]...[S
[email protected]............................
.G............@.......................................@...............
......................d........e...........Z..0.......0...............
........................................x............................t
ext............................... ..`.rdata...-......................
....@[email protected][email protected]....
..............@[email protected][email protected]............
......................................................................
......................................................................
......................................................................
......................................................................
............................................3..|$.....j....j.j.H......
[email protected]$...t,...t ...t..."[email protected]$...
[email protected].^[email protected]'[email protected].;.s.N....|O.u.;.r.3
..........#._^[email protected]...$....Vj.....d.@.
WV.D$.P..\[email protected][email protected].@.........$......^3...W.........U..........
[email protected][email protected]..\[email protected][email protected].@...............;u.r.h
W...........P..V..Y;E.s.......P.u.S..V..P.~....M......3.^.0W.....U..Q.
e...~..St8.E.P.v.3..........t$9].t..}.....}..u...{....Y..u.P..|..Y<<< skipped >>>
GET /chunks/goog-malware-shavar/nhJUhSVWvHs0hfzlykFUz6TAZgIYTI2u0kvRVsqf6qQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/nhJUhSVWvHs0hfzlykFUz6TAZgIYTI2u0kvRVsqf6qQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/GsrVhUq6AbrMVrXw4Ec6ftazfcF7150-LStN0PdRwKA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/GsrVhUq6AbrMVrXw4Ec6ftazfcF7150-LStN0PdRwKA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/CBZSVliJ3jUTEovyUiGBSNmHnvKYhm043-gh-uvUrbg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/CBZSVliJ3jUTEovyUiGBSNmHnvKYhm043-gh-uvUrbg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/FDTTAe43Pc4fgrkoGNLqTPAl11sblwDJtByrMIJs2GY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/FDTTAe43Pc4fgrkoGNLqTPAl11sblwDJtByrMIJs2GY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/Xg-BBhKSb2OnBWRaP9C4JWVmxAKB71AgLuAzzo9JV-4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Xg-BBhKSb2OnBWRaP9C4JWVmxAKB71AgLuAzzo9JV-4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /i/banners/mmo/Stormfall_300x250_en.jpg HTTP/1.1
Host: mpcstatic.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:24 GMT
Content-Type: image/jpeg
Content-Length: 43580
Last-Modified: Thu, 15 Jan 2015 11:44:17 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:24 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes......Exif..II*.................Ducky.......H.....ohXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:995966C1CA9BE4119
F58F2036B4EFF8F" xmpMM:DocumentID="xmp.did:3525ABA89C7B11E48D3BAA443C8
88E42" xmpMM:InstanceID="xmp.iid:3525ABA79C7B11E48D3BAA443C888E42" xmp
:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:2D7E604D789CE4119649EFC31A619287" stRef:doc
umentID="xmp.did:995966C1CA9BE4119F58F2036B4EFF8F"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;...&Adobe.d...............%f..C(..l(...:............................
......................................................................
............................................,.........................
.................................................................. !.1
".A2.0#.@B3$C4.%&.......................!1.AQ"..aq..2.BR#3. ...b....r.
C...Ss$4......dt......................!01. @.P`Aa.q."Q.2p...b.........
............!1AQaq....... ...0@...............'g.R.q..|....JMa.>...
..5.....Q^7...VU...F.RvT$.J..S....9u.#R7%Wnmld"..:..J.9;....r..n2.<<< skipped >>>
GET /gn/128x128/468_128x128.png HTTP/1.1
Host: mpcstatic.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:25 GMT
Content-Type: image/png
Content-Length: 32048
Last-Modified: Wed, 20 Mar 2013 12:51:26 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:25 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes.PNG........IHDR.............L\......pHYs...........~... .IDATx.l.k.d.
u&....>.^......f...)Z...G.myb..=.q0c........#.=.. ...f0F. @.d...<
;..3.(.e.,K.,Y...$.2-..)Rd?Hv...}...s.^...]..6R....T.}.^.o}..%..0RE.@.
.>...0..........;ED.HF.I.Q.R..*...@D................ A...D....t-..Z
e.W.X..*...~p...@[email protected]..`..3..'."$..$........"H....f.S.$G.B..b.G.
[email protected]....|.w............$SJm...T.i..RJ979..sJ..,...YR3Kf
*.K..\.^." p`.zo..(....G.R..K.u.......>..'......;..2.<\..l @.@..
...ng....R....P...."..u.;'C...6....T2..&.*.R...0.....|>.u.....w.~..
.i..=r..t...".P3..."V..z..@Y. "..._.u...w.."....%D.A..........4..P@y3.
[email protected].][email protected].\...8\..$%y.,CD..PIQ.................AJaH8.B../..
.......o........}@[email protected](L..W.......?.........lL...m[..R...../...U. ...
...i......X.#"!H.[Z%.C.....*.g.a..... (...e...=..Da...K.K.....I. .#8.A
(..........a. ,\$d.e.<[email protected]. ...c...ptfg|........sg.l
o.F....d.w..y.....~...=........&C.}/"0..9...h>Ly.D.. I...J5_.T...S
..sE$...z..U(...H.BB.........d.\...)BDL[....( X..."....x..C(.q;.......
..'...."...p.3TH....a..!...Izu..*............. .2.....;...g......]g..m
.%.]..........f..8.\..d3.k...jc.PM.....CB..ylp..B..5..L..I.&.....f...H
....A .......B.K.D.....a.. b*...... e......!A....|.....PIe...F.5...PP.
Q8.A($j.RH..P.....P......3(.rR..K,.............~[-.q..s..........\.ugN
.7.Is.,.....H.F....P.D."!b....D(....L...%@.<.U... .yLY....B.4.C$.e.
..J-.B.....#...........q..u..l..p.:i......\.*a".3KTH..T.($".D..E..@...
._"..,.../%....m3..r.....c./\.:.....v4J;;;......g....m,.R$..Z..3..<<< skipped >>>
GET /chunks/goog-phish-shavar/InCnLK-Y8LZ6JG7r-6OZj7o4DrW6iCbFTv3xbble6yQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/InCnLK-Y8LZ6JG7r-6OZj7o4DrW6iCbFTv3xbble6yQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/Y0cCKitNdebmBGg2qVxMow9PkJ5C5cS4IunvOy1sG4I=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Y0cCKitNdebmBGg2qVxMow9PkJ5C5cS4IunvOy1sG4I=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/m8zTXWVYnt2StqmNe4n0gx7bH32b0Uex1h36Ocbxmp0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/m8zTXWVYnt2StqmNe4n0gx7bH32b0Uex1h36Ocbxmp0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/Lbqo50DoB6E0rsYdfnv8-3rJNk-O52A9UO9OtxxGEw8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Lbqo50DoB6E0rsYdfnv8-3rJNk-O52A9UO9OtxxGEw8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/k0cSSdexw9nzUo-SpJK5J2Fc6MX3OaEDyf9RhcxZqUM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/k0cSSdexw9nzUo-SpJK5J2Fc6MX3OaEDyf9RhcxZqUM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/7bOJgy8Hm2aYptpm9nr6UfbSLV0FRWxA8aiAgMmpc3w=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/7bOJgy8Hm2aYptpm9nr6UfbSLV0FRWxA8aiAgMmpc3w=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /gn/111x83/1811_111x83.jpg HTTP/1.1
Host: mpcstatic.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: image/jpeg
Content-Length: 12115
Last-Modified: Thu, 23 Jan 2014 02:46:42 GMT
Connection: keep-alive
Expires: Fri, 08 May 2015 04:18:23 GMT
Cache-Control: max-age=604800
Access-Control-Allow-Origin: *
Accept-Ranges: bytes......Exif..II*.................Ducky.......P......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
0 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpRights="hXXp://ns.adobe.com/xap/1.0/rights/" xmlns
:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.
com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0
/" xmpRights:Marked="False" xmpMM:OriginalDocumentID="uuid:C09D1BEE168
3DE1196BDF2ACE5307927" xmpMM:DocumentID="xmp.did:E505EECB836611E38F00A
3B9694BA0D0" xmpMM:InstanceID="xmp.iid:E505EECA836611E38F00A3B9694BA0D
0" xmp:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:Derived
From stRef:instanceID="xmp.iid:B315E42E657CE311BFB4D4AFCE9B0DED" stRef
:documentID="uuid:F92CC608C55EE111A7E0AEF59647EB63"/> </rdf:Desc
ription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&
gt;...&Adobe.d................ ...=..!.../Q...........................
......................................................................
...........................................S.o........................
.....................................................................!
.".12.0A$.#3&........................!..1A".Qa.q2#....BR3....C.$..0...
b.5r.c.T....................1..!A..Q aq....."[email protected]..#..............
......!1AQaq.........0. ................$.3].Q..Ky.$.g^E.HJ.en....<<< skipped >>>
GET /chunks/goog-malware-shavar/T_aMBLuw7gCWF9l5r-w4H8u5L6uL0GLJfqLot_fdaek=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/T_aMBLuw7gCWF9l5r-w4H8u5L6uL0GLJfqLot_fdaek=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/qzgYzW75oibJa6fwVg4hubmLlvrDL4ZEYWL5JJvg_H4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qzgYzW75oibJa6fwVg4hubmLlvrDL4ZEYWL5JJvg_H4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /PlayFreeBrowser/MPCBrowserUpdater.exe HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/octet-stream
Content-Length: 619568
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-97430"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytesMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$...........@...@...
@...[S..O...[S2.....[S3.]...[S7.F...I...I...@...$...[[email protected]...[S
[email protected]............................
.G............@.......................................@...............
......................d........e...........Z..0.......0...............
........................................x............................t
ext............................... ..`.rdata...-......................
....@[email protected][email protected]....
..............@[email protected][email protected]............
......................................................................
......................................................................
......................................................................
......................................................................
............................................3..|$.....j....j.j.H......
[email protected]$...t,...t ...t..."[email protected]$...
[email protected].^[email protected]'[email protected].;.s.N....|O.u.;.r.3
..........#._^[email protected]...$....Vj.....d.@.
WV.D$.P..\[email protected][email protected].@.........$......^3...W.........U..........
[email protected][email protected]..\[email protected][email protected].@...............;u.r.h
W...........P..V..Y;E.s.......P.u.S..V..P.~....M......3.^.0W.....U..Q.
e...~..St8.E.P.v.3..........t$9].t..}.....}..u...{....Y..u.P..|..Y<<< skipped >>>
GET /chunks/goog-malware-shavar/_LeYmVcLjaymWdywoaBs2fZ3zvbAC0b1zHa4o6BHJE8=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/_LeYmVcLjaymWdywoaBs2fZ3zvbAC0b1zHa4o6BHJE8=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/nsXHQXzYI3AuGyYkuMQgRG7dxGi0A5Al7OIum9R-hyE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/nsXHQXzYI3AuGyYkuMQgRG7dxGi0A5Al7OIum9R-hyE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/GUm2SD84TFLXUY9w5Ml6upZqTjz35cgyPrGvWrBgYeI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/GUm2SD84TFLXUY9w5Ml6upZqTjz35cgyPrGvWrBgYeI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/i5G2FM8_tLEjfy7aO0N4kmHdYf7-_pBv3JkZPz8emiA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/i5G2FM8_tLEjfy7aO0N4kmHdYf7-_pBv3JkZPz8emiA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/XXIH_VyGQMK6X1r6-qVTBZRUmfW6hzxd-YkgYKOoYjY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/XXIH_VyGQMK6X1r6-qVTBZRUmfW6hzxd-YkgYKOoYjY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/BC0-t8qDOZWMvEUrn6JXSuUN6qhlTVaqNx79F0rdNVc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/BC0-t8qDOZWMvEUrn6JXSuUN6qhlTVaqNx79F0rdNVc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/D_1Zrj0aSqF6XUXiWJ9r6ZYUEaVZYpvCWaBBaTVDy0o=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/D_1Zrj0aSqF6XUXiWJ9r6ZYUEaVZYpvCWaBBaTVDy0o=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/jEtUT_cL0M27Wn976ODIjlalYuMX3QGH-mjk2rUKFQA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/jEtUT_cL0M27Wn976ODIjlalYuMX3QGH-mjk2rUKFQA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
POST /downloads?client=PFBrowser&appver=2.3&pver=2.3&apikey=0151016567ffe9484fd45115e97569642d6f33617a2df7c019a2a8b33c HTTP/1.1
Host: sba.yandex.net
Connection: keep-alive
Content-Length: 115
Content-Type: text/plain
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
goog-malware-shavar
goog-phish-shavar
goog-badbinurl-shavar
goog-csdwhite-sha256
goog-downloadwhite-digest256
HTTP/1.1 307 Temporarily redirect
Location: hXXps://sba.yandex.net/downloads?client=PFBrowser&appver=2.3&pver=2.3&apikey=0151016567ffe9484fd45115e97569642d6f33617a2df7c019a2a8b33c
Content-Length: 0HTTP/1.1 307 Temporarily redirect..Location: hXXps://sba.yandex.net/do
wnloads?client=PFBrowser&appver=2.3&pver=2.3&apikey=0151016567ffe9484f
d45115e97569642d6f33617a2df7c019a2a8b33c..Content-Length: 0....
..
GET /chunks/goog-phish-shavar/Tj7ZLCSSjPdV1SzabZFpEPSGnNkXuSnbXXrEG9YWUsc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Tj7ZLCSSjPdV1SzabZFpEPSGnNkXuSnbXXrEG9YWUsc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/YG__nsDShaQvw9cK8iRvgEwVjCEJcjecHox6seWUdLQ=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/YG__nsDShaQvw9cK8iRvgEwVjCEJcjecHox6seWUdLQ=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/M_uIHnItKjxLGZ6Y6sA3mLX9k8jkxrLA4WFXXMB8GPM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/M_uIHnItKjxLGZ6Y6sA3mLX9k8jkxrLA4WFXXMB8GPM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/-4o5ao5EnwLZD9iXKCnEsuiZD1-825UgvePOW0l7Jig=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/-4o5ao5EnwLZD9iXKCnEsuiZD1-825UgvePOW0l7Jig=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/OypAprm_9JNXzDZt_V9HoRneNyy7siQEwJ3hHQjmCHY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/OypAprm_9JNXzDZt_V9HoRneNyy7siQEwJ3hHQjmCHY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/h_xpPnaTd4FhVPIkCA2nensqXe_s9gRnukwHWL_1IIM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/h_xpPnaTd4FhVPIkCA2nensqXe_s9gRnukwHWL_1IIM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/ihvaXT0zxWqt0I1IIj7mFRJdHKF0OMXfAKRwiTwrFnk=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ihvaXT0zxWqt0I1IIj7mFRJdHKF0OMXfAKRwiTwrFnk=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/l0NbfG_xC03kXPH0E5TtymYBrP3rti1X7kASdMQdDBc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/l0NbfG_xC03kXPH0E5TtymYBrP3rti1X7kASdMQdDBc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/ZuAPRjyGYJlkTcv1FEc5TDP_4G-_uF22_OMHVkTckZw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ZuAPRjyGYJlkTcv1FEc5TDP_4G-_uF22_OMHVkTckZw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/MuNLeGrVYTt6Y1cOK2042BI3JSNbelnx-pT6Oqdi4yg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/MuNLeGrVYTt6Y1cOK2042BI3JSNbelnx-pT6Oqdi4yg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/SBcYP83hLjrvJOk2McHsxGs6FsHWjiidYEUsQI1V2Fw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/SBcYP83hLjrvJOk2McHsxGs6FsHWjiidYEUsQI1V2Fw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/O9g5OJm4JRG7U6M0FrlMP6KS2sLifUb-a-mH5mfdXIc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/O9g5OJm4JRG7U6M0FrlMP6KS2sLifUb-a-mH5mfdXIc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/L8YfZVfXg6CBxtxY09kJVtVDgBO0dITHTfapA4cuPXw=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/L8YfZVfXg6CBxtxY09kJVtVDgBO0dITHTfapA4cuPXw=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /PlayFreeBrowser/chrome.packed.7z HTTP/1.1
User-Agent: Game installer
Host: files.playfree.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Fri, 01 May 2015 03:55:05 GMT
Content-Type: application/x-7z-compressed
Content-Length: 34442382
Last-Modified: Wed, 09 Oct 2013 07:40:57 GMT
Connection: keep-alive
ETag: "52550889-20d8c8e"
Expires: Fri, 01 May 2015 04:55:05 GMT
Cache-Control: max-age=3600
Cache-Control: stale-if-error=14400
Cache-Control: must-revalidate
Accept-Ranges: bytes7z..'...3;..................z.........8%D.z.x../.Bg;....N.zN.......9 .
......M....4..hM.......X...S.-....O ..`..85.........F....$........m.cW
.F<$7i*..... $q..0D.-8.wm.=..`}.Fv..b......I....-...<...%RzE.5G3
PS...@!....z...c&s.....X..4.I...>.6..R_..~...Ov.t.Uw..I......r.U.kJ
h..z.S...1g.Y......2..aa..7..O..'M..wH.B'.P..}EM......y|...bc.a....^..
..."...Oaq......#o...2.U...nSK%.'m.f!!.....'..`...@...$..9.wL...!...K.
..g....sV.7../L...V...G..........k.<)..D.......H..-.9........(Q...5
?j...g...'..0g...E.3 .....k..z..<...m.......f.. .,~.k.......Q..7).`
......&..x.#*.a1D4...,...w.....=.....g#3z.{j.#-.........$....<0...W
.wE... ...t.....C........"BNB5h:.J..Iz.....I...#....6..s......R...7.N.
.I.l......7.2.=W..VO.. .....Zw...M...........no.q9..1.q% q.%...G.).g.Y
V.....Y^!g....|x..R...q.\H.;....~......x@,..*.&.......<h.X.4..~.&
gt;.z...T....:Fz.7.Y.^k.....e...........0.$.J$..rhX....E.<....5l.H.
%..O.D...w...4K8.....o^..P.~N....0.Z.'i.......K$..~.(x.C....>....y.
<...I!2.AB.....p.l....m...|.!1a..T..F..C.....~....:..&.....Q\_..J.a
p.. 2i..n.........'...g..'[email protected][..#.U....$..o.F.1B.&
gt;.k8.4r...a.aa .,.)i%.g.V. %...=.f6...sK.,B'...._.......z.x.7..).n~.
z....:j...J$'.j...L..^.c\.{.K...q.|n.$...F. .H.Q.~o..HT..I...[........
o..o..'Y-.S..6.IO.c.5Q.D.~...[2.L&[UM...U...1..I*H...f...>..C.G..V.
..b.[..C..KOB....X:u...q.....<.......=..eEt..D....D..T..../^.D.g.&U
9.........)%..k.p..V...,[email protected]_.A......... ....dT
.kK.&O..G..y....&N5...P........(..Tu..a......M0..dx.9.9....mV.*x..<<< skipped >>>
GET /chunks/goog-phish-shavar/ttESbMYCl0F1zsR55cKlwxZJYMsyLjORkbBoc7Zm5gY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:31 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev12.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/ttESbMYCl0F1zsR55cKlwxZJYMsyLjORkbBoc7Zm5gY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/wZBd-e3nlAYWe0lPx6hvMHNc-sDwWwuhlIin-owxthM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/wZBd-e3nlAYWe0lPx6hvMHNc-sDwWwuhlIin-owxthM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/Y-vgliRy7vwOHI7QAOD7H4oqSf-TJiaCBLsl-TOu6W4=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/Y-vgliRy7vwOHI7QAOD7H4oqSf-TJiaCBLsl-TOu6W4=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
HEAD /edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Host: redirector.gvt1.com
HTTP/1.1 302 Found
Date: Fri, 01 May 2015 04:22:32 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Location: hXXp://r2---sn-ugpva5o-3c2e.gvt1.com/edgedl/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?cms_redirect=yes&expire=1430468552&ip=37.57.16.189&ipbits=0&mm=28&mn=sn-ugpva5o-3c2e&ms=nvh&mt=1430454086&mv=u&pcm2cms=yes&pl=22&shardbypass=yes&sparams=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=26347A8AAAADD774630CF4C618EF0C0A5FC11F65.0E69BCDACB63B8EE5BFA7AE881E0B9EDF4DCB9C8&key=cms1
Content-Type: text/html; charset=UTF-8
Server: ClientMapServer
Content-Length: 665
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Alternate-Protocol: 80:quic,p=1HTTP/1.1 302 Found..Date: Fri, 01 May 2015 04:22:32 GMT..Pragma: no-ca
che..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache,
must-revalidate..Location: hXXp://r2---sn-ugpva5o-3c2e.gvt1.com/edgedl
/chrome/win/8E219F321F3A3148/42.0.2311.135_chrome_installer.exe?cms_re
direct=yes&expire=1430468552&ip=37.57.16.189&ipbits=0&mm=28&mn=sn-ugpv
a5o-3c2e&ms=nvh&mt=1430454086&mv=u&pcm2cms=yes&pl=22&shardbypass=yes&s
params=expire,ip,ipbits,mm,mn,ms,mv,pcm2cms,pl,shardbypass&signature=2
6347A8AAAADD774630CF4C618EF0C0A5FC11F65.0E69BCDACB63B8EE5BFA7AE881E0B9
EDF4DCB9C8&key=cms1..Content-Type: text/html; charset=UTF-8..Server: C
lientMapServer..Content-Length: 665..X-XSS-Protection: 1; mode=block..
X-Frame-Options: SAMEORIGIN..Alternate-Protocol: 80:quic,p=1..
GET /chunks/goog-phish-shavar/qDC0G_w_wSrAQ-0l04BWQgPpcKgZMDT6ciA2msBNIzY=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/qDC0G_w_wSrAQ-0l04BWQgPpcKgZMDT6ciA2msBNIzY=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/Bo9JfyHVL7b5NSgfR8eXJuvq1Sz1--op2i8kfamuRcI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/Bo9JfyHVL7b5NSgfR8eXJuvq1Sz1--op2i8kfamuRcI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/0D3N_cx0Jm-0zlRfzxtI1c1JCExEEO-3DUtScKCpOHs=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:30 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev08.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/0D3N_cx0Jm-0zlRfzxtI1c1JCExEEO-3DUtScKCpOHs=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /en/?utm_source=gs_en&utm_medium=hp HTTP/1.1
Host: home.playfree.org
Connection: keep-alive
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Server: nginx/1.2.7
Date: Fri, 01 May 2015 04:18:23 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.12
X-Country-Detected: UA
Set-Cookie: utm_source_channel_id=gs_en; expires=Thu, 30-Jul-2015 04:18:23 GMT
X-Source-Type: gsen2cc6..<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://www
.w3.org/TR/html4/strict.dtd" >.<html>.<head a="">..<
meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
..<title>PlayFree Search</title>..<link rel="shortcut i
con" href="hXXp://VVV.playfree.org/favicon.ico"/> ..<link rel="s
tylesheet" href="main0.css" type="text/css"/>..<script src="acts
.js" type="text/javascript"></script>..<script type="text/
javascript" src="hXXp://mpcstatic.com/i/mmo_banners.js"></script
>..<!--[if IE 7]>...<style type="text/css">....#srchCrt
{top:-2px;}....</style>..<![endif]-->.<script type="tex
t/javascript">.window.google_analytics_uacct = "UA-1217017-45";.goo
gle_analytics_domain_name = ".playfree.org";.</script>..<scri
pt type="text/javascript">.. var _gaq = _gaq || [];. _gaq.push(['
_setAccount', 'UA-1217017-45']);. _gaq.push(['_setDomainName', '.play
free.org']);. _gaq.push(['_trackPageview']);.. (function() {. var
ga = document.createElement('script'); ga.type = 'text/javascript'; g
a.async = true;. ga.src = ('https:' == document.location.protocol ?
'hXXps://ssl' : 'hXXp://www') '.google-analytics.com/ga.js';. va
r s = document.getElementsByTagName('script')[0]; s.parentNode.insertB
efore(ga, s);. })();..</script> <style>.#s{border:0px; he
ight:22px; background:#fffee7; margin:12px 0 0 10px;}.#btmFrmHldr{widt
h:66em; margin-left:60px;}.#btmSctn{height:90px;}.div#pagination_w<<< skipped >>>
GET /chunks/goog-malware-shavar/yblLd2E6Kl_fu3GsgarktrXxWijZbNqYOqggb8uZQ48=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/yblLd2E6Kl_fu3GsgarktrXxWijZbNqYOqggb8uZQ48=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/6REFNUxyRF2vLNuQD5eV-JDP4re7A_YwPBkbPa1JkfE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/6REFNUxyRF2vLNuQD5eV-JDP4re7A_YwPBkbPa1JkfE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/6uQWqaT1RCGblQ4ZpLsL58bVvNhg6v7DD891bikH8qM=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/6uQWqaT1RCGblQ4ZpLsL58bVvNhg6v7DD891bikH8qM=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/6QP0kMWCUrsl3TMa6i0RJicPwULRgr-75UnuqkTrowg=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/6QP0kMWCUrsl3TMa6i0RJicPwULRgr-75UnuqkTrowg=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/AFGjLCcPvpsG1HUPtkI98qT8qJteSviPkekn-QzuSyE=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/AFGjLCcPvpsG1HUPtkI98qT8qJteSviPkekn-QzuSyE=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
POST /service/update2?w=3:KUuZkuoC7H8t1GILnNZ8kHg9xSafCQra5vhZDuzrPIy84ga3Jm6MJCU8kEVOE22Rl9a0cnj1Kq5i__mvd6itMjmMDN93A0guOwTCflpKx08iVu74hey4YZb6Lh-41BNcBwCze4rZ3nTS926S43CTAQX8sbxiX50uWVfvMVyScZ0 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
If-Match: "BPc86kPTHilZjvD4XKPFns7z0kw"
User-Agent: MPCBrowser Update/1.3.27.0;winhttp;cup
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
Content-Length: 449
Host: omaha.playfree.org
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" version="1.3.27.0" ismachine="0" sessionid="{17D31739-CE97-41F0-B418-534DA8AFFCEB}" installsource="otherinstallcmd" testsource="auto" requestid="{8D473A04-AF21-48B6-8BE8-05E5243F071A}"><os platform="win" version="6.1" sp="Service Pack 1" arch="x64"/><app appid="{2F0B3EEC-E5EE-47C1-829C-ADE0D31F2DFC}" version="" nextversion="" lang="en" brand="" client=""><updatecheck/></app></request>
HTTP/1.1 200 OK
Server: nginx/1.4.1
Date: Fri, 01 May 2015 04:18:16 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.15
Set-Cookie: pid=k7qbld3k8jiee7cuvdijdt61g6; expires=Sat, 02-May-2015 04:18:16 GMT; path=/; domain=.omaha.playfree.org
Cache-Control: private, max-age=10800, pre-check=10800
Last-Modified: Tue, 27 Nov 2012 07:34:24 GMTd2..<?xml version="1.0"?>.<response protocol="3.0" server="pr
od"><daystart elapsed_seconds="83896"/><app appid="{2F0B3E
EC-E5EE-47C1-829C-ADE0D31F2DFC}" status="ok"><updatecheck status
="noupdate"/></app></response>...0..HTTP/1.1 200 OK..Se
rver: nginx/1.4.1..Date: Fri, 01 May 2015 04:18:16 GMT..Content-Type:
text/html..Transfer-Encoding: chunked..Connection: keep-alive..X-Power
ed-By: PHP/5.4.15..Set-Cookie: pid=k7qbld3k8jiee7cuvdijdt61g6; expires
=Sat, 02-May-2015 04:18:16 GMT; path=/; domain=.omaha.playfree.org..Ca
che-Control: private, max-age=10800, pre-check=10800..Last-Modified: T
ue, 27 Nov 2012 07:34:24 GMT..d2..<?xml version="1.0"?>.<resp
onse protocol="3.0" server="prod"><daystart elapsed_seconds="838
96"/><app appid="{2F0B3EEC-E5EE-47C1-829C-ADE0D31F2DFC}" status=
"ok"><updatecheck status="noupdate"/></app></respons
e>...0..
GET /chunks/goog-malware-shavar/DFBYtvq866rJuHxVyLHxF65hHot39cLoMpvzYSy1k7o=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/DFBYtvq866rJuHxVyLHxF65hHot39cLoMpvzYSy1k7o=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /ga.js HTTP/1.1
Host: VVV.google-analytics.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Date: Fri, 01 May 2015 02:20:30 GMT
Expires: Fri, 01 May 2015 04:20:30 GMT
Last-Modified: Mon, 27 Apr 2015 18:49:35 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 16075
Cache-Control: public, max-age=7200
Age: 7074
Alternate-Protocol: 80:quic,p=1...........}.W........_/.>.!aj..f....--....Y.!MHB.0....o..-'.......
{K..y.....d.Wig.....r.H.P.. ............"..a?..;..P2...C.R.&..e....o.e
x"...e.....[..C.K...G:....de...d.F.,..|.=..Fn..9..//5$X...Co..=..'z2..
.`0..%[email protected]...#.^a.......Kh.'.C.....I.]......tp..:.sO...x..
.8...t0<....\b;=. .z.e>.1..#.v.j......<q...#[email protected]...}H1.C..
.R.5...z..XWb.2.t.......B.....[(i.....P...x.....9.nM...."...^.....c..
R......t...Z..q.hl......;.c.....9.@g_.(..n.hO....|......t`.|.)H..Z....
.l..f .j......J...%._.KN......Tf..g.^.b....r.I..z...UK.\^^.m....}..DA/
.......g.A........0.........".c0.....$~I....D#......{...}.=..j...m....
@.....k.?$....J..Q......}.g......~...6.l<]..x...d?.\...w.3].._.X@..
|....}.C..$0.|.53...Q.8.....i.0=Vr.h.........<.a>.....4.:...ttg.
.....f....'.T.`=..........a...oB...Q.q......3N5 ..<....R....4......
....K..I.i#..C..$#i....`Ja..:..z.*...O...?..41.!.w}......T............
.........y..pE^r..n....A..............q..`.i>;........ .).......m..
P61I.jK.nG..Vj......9.....2....Tv. ^. ........OZ....U.9399].).,.p..\..
\YW..j3..H%...........e.c.....[[email protected].=...R...
.]....xz.`.<..7........r1..87.....7.iL}u..Yu;T. X..d.GT L Uy.....q}
......./...=. ..<#u%..4h...mZJ......p.m...,,<..4.,o$..E.a&.-qy9Z
^6i-,@...".6.7.......-f;.`..f.2...?./.S<[email protected].%.|.
.:.J5.Vy...........%5....... ..g.*..v..".......K..e0....H.....n..6a...
q..I..8..:.q1`......Z*'[email protected]... X.1.....
.B.km._.Uzr..2.D..2..n..}8.wu.O....38..}5.c.`.. ....`...MC.....#A[<<< skipped >>>
GET /r/__utm.gif?utmwv=5.6.4&utms=1&utmn=719186822&utmhn=home.playfree.org&utmcs=UTF-8&utmsr=1716x901&utmvp=833x755&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=11.8 r800&utmdt=PlayFree Search&utmhid=2008743007&utmr=-&utmp=/en/?utm_source=gs_en&utm_medium=hp&utmht=1430453906475&utmac=UA-1217017-45&utmcc=__utma=120822935.470092875.1430453906.1430453906.1430453906.1;+__utmz=120822935.1430453906.1.1.utmcsr=gs_en|utmccn=(not%20set)|utmcmd=hp;&utmjid=470535854&utmredir=1&utmu=qBAAAAAAAAAAAAAAAAAAAAAE~ HTTP/1.1
Host: VVV.google-analytics.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept: */*
Referer: hXXp://home.playfree.org/en/?utm_source=gs_en&utm_medium=hp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Date: Fri, 01 May 2015 04:18:26 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Server: Golfe2
Content-Length: 35
Alternate-Protocol: 80:quic,p=1GIF89a.............,...........D..;HTTP/1.1 200 OK..Access-Control-All
ow-Origin: *..Date: Fri, 01 May 2015 04:18:26 GMT..Pragma: no-cache..E
xpires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, no-sto
re, must-revalidate..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-C
ontent-Type-Options: nosniff..Content-Type: image/gif..Server: Golfe2.
.Content-Length: 35..Alternate-Protocol: 80:quic,p=1..GIF89a..........
...,...........D..;....
GET /chunks/goog-malware-shavar/uq-M1FCqWXfGGjcE0dku9n1tg5Z59jjylidsIBdF6NA=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/uq-M1FCqWXfGGjcE0dku9n1tg5Z59jjylidsIBdF6NA=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/olMNSrIv3_9-5Zz2qU3JZv0ECEq0RlY7SE12jovxqOc=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev06.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/olMNSrIv3_9-5Zz2qU3JZv0ECEq0RlY7SE12jovxqOc=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/upbUSLkFFgKYbxZEi1SDt8e2LlKATdvoZ-bwaW7Zj_Y=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:34 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev02.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/upbUSLkFFgKYbxZEi1SDt8e2LlKATdvoZ-bwaW7Zj_Y=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/n1yFjPQFEChBHb2nPFdlSnxInZe06KGVB02Q5AxqI18=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/n1yFjPQFEChBHb2nPFdlSnxInZe06KGVB02Q5AxqI18=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /customization/?bundle=gs_en HTTP/1.1
User-Agent: Game installer
Host: VVV.playfree.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:02 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.38a58..{"target_region":"en","source_site":"en","origin":"gs","desktop_i
con":"","desktop_name":"","desktop_url":"","omnibox_search_name":"Play
Free","omnibox_search_url":"http:\/\/home.playfree.org\/en\/results.ph
p?category=web&s={searchTerms}&utm_source=gs_en&utm_medium=results","o
mnibox_suggest_url":"http:\/\/home.playfree.org\/suggest\/?suggest={se
archTerms}","omnibox_search_keywords":"playfree.org","omnibox_search_f
avicon":"http:\/\/VVV.playfree.org\/favicon.ico","omnibox_search_expor
t":"","home_page_url":"http:\/\/home.playfree.org\/en\/?utm_source=gs_
en&utm_medium=hp","homepage_export":"","newtab_url":"0","newtab_search
_url":"0","welcome_url":"http:\/\/VVV.playfree.org\/en\/welcome.html?u
tm_source=gs_en&utm_medium=welcome","uninstall_url":"uninstall.html","
aboutus_url":"about-us\/","privacy_policy_url":"privacy-policy\/","tou
_url":"terms-of-use\/","support_url":"support\/","howtouninstall_url":
"how-to-uninstall\/","help_url":"help\/","newtab_bookmark_title_1":"Se
arch","newtab_bookmark_1":"http:\/\/home.playfree.org\/en\/?utm_source
=gs_en&utm_medium=newtab","newtab_bookmark_preview_1":"","newtab_bookm
ark_title_2":"","newtab_bookmark_2":"","newtab_bookmark_preview_2":"",
"newtab_bookmark_title_3":"","newtab_bookmark_3":"","newtab_bookmark_p
review_3":"","newtab_bookmark_title_4":"","newtab_bookmark_4":"","newt
ab_bookmark_preview_4":"","newtab_bookmark_title_5":"","newtab_bookmar
k_5":"","newtab_bookmark_preview_5":"","newtab_bookmark_title_6":"","n
ewtab_bookmark_6":"","newtab_bookmark_preview_6":"","newtab_bookma<<< skipped >>>
GET /customization/?bundle=gs_en HTTP/1.1
User-Agent: Game installer
Host: VVV.playfree.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.7.10
Date: Fri, 01 May 2015 04:18:08 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.38a58..{"target_region":"en","source_site":"en","origin":"gs","desktop_i
con":"","desktop_name":"","desktop_url":"","omnibox_search_name":"Play
Free","omnibox_search_url":"http:\/\/home.playfree.org\/en\/results.ph
p?category=web&s={searchTerms}&utm_source=gs_en&utm_medium=results","o
mnibox_suggest_url":"http:\/\/home.playfree.org\/suggest\/?suggest={se
archTerms}","omnibox_search_keywords":"playfree.org","omnibox_search_f
avicon":"http:\/\/VVV.playfree.org\/favicon.ico","omnibox_search_expor
t":"","home_page_url":"http:\/\/home.playfree.org\/en\/?utm_source=gs_
en&utm_medium=hp","homepage_export":"","newtab_url":"0","newtab_search
_url":"0","welcome_url":"http:\/\/VVV.playfree.org\/en\/welcome.html?u
tm_source=gs_en&utm_medium=welcome","uninstall_url":"uninstall.html","
aboutus_url":"about-us\/","privacy_policy_url":"privacy-policy\/","tou
_url":"terms-of-use\/","support_url":"support\/","howtouninstall_url":
"how-to-uninstall\/","help_url":"help\/","newtab_bookmark_title_1":"Se
arch","newtab_bookmark_1":"http:\/\/home.playfree.org\/en\/?utm_source
=gs_en&utm_medium=newtab","newtab_bookmark_preview_1":"","newtab_bookm
ark_title_2":"","newtab_bookmark_2":"","newtab_bookmark_preview_2":"",
"newtab_bookmark_title_3":"","newtab_bookmark_3":"","newtab_bookmark_p
review_3":"","newtab_bookmark_title_4":"","newtab_bookmark_4":"","newt
ab_bookmark_preview_4":"","newtab_bookmark_title_5":"","newtab_bookmar
k_5":"","newtab_bookmark_preview_5":"","newtab_bookmark_title_6":"","n
ewtab_bookmark_6":"","newtab_bookmark_preview_6":"","newtab_bookma<<< skipped >>>
GET /chunks/goog-malware-shavar/jNaFSriOZfpnZyKuKOMt15IDydkN0sT32zGXqNfHpk0=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:35 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev07.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/jNaFSriOZfpnZyKuKOMt15IDydkN0sT32zGXqNfHpk0=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-phish-shavar/HM7dZNDeI2vQqgLnnwJfkuP4fRmUKMAJ7bTbK1qJ4Ho=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:33 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev11.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-phish-shavar/HM7dZNDeI2vQqgLnnwJfkuP4fRmUKMAJ7bTbK1qJ4Ho=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /chunks/goog-malware-shavar/8NY5MEB8lUJJQjr0HAtADQtTEJjYvFsFmh9jeMOO_dI=.chunk HTTP/1.1
Host: sba.cdn.yandex.net
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.16 (KHTML, like Gecko) Chrome/20.0.1207.0 PlayFreeBrowser/3.0.0.4 Safari/537.16
Accept-Encoding: gzip,deflate,sdch
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.6.2
Date: Fri, 01 May 2015 04:21:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=5
Location: hXXp://cache-kiev01.cdn.yandex.net/sba.cdn.yandex.net/chunks/goog-malware-shavar/8NY5MEB8lUJJQjr0HAtADQtTEJjYvFsFmh9jeMOO_dI=.chunk
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store,no-cache,must-revalidate
Pragma: no-cache0..
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=471323, public, no-transform, must-revalidate
Last-Modified: Wed, 29 Apr 2015 15:15:07 GMT
Expires: Wed, 6 May 2015 15:15:07 GMT
Date: Fri, 01 May 2015 04:22:52 GMT
Connection: keep-alive0..........0..... .....0......0...0......'.V.8.F.V....H....JW..2015042
9151507Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
.A..2.....:...:......20150429151507Z....20150506151507Z0...*.H........
.....M...2..s..7...........rh.O..2Q........Vn...09..e]..D$.u...r3...x.
...T.#...................3.X.."[email protected]".)=..d.3...SZK...bH.PD..
I..9Js.H).2I.....l^|\.?$_7;E......y...ff...}^9...1....}.....fc..:.....
........T...1;'.o..V.e.=.b*tX[.,..M.H..O7..!.%.A..,...#0...0...0......
....r..?.*......y"..0...*.H........0..1.0...U....US1.0...U....VeriSign
, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at http
s://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Signing
2009-2 CA0...150226000000Z..150527235959Z0..1.0...U....US1.0...U....V
eriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use
at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Class 3 Co
de Signing 2009-2 OCSP Responder0.."0...*.H.............0.............
m5*R........2....>...yU4..L.. ...........u..Hez..Pn.....d...nz(...V
7.}^...d!RX...bl..[..a...L.. .~..Ij......%..%p.-...u..:..i..F*]...*...
.{NH..|0...gHX.Q.r....S..........._.9.(w...suC...N..s.....&."...:.C.Q.
i~rl..<..krS..8.B..o][email protected]
.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.verisign.c
om/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incorp. by
reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U........
0... .....0......0"..U....0...0.1.0...U....TGV-B-32010...*.H......<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
@.reloc
QPWSSh
>%u]2
Ht.Ht
tE<.tA<@t=
u.WSh
<.tW<@tS
xSSSh
FTPjKS
FtPj;S
C.PjRV
CHROME_METRO_DLL
app\hard_error_handler_win.cc
ntdll.dll
CHROME_BREAKPAD_PIPE_NAME
1.3.21.115
app\breakpad_win.cc
Check failed: index < kMaxReportedActiveExtensions.
Check failed: url_cstring.
info.size() <= kMaxReportedPrinterRecords
Could not find exported function
app\client_util.cc
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Failed to load Chrome DLL from
Could not get Chrome DLL version.
ChromeMain
installer\util\google_update_settings.cc
Removed multi-install failure key; switching to channel:
Removed incremental installer failure key; switching to channel:
Failed to write to application's ClientState key
installer\util\install_util.cc
C:\quickrr\chromium\src\base/win/scoped_handle.h
installer\util\browser_distribution.cc
C:\quickrr\chromium\src\base/string_util.h
Check failed: length == static_cast<int>(language.length() 1).
CHROME_BINARIES == type
auto-launch-chrome
chrome
chrome-frame
chrome-sxs
do-not-launch-chrome
make-chrome-default
new-setup-exe
register-chrome-browser
register-chrome-browser-suffix
register-url-protocol
rename-chrome-exe
remove-chrome-registration
update-setup-exe
toast-results-key
Check failed: key.
installer\util\channel_info.cc
installer\util\l10n_string_util.cc
installer\util\app_commands.cc
Skipping over key "
Failed to open key "
Cannot initialize AppCommands from an invalid key.
googlechromeframe
installer\util\chrome_app_host_distribution.cc
This should never be accessed as Chrome App Host is not a
This should never be accessed as Chrome App Host has no
googlechromeapphost
installer\util\chromium_binaries_distribution.cc
installer\util\master_preferences.cc
Check failed: master_dictionary_.get().
: Bad boy, the buffer passed to placement new is not aligned!
C:\quickrr\chromium\src\base/lazy_instance.h
installer\util\language_selector.cc
Cannot initialize an AppCommand from an invalid key.
installer\util\app_command.cc
auto_launch_chrome
chrome_frame
chrome_shortcut_icon_index
import_bookmarks
import_bookmarks_from_file
import_history
import_home_page
import_search_engine
do_not_launch_chrome
make_chrome_default
make_chrome_default_for_user
extensions.settings
app\image_pre_reader_win.cc
Check failed: pe_image.VerifyMagic().
reinterpret_cast<const uint8*>(section 1) <= &headers[0] headers.size()
section == pe_image.GetImageSectionFromAddr(start length - 1)
section == pe_image.GetImageSectionFromAddr(start)
ERROR_REPORT
logging.cc
string_util.cc
Check failed: IsWprintfFormatPortable(format).
C:\quickrr\chromium\src\base/string_util_win.h
Check failed: rootkey && subkey && access && disposition.
win\registry.cc
Check failed: rootkey && subkey && access.
Check failed: key_.
Check failed: !subkey.
utf_string_conversions.cc
Check failed: other.IsValid().
version.cc
command_line.cc
user.js
file_path.cc
Check failed: data_.get().
file_version_info_win.cc
string_split.cc
Adebug\trace_event_impl.cc
at_exit.cc
time_win.cc
Check failed: it != outbuf.begin().
string_number_conversions.cc
Check failed: path.empty().
key >= base::DIR_CURRENT
path_service.cc
win\windows_version.cc
version_number_.minor == 2
win\scoped_handle.cc
values.cc
Check failed: (current_entry == dictionary_.end()) || current_entry->second.
Check failed: IsStringUTF8(key).
ins_res.first->second != in_value
json\json_file_value_serializer.cc
win\i18n.cc
kernel32.dll not found.
debug\trace_event_win.cc
callback_internal.cc
threading\thread_local_win.cc
0123456789
C:\quickrr\chromium\src\base/win/scoped_co_mem.h
json\json_writer.cc
win\scoped_process_information.cc
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
json\json_reader.cc
.syzygy
.thunks
Check failed: image.VerifyMagic().
debug\profiler.cc
tracked_objects.cc
\uX
json\json_parser.cc
Line: %i, column: %i, %s
CHROME_PROFILER_TIME
Check failed: !TlsGetValue(g_native_tls_key).
Check failed: value != TLS_OUT_OF_INDEXES.
threading\thread_local_storage_win.cc
kernel32.dll
win\src\sandbox_utils.cc
win\src\win_utils.cc
Check failed: !path.empty().
win\src\broker_services.cc
win\src\sharedmem_ipc_client.cc
Check failed: name.second.
win\src\handle_closer_agent.cc
win\src\restricted_token_utils.cc
win\src\sandbox_policy_base.cc
Check failed: !appcontainer_list_.get().
win\src\app_container.cc
Check failed: attributes_.empty().
Check failed: !capabilities_.AppContainerSid.
win\src\handle_closer.cc
win\src\restricted_token.cc
win\src\sid.cc
win\src\sharedmem_ipc_server.cc
win\src\interception.cc
win\src\window.cc
NtOpenKey
NtCreateKey
win\src\registry_policy.cc
win\src\sync_policy.cc
win\src\filesystem_policy.cc
win\src\crosscall_server.cc
NtOpenKeyEx
win\src\process_thread_dispatcher.cc
CreateNamedPipeW
win\src\acl.cc
win\src\service_resolver.cc
win\src\Wow64.cc
AutoSelectCertificateForUrls
CloudPrintProxyEnabled
CloudPrintSubmitEnabled
CookiesAllowedForUrls
CookiesBlockedForUrls
CookiesSessionOnlyForUrls
DefaultSearchProviderAlternateURLs
DefaultSearchProviderIconURL
DefaultSearchProviderInstantURL
DefaultSearchProviderKeyword
DefaultSearchProviderSearchURL
DefaultSearchProviderSuggestURL
EnableAuthNegotiatePort
EnableOriginBoundCerts
EnterpriseWebStoreName
EnterpriseWebStoreURL
HideWebStorePromo
ImagesAllowedForUrls
ImagesBlockedForUrls
ImportBookmarks
ImportHistory
ImportHomepage
ImportSavedPasswords
ImportSearchEngine
JavaScriptAllowedForUrls
JavaScriptBlockedForUrls
MetricsReportingEnabled
NotificationsAllowedForUrls
NotificationsBlockedForUrls
PasswordManagerAllowShowPasswords
PasswordManagerEnabled
PluginsAllowedForUrls
PluginsBlockedForUrls
PopupsAllowedForUrls
PopupsBlockedForUrls
ProxyBypassList
ProxyPacUrl
RemoteAccessHostDomain
RemoteAccessHostFirewallTraversal
RemoteAccessHostRequireCurtain
RemoteAccessHostRequireTwoFactor
RemoteAccessHostTalkGadgetPrefix
RestoreOnStartupURLs
URLBlacklist
URLWhitelist
ChromeFrameContentTypes
ChromeFrameRendererSettings
ChromeOsLockOnIdleSuspend
ChromeOsReleaseChannel
ChromeOsReleaseChannelDelegated
DeviceLoginScreenSaverId
DeviceLoginScreenSaverTimeout
DeviceMetricsReportingEnabled
DeviceStartUpUrls
RenderInChromeFrameList
ReportDeviceActivityTimes
ReportDeviceBootMode
ReportDeviceLocation
ReportDeviceVersionInfo
full-memory-crash-report
https
0123456789:
?456789:;<=
!"#$%&'()* ,-./0123
windows-936
windows-950
windows-949
windows-932
windows-874
windows-1254
windows-1251
windows-1256
windows-1255
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
windows-%d
!$*);^-/
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones
ucol_nextSortKeyPart
ucol_getSortKey
Returns %d.
Returns. Status = %d.
Returns %d. Status = %d.
Returns %d. Status = %p.
keyMap
keyTypeData
Keys
>CHROME_PRE_READ_EXPERIMENT
CHROME_HEADLESS
CHROME_LOG_FILE
CHROMEOS_SESSION_LOG_DIR
CHROME_CRASHED
CHROME_RESTART
allow-http-background-page
app-notify-channel-server-url
apps-checkout-url
apps-gallery-download-url
apps-gallery-url
apps-gallery-update-url
chrome-frame-shutdown-delay
chrome-version
device-management-url
disable-extensions-http-throttling
disable-sync-passwords
disable-sync-typed-urls
disable-web-resources
disable-website-settings
enable-auth-negotiate-port
enable-autologin
enable-crxless-web-apps
enable-http-pipelining
enable-metrics-reporting-for-testing
enable-npn-http
enable-password-generation
enable-websocket-over-spdy
explicitly-allowed-ports
google-search-domain-check-url
import
import-from-file
install-from-webstore
instant-url
nacl-loader-cmd-prefix
pack-extension-key
promo-server-url
proxy-bypass-list
proxy-pac-url
safebrowsing-url-prefix
sync-invalidate-xmpp-login
sync-keystore-encryption
sync-notification-host-port
sync-url
sync-try-ssltcp-first-for-xmpp
try-chrome-again
ignore-certificate-errors
variations-server-url
visit-urls
thumbnail-urls
web-intents-native-services-enabled
winhttp-proxy-resolver
plugins-metadata-server-url
profile.exited_cleanly
profile.exit_type
session.restore_on_startup
session.urls_to_restore_on_startup
session.restore_on_startup_migrated
intl.app_locale
intl.charset_default
intl.accept_languages
intl.static_encodings
intl.global.charset_default
webkit.webprefs.global.default_font_size
webkit.webprefs.global.default_fixed_font_size
webkit.webprefs.global.minimum_font_size
webkit.webprefs.global.minimum_logical_font_size
webkit.webprefs.global.javascript_can_open_windows_automatically
webkit.webprefs.global.javascript_enabled
webkit.webprefs.global.loads_images_automatically
webkit.webprefs.global.plugins_enabled
webkit.webprefs.global.standard_font_family
webkit.webprefs.global.fixed_font_family
webkit.webprefs.global.serif_font_family
webkit.webprefs.global.sansserif_font_family
webkit.webprefs.global.cursive_font_family
webkit.webprefs.global.fantasy_font_family
webkit.webprefs.standard_font_family
webkit.webprefs.fixed_font_family
webkit.webprefs.serif_font_family
webkit.webprefs.sansserif_font_family
webkit.webprefs.cursive_font_family
webkit.webprefs.fantasy_font_family
webkit.webprefs.fonts.standard
webkit.webprefs.fonts.fixed
webkit.webprefs.fonts.serif
webkit.webprefs.fonts.sansserif
webkit.webprefs.fonts.cursive
webkit.webprefs.fonts.fantasy
webkit.webprefs.fonts.pictograph
webkit.webprefs.fonts.standard.Arab
webkit.webprefs.fonts.fixed.Arab
webkit.webprefs.fonts.serif.Arab
webkit.webprefs.fonts.sansserif.Arab
webkit.webprefs.fonts.standard.Cyrl
webkit.webprefs.fonts.fixed.Cyrl
webkit.webprefs.fonts.serif.Cyrl
webkit.webprefs.fonts.sansserif.Cyrl
webkit.webprefs.fonts.standard.Grek
webkit.webprefs.fonts.fixed.Grek
webkit.webprefs.fonts.serif.Grek
webkit.webprefs.fonts.sansserif.Grek
webkit.webprefs.fonts.standard.Jpan
webkit.webprefs.fonts.fixed.Jpan
webkit.webprefs.fonts.serif.Jpan
webkit.webprefs.fonts.sansserif.Jpan
webkit.webprefs.fonts.standard.Hang
webkit.webprefs.fonts.fixed.Hang
webkit.webprefs.fonts.serif.Hang
webkit.webprefs.fonts.sansserif.Hang
webkit.webprefs.fonts.cursive.Hang
webkit.webprefs.fonts.standard.Hans
webkit.webprefs.fonts.fixed.Hans
webkit.webprefs.fonts.serif.Hans
webkit.webprefs.fonts.sansserif.Hans
webkit.webprefs.fonts.standard.Hant
webkit.webprefs.fonts.fixed.Hant
webkit.webprefs.fonts.serif.Hant
webkit.webprefs.fonts.sansserif.Hant
webkit.webprefs.web_security_enabled
webkit.webprefs.dom_paste_enabled
webkit.webprefs.shrinks_standalone_images_to_fit
webkit.webprefs.inspector_settings
webkit.webprefs.uses_universal_detector
webkit.webprefs.text_areas_are_resizable
webkit.webprefs.java_enabled
webkit.webprefs.tabs_to_links
webkit.webprefs.allow_displaying_insecure_content
webkit.webprefs.allow_running_insecure_content
webkit.webprefs.fonts.standard.Zyyy
webkit.webprefs.fonts.fixed.Zyyy
webkit.webprefs.fonts.serif.Zyyy
webkit.webprefs.fonts.sansserif.Zyyy
webkit.webprefs.fonts.cursive.Zyyy
webkit.webprefs.fonts.fantasy.Zyyy
webkit.webprefs.fonts.pictograph.Zyyy
webkit.webprefs.default_font_size
webkit.webprefs.default_fixed_font_size
webkit.webprefs.minimum_font_size
webkit.webprefs.minimum_logical_font_size
webkit.webprefs.javascript_enabled
webkit.webprefs.javascript_can_open_windows_automatically
webkit.webprefs.loads_images_automatically
webkit.webprefs.plugins_enabled
bookmark_bar.show_on_all_tabs
bookmark_editor.expanded_nodes
profile.password_manager_enabled
profile.password_manager_allow_show_passwords
password_generation.enabled
autologin.enabled
reverse_autologin.enabled
reverse_autologin.rejected_email_list
safebrowsing.enabled
safebrowsing.reporting_enabled
safebrowsing.proceed_anyway_disabled
incognito.mode_availability
search.suggest_enabled
browser.confirm_to_quit
security.cookie_behavior
default_search_provider.synced_guid
default_search_provider.enabled
default_search_provider.search_url
default_search_provider.suggest_url
default_search_provider.instant_url
default_search_provider.icon_url
default_search_provider.encodings
default_search_provider.name
default_search_provider.keyword
default_search_provider.id
default_search_provider.prepopulate_id
default_search_provider.alternate_urls
download.prompt_for_download
alternate_error_pages.enabled
dns_prefetching.startup_list
dns_prefetching.host_referral_list
spdy.disabled
net.http_server_properties
spdy.servers
spdy.alternate_protocol
protocol.disabled_schemes
policy.url_blacklist
policy.url_whitelist
instant.animation_scale_factor
instant.confirm_dialog_shown
instant.enabled
instant.experimental_zero_suggest_url_prefix
instant.show_search_provider_logo
instant.show_white_ntp
local_state.multiple_profile_prefs_version
dns_prefetching.enabled
browser.show_home_button
profile.recently_selected_encodings
browser.clear_data.browsing_history
browser.clear_data.download_history
browser.clear_data.cache
browser.clear_data.cookies
browser.clear_data.passwords
browser.clear_data.form_data
browser.clear_data.hosted_apps_data
browser.clear_data.content_licenses
browser.clear_data.time_period
browser.enable_spellchecking
browser.enabled_labs_experiments
browser.enable_autospellcorrect
browser.speechinput_censor_results
browser.speechinput_tray_notification_shown_contexts
history.saving_disabled
extensions.theme.pack
extensions.theme.id
extensions.theme.images
extensions.theme.colors
extensions.theme.tints
extensions.theme.properties
extensions.ui.developer_mode
extensions.toolbarsize
extensions.commands
plugins.last_internal_directory
plugins.plugins_list
plugins.plugins_disabled
plugins.plugins_disabled_exceptions
plugins.plugins_enabled
plugins.enabled_internal_pdf3
plugins.enabled_nacl
plugins.migrated_to_pepper_flash
plugins.show_details
plugins.allow_outdated
plugins.always_authorize
plugins.metadata
plugins.resource_cache_update
browser.check_default_browser
browser.suppress_switch_to_metro_mode_on_set_default
browser.default_browser_setting_enabled
browser.custom_chrome_frame
browser.show_omnibox_search_hint
profile.notifications_default_content_setting
profile.notification_allowed_sites
profile.notification_denied_sites
browser.desktop_notification_position
profile.default_content_settings
profile.content_settings.clear_on_exit_migrated
profile.content_settings.pref_version
profile.content_settings.patterns
profile.content_settings.pattern_pairs
profile.content_settings.whitelist_version
profile.content_settings.plugin_whitelist
profile.block_third_party_cookies
profile.clear_site_data_on_exit
profile.default_zoom_level
profile.per_host_zoom_levels
autofill.enabled
autofill.auxiliary_profiles_enabled
autofill.positive_upload_rate
autofill.negative_upload_rate
autofill.pdm.first_run
bookmarks.editing_enabled
translate.enabled
geolocation.default_content_setting
geolocation.content_settings
import_saved_passwords
webstore.enterprise_store_url
webstore.enterprise_store_name
profile.avatar_index
profile.name
printing.enabled
printing.print_preview_disabled
profile.last_used
profile.last_active_profiles
profile.profiles_created
profile.created_by_version
profile.info_cache
ssl.rev_checking.enabled
ssl.version_min
ssl.version_max
ssl.cipher_suites.blacklist
ssl.origin_bound_certs.enabled
ssl.ssl_record_splitting.disabled
user_experience_metrics.client_id
user_experience_metrics.session_id
user_experience_metrics.low_entropy_source
user_experience_metrics.client_id_timestamp
user_experience_metrics.reporting_enabled
user_experience_metrics.initial_logs
user_experience_metrics.initial_logs_as_protobufs
user_experience_metrics.ongoing_logs
user_experience_metrics.ongoing_logs_as_protobufs
user_experience_metrics.profiles
user_experience_metrics.stability.exited_cleanly
user_experience_metrics.stability.stats_version
user_experience_metrics.stability.stats_buildtime
user_experience_metrics.stability.session_end_completed
user_experience_metrics.stability.launch_count
user_experience_metrics.stability.crash_count
user_experience_metrics.stability.incomplete_session_end_count
user_experience_metrics.stability.page_load_count
user_experience_metrics.stability.renderer_crash_count
user_experience_metrics.stability.launch_time_sec
user_experience_metrics.stability.extension_renderer_crash_count
user_experience_metrics.stability.last_timestamp_sec
user_experience_metrics.stability.plugin_stats2
user_experience_metrics.stability.renderer_hang_count
user_experience_metrics.stability.child_process_crash_count
user_experience_metrics.stability.other_user_crash_count
user_experience_metrics.stability.kernel_crash_count
user_experience_metrics.stability.system_unclean_shutdowns
user_experience_metrics.stability.breakpad_registration_ok
user_experience_metrics.stability.breakpad_registration_fail
user_experience_metrics.stability.debugger_present
user_experience_metrics.stability.debugger_not_present
uninstall_metrics.page_load_count
uninstall_metrics.launch_count
uninstall_metrics.installation_date2
uninstall_metrics.uptime_sec
uninstall_metrics.last_launch_time_sec
uninstall_metrics.last_observed_running_time_sec
browser.window_placement
task_manager.window_placement
keyword_editor.window_placement
preferences.window_placement
renderer.memory_cache.size
download.default_directory
download.directory_upgrade
savefile.default_directory
savefile.type
selectfile.last_directory
select_file_dialogs.allowed
filebrowser.tasks.default_by_mime_type
filebrowser.tasks.default_by_suffix
download.extensions_to_open
browser.hung_plugin_detect_freq
browser.plugin_message_response_timeout
spellcheck.dictionary
spellcheck.confirm_dialog_shown
spellcheck.use_spelling_service
protocol_handler.excluded_schemes
safe_browsing.client_key
safe_browsing.wrapped_key
options_window.last_tab_index
content_settings_window.last_tab_index
certificate_manager_window.last_tab_index
browser.last_known_google_url
browser.last_prompted_google_url
browser.last_redirect_origin
shutdown.type
shutdown.num_processes
shutdown.num_processes_slow
restart.last.session.on.shutdown
was.restarted
restart.switch_mode
user_experience_metrics.num_bookmarks_on_bookmark_bar
user_experience_metrics.num_folders_on_bookmark_bar
user_experience_metrics.num_bookmarks_in_other_bookmark_folder
user_experience_metrics.num_folders_in_other_bookmark_folder
user_experience_metrics.num_keywords
extensions.disabled
plugins.disable_plugin_finder
extensions.browseractions.container.width
extensions.allowed_install_sites
extensions.install.allowlist
extensions.install.denylist
extensions.alerts.initialized
extensions.install.forcelist
extensions.autoupdate.last_check
extensions.autoupdate.next_check
extensions.blacklistupdate.version
ntp.collapsed_foreign_sessions
ntp.most_visited_blacklist
ntp.promo_resource_cache_update
ntp.tips_resource_server
ntp.date_resource_server
ntp.shown_bookmarks_folder
ntp.shown_page
ntp.promo_desktop_session_found
ntp.webstore_enabled
ntp.app_page_names
ntp.game_page_names
devtools.disabled
devtools.dock_side
devtools.edited_files
devtools.split_location
devtools.open_docked
sync.last_synced_time
sync.has_setup_completed
sync.keep_everything_synced
sync.bookmarks
sync.passwords
sync.preferences
sync.app_notifications
sync.app_settings
sync.apps
sync.autofill
sync.autofill_profile
sync.themes
sync.typed_urls
sync.extensions
sync.extension_settings
sync.search_engines
sync.sessions
sync.managed
sync.suppress_start
sync.acknowledged_types
sync.max_invalidation_versions
sync.session_sync_guid
invalidator.invalidation_state
invalidator.max_invalidation_versions
sync.encryption_bootstrap_token
sync.keystore_encryption_bootstrap_token
sync.using_secondary_passphrase
google.services.username
google.services.username_pattern
sync_promo.startup_count
sync_promo.view_count
sync_promo.user_skipped
sync_promo.show_on_first_run_allowed
sync_promo.show_ntp_bubble
profile.gaia_info_update_time
profile.gaia_info_picture_url
browser.web_app.create_on_desktop
browser.web_app.create_in_apps_menu
browser.web_app.create_in_quick_launch_bar
geolocation.access_token
remote_access.host_firewall_traversal
remote_access.host_require_two_factor
remote_access.host_domain
remote_access.host_talkgadget_prefix
remote_access.host_require_curtain
printing.print_preview_sticky_settings
cloud_print.service_url
cloud_print.signin_url
cloud_print.dialog_size.width
cloud_print.dialog_size.height
cloud_print.signin_dialog_size.width
cloud_print.signin_dialog_size.height
chrome_to_mobile.device_list
background_contents.registered
browser.shown_autolaunch_infobar
auth.schemes
auth.disable_negotiate_cname_lookup
auth.enable_negotiate_port
auth.server_whitelist
auth.negotiate_delegate_whitelist
auth.gssapi_library_name
auth.spdyproxy.origin
auth.allow_cross_origin_prompt
browser.clear_lso_data_enabled
browser.pepper_flash_settings_enabled
browser.disk_cache_dir
browser.disk_cache_size
browser.media_cache_size
cros.system.releaseChannel
policy.load_cloud_policy_on_signin
cloud_print.enabled
cloud_print.proxy_id
cloud_print.auth_token
cloud_print.xmpp_auth_token
cloud_print.email
cloud_print.print_system_settings
cloud_print.enable_job_poll
cloud_print.robot_refresh_token
cloud_print.robot_email
cloud_print.connect_new_printers
cloud_print.printer_blacklist
cloud_print.submit_enabled
net.max_connections_per_proxy
profile.managed_default_content_settings.cookies
profile.managed_default_content_settings.images
profile.managed_default_content_settings.javascript
profile.managed_default_content_settings.plugins
profile.managed_default_content_settings.popups
profile.managed_default_content_settings.geolocation
profile.managed_default_content_settings.notifications
profile.managed_default_content_settings.media_stream
profile.managed_cookies_allowed_for_urls
profile.managed_cookies_blocked_for_urls
profile.managed_cookies_sessiononly_for_urls
profile.managed_images_allowed_for_urls
profile.managed_images_blocked_for_urls
profile.managed_javascript_allowed_for_urls
profile.managed_javascript_blocked_for_urls
profile.managed_plugins_allowed_for_urls
profile.managed_plugins_blocked_for_urls
profile.managed_popups_allowed_for_urls
profile.managed_popups_blocked_for_urls
profile.managed_notifications_allowed_for_urls
profile.managed_notifications_blocked_for_urls
profile.managed_auto_select_certificate_for_urls
background_mode.user_created_login_item
background_mode.user_removed_login_item
background_mode.enabled
custom_handlers.registered_protocol_handlers
custom_handlers.ignored_protocol_handlers
custom_handlers.enabled
policy.device_refresh_rate
policy.user_refresh_rate
recovery_component.version
component_updater.state
webintents.enabled
media_galleries.gallery_id
media_galleries.remembered_galleries
network_profile.warnings_left
network_profile.last_warning_time
policy.last_statistics_update
chrome.googleechotest.com
hXXp://pipelining.googleechotest.com/
allow-webui-compositing
disable-webgl
blacklist-webgl
disable-image-transport-surface
speech-service-key
disable-webaudio
disable-web-security
disable-web-sockets
enable-experimental-webkit-features
disable-web-media-player-ms
enable-privileged-webgl-extensions
enable-tcp-fastopen
enable-viewport
in-process-webgl
remote-debugging-port
renderer-cmd-prefix
testing-fixed-http-port
testing-fixed-https-port
utility-cmd-prefix
webcore-log-channels
zygote-cmd-prefix
Visual C CRT: Not enough memory to complete call to strerror.
?#%X.y
Broken pipe
Inappropriate I/O control operation
Operation not permitted
portuguese-brazilian
GetProcessWindowStation
operator
SHELL32.dll
ole32.dll
C:\quickrr\chromium\src\build\Release\chrome_exe.pdb
ShellExecuteW
SHLWAPI.dll
KERNEL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WINMM.dll
GetWindowsDirectoryW
CreateIoCompletionPort
WaitNamedPipeW
TransactNamedPipe
SetNamedPipeHandleState
GetProcessHandleCount
GetProcessHeap
GetCPInfo
CloseWindowStation
CreateWindowStationW
SetProcessWindowStation
RegQueryInfoKeyW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
PlayFreeBrowser.exe
SetActiveURL
zcÁ
bd.tvt
]"kL:%s!
C$Ö
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD0T1;2c2?3d3
8 8*8>8~8
<$<9<[<{<3 3$3(3<7
6,7074787<7
:':-:5:=:
8$8(8,8084888<8@8
9(9/94989<9]9
9&:,:0:4:8:
8.9;9[9':>:
8&9.969>9~9
3(7,7074787
> >$>8><>
? ?$?(?,?0?4?
5 5$5(5,50545
?$?,?4?<?
\\.\pipe\GoogleCrashServices\
\\.\pipe\ChromeCrashServices
error %u
hurl-chunk-%i
prn-info-%d
0.0.0.0-devel
Chrome
ChromeFrame
Software\Google\ChromeFrame
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}ChromeCanary
registering_chrome
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser
hXXp://VVV.playfree.org/en/uninstall.html?utm_source=[%ORIGIN%]_[%SOURCE_SITE%]&utm_medium=uninstall
%d.%d.%d
ed-d-d
hXXp://update.playfree.org/browser/updatechecker/?
{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}{00337EA4-7B9A-44a6-B45B-B1722CD4343E}MPCBrowserUpdate.exe
CFEndTempOptOutCmd
CFOptInCmd
CFOptOutCmd
CFTempOptOutCmd
UninstallCmdLine
WebAccessible
app_host.exe
PlayFreeBrowser.dll
npchrome_frame.dll
chrome_frame_helper.exe
ChromeFrameHelperWindowClass
ChromeFrameReadyMode
chrome_launcher.exe
new_chrome.exe
old_chrome.exe
delegate_execute.exe
nacl64.exe
setup.exe
InstallerSuccessLaunchCmdLine
-chrome
-chromeframe
{5C65F4B0-3651-4514-B207-D10CB699B14B}hXXps://clients4.google.com/firefox/metrics/collect
{8BA986DA-5100-405E-AA35-86F34A02ACBF}Google Chrome Frame
Google\Chrome Frame
Chrome in a Frame.
Uninstall Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}Google Chrome App Host
A standalone platform for Chrome apps.
.Uninstall Chrome App Host
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome App Host
debug_message.exe
debug.log
.\debug.log
Software\Microsoft\Windows\CurrentVersion\Run
\StringFileInfo\xx\%ls
ckernel32.dll
psapi.dll
Chrome_MessagePumpWindow
%s\%s.dmp
rpcrt4.dll
dbghelp.dll
x-x-x-xx-xxxxxx
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_NLSTEXT
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
pipe\
ALPC Port
cntdll.dll
s0x%X
wow_helper.exe"
00000000
333333333333333333
333333333336
%%CollationBin
NPlayFreeBrowser.exe
metro_driver.dll
Chrome_StatusTrayWindow
Chrome_MessageWindow
Reported Crashes.txt
testing_interface.dll
Certificate Revocation Lists
Custom Dictionary.txt
Login Data
Origin Bound Certs
Cached Theme.pak
Web Applications
Web Data
pepflashplayer.dll
CHROME_METRO_NAV_SEARCH_REQUEST
CHROME_METRO_GET_CURRENT_TAB_INFO
mscoree.dll
ADVAPI32.DLL
nKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe
3.0.0.4
chrome_exe
PlayFreeBrowser.exe_3336:
.text
`.rdata
@.data
.rsrc
@.reloc
QPWSSh
>%u]2
Ht.Ht
tE<.tA<@t=
u.WSh
<.tW<@tS
xSSSh
FTPjKS
FtPj;S
C.PjRV
CHROME_METRO_DLL
app\hard_error_handler_win.cc
ntdll.dll
CHROME_BREAKPAD_PIPE_NAME
1.3.21.115
app\breakpad_win.cc
Check failed: index < kMaxReportedActiveExtensions.
Check failed: url_cstring.
info.size() <= kMaxReportedPrinterRecords
Could not find exported function
app\client_util.cc
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Failed to load Chrome DLL from
Could not get Chrome DLL version.
ChromeMain
installer\util\google_update_settings.cc
Removed multi-install failure key; switching to channel:
Removed incremental installer failure key; switching to channel:
Failed to write to application's ClientState key
installer\util\install_util.cc
C:\quickrr\chromium\src\base/win/scoped_handle.h
installer\util\browser_distribution.cc
C:\quickrr\chromium\src\base/string_util.h
Check failed: length == static_cast<int>(language.length() 1).
CHROME_BINARIES == type
auto-launch-chrome
chrome
chrome-frame
chrome-sxs
do-not-launch-chrome
make-chrome-default
new-setup-exe
register-chrome-browser
register-chrome-browser-suffix
register-url-protocol
rename-chrome-exe
remove-chrome-registration
update-setup-exe
toast-results-key
Check failed: key.
installer\util\channel_info.cc
installer\util\l10n_string_util.cc
installer\util\app_commands.cc
Skipping over key "
Failed to open key "
Cannot initialize AppCommands from an invalid key.
googlechromeframe
installer\util\chrome_app_host_distribution.cc
This should never be accessed as Chrome App Host is not a
This should never be accessed as Chrome App Host has no
googlechromeapphost
installer\util\chromium_binaries_distribution.cc
installer\util\master_preferences.cc
Check failed: master_dictionary_.get().
: Bad boy, the buffer passed to placement new is not aligned!
C:\quickrr\chromium\src\base/lazy_instance.h
installer\util\language_selector.cc
Cannot initialize an AppCommand from an invalid key.
installer\util\app_command.cc
auto_launch_chrome
chrome_frame
chrome_shortcut_icon_index
import_bookmarks
import_bookmarks_from_file
import_history
import_home_page
import_search_engine
do_not_launch_chrome
make_chrome_default
make_chrome_default_for_user
extensions.settings
app\image_pre_reader_win.cc
Check failed: pe_image.VerifyMagic().
reinterpret_cast<const uint8*>(section 1) <= &headers[0] headers.size()
section == pe_image.GetImageSectionFromAddr(start length - 1)
section == pe_image.GetImageSectionFromAddr(start)
ERROR_REPORT
logging.cc
string_util.cc
Check failed: IsWprintfFormatPortable(format).
C:\quickrr\chromium\src\base/string_util_win.h
Check failed: rootkey && subkey && access && disposition.
win\registry.cc
Check failed: rootkey && subkey && access.
Check failed: key_.
Check failed: !subkey.
utf_string_conversions.cc
Check failed: other.IsValid().
version.cc
command_line.cc
user.js
file_path.cc
Check failed: data_.get().
file_version_info_win.cc
string_split.cc
Adebug\trace_event_impl.cc
at_exit.cc
time_win.cc
Check failed: it != outbuf.begin().
string_number_conversions.cc
Check failed: path.empty().
key >= base::DIR_CURRENT
path_service.cc
win\windows_version.cc
version_number_.minor == 2
win\scoped_handle.cc
values.cc
Check failed: (current_entry == dictionary_.end()) || current_entry->second.
Check failed: IsStringUTF8(key).
ins_res.first->second != in_value
json\json_file_value_serializer.cc
win\i18n.cc
kernel32.dll not found.
debug\trace_event_win.cc
callback_internal.cc
threading\thread_local_win.cc
0123456789
C:\quickrr\chromium\src\base/win/scoped_co_mem.h
json\json_writer.cc
win\scoped_process_information.cc
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
json\json_reader.cc
.syzygy
.thunks
Check failed: image.VerifyMagic().
debug\profiler.cc
tracked_objects.cc
\uX
json\json_parser.cc
Line: %i, column: %i, %s
CHROME_PROFILER_TIME
Check failed: !TlsGetValue(g_native_tls_key).
Check failed: value != TLS_OUT_OF_INDEXES.
threading\thread_local_storage_win.cc
kernel32.dll
win\src\sandbox_utils.cc
win\src\win_utils.cc
Check failed: !path.empty().
win\src\broker_services.cc
win\src\sharedmem_ipc_client.cc
Check failed: name.second.
win\src\handle_closer_agent.cc
win\src\restricted_token_utils.cc
win\src\sandbox_policy_base.cc
Check failed: !appcontainer_list_.get().
win\src\app_container.cc
Check failed: attributes_.empty().
Check failed: !capabilities_.AppContainerSid.
win\src\handle_closer.cc
win\src\restricted_token.cc
win\src\sid.cc
win\src\sharedmem_ipc_server.cc
win\src\interception.cc
win\src\window.cc
NtOpenKey
NtCreateKey
win\src\registry_policy.cc
win\src\sync_policy.cc
win\src\filesystem_policy.cc
win\src\crosscall_server.cc
NtOpenKeyEx
win\src\process_thread_dispatcher.cc
CreateNamedPipeW
win\src\acl.cc
win\src\service_resolver.cc
win\src\Wow64.cc
AutoSelectCertificateForUrls
CloudPrintProxyEnabled
CloudPrintSubmitEnabled
CookiesAllowedForUrls
CookiesBlockedForUrls
CookiesSessionOnlyForUrls
DefaultSearchProviderAlternateURLs
DefaultSearchProviderIconURL
DefaultSearchProviderInstantURL
DefaultSearchProviderKeyword
DefaultSearchProviderSearchURL
DefaultSearchProviderSuggestURL
EnableAuthNegotiatePort
EnableOriginBoundCerts
EnterpriseWebStoreName
EnterpriseWebStoreURL
HideWebStorePromo
ImagesAllowedForUrls
ImagesBlockedForUrls
ImportBookmarks
ImportHistory
ImportHomepage
ImportSavedPasswords
ImportSearchEngine
JavaScriptAllowedForUrls
JavaScriptBlockedForUrls
MetricsReportingEnabled
NotificationsAllowedForUrls
NotificationsBlockedForUrls
PasswordManagerAllowShowPasswords
PasswordManagerEnabled
PluginsAllowedForUrls
PluginsBlockedForUrls
PopupsAllowedForUrls
PopupsBlockedForUrls
ProxyBypassList
ProxyPacUrl
RemoteAccessHostDomain
RemoteAccessHostFirewallTraversal
RemoteAccessHostRequireCurtain
RemoteAccessHostRequireTwoFactor
RemoteAccessHostTalkGadgetPrefix
RestoreOnStartupURLs
URLBlacklist
URLWhitelist
ChromeFrameContentTypes
ChromeFrameRendererSettings
ChromeOsLockOnIdleSuspend
ChromeOsReleaseChannel
ChromeOsReleaseChannelDelegated
DeviceLoginScreenSaverId
DeviceLoginScreenSaverTimeout
DeviceMetricsReportingEnabled
DeviceStartUpUrls
RenderInChromeFrameList
ReportDeviceActivityTimes
ReportDeviceBootMode
ReportDeviceLocation
ReportDeviceVersionInfo
full-memory-crash-report
https
0123456789:
?456789:;<=
!"#$%&'()* ,-./0123
windows-936
windows-950
windows-949
windows-932
windows-874
windows-1254
windows-1251
windows-1256
windows-1255
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
windows-%d
!$*);^-/
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones
ucol_nextSortKeyPart
ucol_getSortKey
Returns %d.
Returns. Status = %d.
Returns %d. Status = %d.
Returns %d. Status = %p.
keyMap
keyTypeData
Keys
>CHROME_PRE_READ_EXPERIMENT
CHROME_HEADLESS
CHROME_LOG_FILE
CHROMEOS_SESSION_LOG_DIR
CHROME_CRASHED
CHROME_RESTART
allow-http-background-page
app-notify-channel-server-url
apps-checkout-url
apps-gallery-download-url
apps-gallery-url
apps-gallery-update-url
chrome-frame-shutdown-delay
chrome-version
device-management-url
disable-extensions-http-throttling
disable-sync-passwords
disable-sync-typed-urls
disable-web-resources
disable-website-settings
enable-auth-negotiate-port
enable-autologin
enable-crxless-web-apps
enable-http-pipelining
enable-metrics-reporting-for-testing
enable-npn-http
enable-password-generation
enable-websocket-over-spdy
explicitly-allowed-ports
google-search-domain-check-url
import
import-from-file
install-from-webstore
instant-url
nacl-loader-cmd-prefix
pack-extension-key
promo-server-url
proxy-bypass-list
proxy-pac-url
safebrowsing-url-prefix
sync-invalidate-xmpp-login
sync-keystore-encryption
sync-notification-host-port
sync-url
sync-try-ssltcp-first-for-xmpp
try-chrome-again
ignore-certificate-errors
variations-server-url
visit-urls
thumbnail-urls
web-intents-native-services-enabled
winhttp-proxy-resolver
plugins-metadata-server-url
profile.exited_cleanly
profile.exit_type
session.restore_on_startup
session.urls_to_restore_on_startup
session.restore_on_startup_migrated
intl.app_locale
intl.charset_default
intl.accept_languages
intl.static_encodings
intl.global.charset_default
webkit.webprefs.global.default_font_size
webkit.webprefs.global.default_fixed_font_size
webkit.webprefs.global.minimum_font_size
webkit.webprefs.global.minimum_logical_font_size
webkit.webprefs.global.javascript_can_open_windows_automatically
webkit.webprefs.global.javascript_enabled
webkit.webprefs.global.loads_images_automatically
webkit.webprefs.global.plugins_enabled
webkit.webprefs.global.standard_font_family
webkit.webprefs.global.fixed_font_family
webkit.webprefs.global.serif_font_family
webkit.webprefs.global.sansserif_font_family
webkit.webprefs.global.cursive_font_family
webkit.webprefs.global.fantasy_font_family
webkit.webprefs.standard_font_family
webkit.webprefs.fixed_font_family
webkit.webprefs.serif_font_family
webkit.webprefs.sansserif_font_family
webkit.webprefs.cursive_font_family
webkit.webprefs.fantasy_font_family
webkit.webprefs.fonts.standard
webkit.webprefs.fonts.fixed
webkit.webprefs.fonts.serif
webkit.webprefs.fonts.sansserif
webkit.webprefs.fonts.cursive
webkit.webprefs.fonts.fantasy
webkit.webprefs.fonts.pictograph
webkit.webprefs.fonts.standard.Arab
webkit.webprefs.fonts.fixed.Arab
webkit.webprefs.fonts.serif.Arab
webkit.webprefs.fonts.sansserif.Arab
webkit.webprefs.fonts.standard.Cyrl
webkit.webprefs.fonts.fixed.Cyrl
webkit.webprefs.fonts.serif.Cyrl
webkit.webprefs.fonts.sansserif.Cyrl
webkit.webprefs.fonts.standard.Grek
webkit.webprefs.fonts.fixed.Grek
webkit.webprefs.fonts.serif.Grek
webkit.webprefs.fonts.sansserif.Grek
webkit.webprefs.fonts.standard.Jpan
webkit.webprefs.fonts.fixed.Jpan
webkit.webprefs.fonts.serif.Jpan
webkit.webprefs.fonts.sansserif.Jpan
webkit.webprefs.fonts.standard.Hang
webkit.webprefs.fonts.fixed.Hang
webkit.webprefs.fonts.serif.Hang
webkit.webprefs.fonts.sansserif.Hang
webkit.webprefs.fonts.cursive.Hang
webkit.webprefs.fonts.standard.Hans
webkit.webprefs.fonts.fixed.Hans
webkit.webprefs.fonts.serif.Hans
webkit.webprefs.fonts.sansserif.Hans
webkit.webprefs.fonts.standard.Hant
webkit.webprefs.fonts.fixed.Hant
webkit.webprefs.fonts.serif.Hant
webkit.webprefs.fonts.sansserif.Hant
webkit.webprefs.web_security_enabled
webkit.webprefs.dom_paste_enabled
webkit.webprefs.shrinks_standalone_images_to_fit
webkit.webprefs.inspector_settings
webkit.webprefs.uses_universal_detector
webkit.webprefs.text_areas_are_resizable
webkit.webprefs.java_enabled
webkit.webprefs.tabs_to_links
webkit.webprefs.allow_displaying_insecure_content
webkit.webprefs.allow_running_insecure_content
webkit.webprefs.fonts.standard.Zyyy
webkit.webprefs.fonts.fixed.Zyyy
webkit.webprefs.fonts.serif.Zyyy
webkit.webprefs.fonts.sansserif.Zyyy
webkit.webprefs.fonts.cursive.Zyyy
webkit.webprefs.fonts.fantasy.Zyyy
webkit.webprefs.fonts.pictograph.Zyyy
webkit.webprefs.default_font_size
webkit.webprefs.default_fixed_font_size
webkit.webprefs.minimum_font_size
webkit.webprefs.minimum_logical_font_size
webkit.webprefs.javascript_enabled
webkit.webprefs.javascript_can_open_windows_automatically
webkit.webprefs.loads_images_automatically
webkit.webprefs.plugins_enabled
bookmark_bar.show_on_all_tabs
bookmark_editor.expanded_nodes
profile.password_manager_enabled
profile.password_manager_allow_show_passwords
password_generation.enabled
autologin.enabled
reverse_autologin.enabled
reverse_autologin.rejected_email_list
safebrowsing.enabled
safebrowsing.reporting_enabled
safebrowsing.proceed_anyway_disabled
incognito.mode_availability
search.suggest_enabled
browser.confirm_to_quit
security.cookie_behavior
default_search_provider.synced_guid
default_search_provider.enabled
default_search_provider.search_url
default_search_provider.suggest_url
default_search_provider.instant_url
default_search_provider.icon_url
default_search_provider.encodings
default_search_provider.name
default_search_provider.keyword
default_search_provider.id
default_search_provider.prepopulate_id
default_search_provider.alternate_urls
download.prompt_for_download
alternate_error_pages.enabled
dns_prefetching.startup_list
dns_prefetching.host_referral_list
spdy.disabled
net.http_server_properties
spdy.servers
spdy.alternate_protocol
protocol.disabled_schemes
policy.url_blacklist
policy.url_whitelist
instant.animation_scale_factor
instant.confirm_dialog_shown
instant.enabled
instant.experimental_zero_suggest_url_prefix
instant.show_search_provider_logo
instant.show_white_ntp
local_state.multiple_profile_prefs_version
dns_prefetching.enabled
browser.show_home_button
profile.recently_selected_encodings
browser.clear_data.browsing_history
browser.clear_data.download_history
browser.clear_data.cache
browser.clear_data.cookies
browser.clear_data.passwords
browser.clear_data.form_data
browser.clear_data.hosted_apps_data
browser.clear_data.content_licenses
browser.clear_data.time_period
browser.enable_spellchecking
browser.enabled_labs_experiments
browser.enable_autospellcorrect
browser.speechinput_censor_results
browser.speechinput_tray_notification_shown_contexts
history.saving_disabled
extensions.theme.pack
extensions.theme.id
extensions.theme.images
extensions.theme.colors
extensions.theme.tints
extensions.theme.properties
extensions.ui.developer_mode
extensions.toolbarsize
extensions.commands
plugins.last_internal_directory
plugins.plugins_list
plugins.plugins_disabled
plugins.plugins_disabled_exceptions
plugins.plugins_enabled
plugins.enabled_internal_pdf3
plugins.enabled_nacl
plugins.migrated_to_pepper_flash
plugins.show_details
plugins.allow_outdated
plugins.always_authorize
plugins.metadata
plugins.resource_cache_update
browser.check_default_browser
browser.suppress_switch_to_metro_mode_on_set_default
browser.default_browser_setting_enabled
browser.custom_chrome_frame
browser.show_omnibox_search_hint
profile.notifications_default_content_setting
profile.notification_allowed_sites
profile.notification_denied_sites
browser.desktop_notification_position
profile.default_content_settings
profile.content_settings.clear_on_exit_migrated
profile.content_settings.pref_version
profile.content_settings.patterns
profile.content_settings.pattern_pairs
profile.content_settings.whitelist_version
profile.content_settings.plugin_whitelist
profile.block_third_party_cookies
profile.clear_site_data_on_exit
profile.default_zoom_level
profile.per_host_zoom_levels
autofill.enabled
autofill.auxiliary_profiles_enabled
autofill.positive_upload_rate
autofill.negative_upload_rate
autofill.pdm.first_run
bookmarks.editing_enabled
translate.enabled
geolocation.default_content_setting
geolocation.content_settings
import_saved_passwords
webstore.enterprise_store_url
webstore.enterprise_store_name
profile.avatar_index
profile.name
printing.enabled
printing.print_preview_disabled
profile.last_used
profile.last_active_profiles
profile.profiles_created
profile.created_by_version
profile.info_cache
ssl.rev_checking.enabled
ssl.version_min
ssl.version_max
ssl.cipher_suites.blacklist
ssl.origin_bound_certs.enabled
ssl.ssl_record_splitting.disabled
user_experience_metrics.client_id
user_experience_metrics.session_id
user_experience_metrics.low_entropy_source
user_experience_metrics.client_id_timestamp
user_experience_metrics.reporting_enabled
user_experience_metrics.initial_logs
user_experience_metrics.initial_logs_as_protobufs
user_experience_metrics.ongoing_logs
user_experience_metrics.ongoing_logs_as_protobufs
user_experience_metrics.profiles
user_experience_metrics.stability.exited_cleanly
user_experience_metrics.stability.stats_version
user_experience_metrics.stability.stats_buildtime
user_experience_metrics.stability.session_end_completed
user_experience_metrics.stability.launch_count
user_experience_metrics.stability.crash_count
user_experience_metrics.stability.incomplete_session_end_count
user_experience_metrics.stability.page_load_count
user_experience_metrics.stability.renderer_crash_count
user_experience_metrics.stability.launch_time_sec
user_experience_metrics.stability.extension_renderer_crash_count
user_experience_metrics.stability.last_timestamp_sec
user_experience_metrics.stability.plugin_stats2
user_experience_metrics.stability.renderer_hang_count
user_experience_metrics.stability.child_process_crash_count
user_experience_metrics.stability.other_user_crash_count
user_experience_metrics.stability.kernel_crash_count
user_experience_metrics.stability.system_unclean_shutdowns
user_experience_metrics.stability.breakpad_registration_ok
user_experience_metrics.stability.breakpad_registration_fail
user_experience_metrics.stability.debugger_present
user_experience_metrics.stability.debugger_not_present
uninstall_metrics.page_load_count
uninstall_metrics.launch_count
uninstall_metrics.installation_date2
uninstall_metrics.uptime_sec
uninstall_metrics.last_launch_time_sec
uninstall_metrics.last_observed_running_time_sec
browser.window_placement
task_manager.window_placement
keyword_editor.window_placement
preferences.window_placement
renderer.memory_cache.size
download.default_directory
download.directory_upgrade
savefile.default_directory
savefile.type
selectfile.last_directory
select_file_dialogs.allowed
filebrowser.tasks.default_by_mime_type
filebrowser.tasks.default_by_suffix
download.extensions_to_open
browser.hung_plugin_detect_freq
browser.plugin_message_response_timeout
spellcheck.dictionary
spellcheck.confirm_dialog_shown
spellcheck.use_spelling_service
protocol_handler.excluded_schemes
safe_browsing.client_key
safe_browsing.wrapped_key
options_window.last_tab_index
content_settings_window.last_tab_index
certificate_manager_window.last_tab_index
browser.last_known_google_url
browser.last_prompted_google_url
browser.last_redirect_origin
shutdown.type
shutdown.num_processes
shutdown.num_processes_slow
restart.last.session.on.shutdown
was.restarted
restart.switch_mode
user_experience_metrics.num_bookmarks_on_bookmark_bar
user_experience_metrics.num_folders_on_bookmark_bar
user_experience_metrics.num_bookmarks_in_other_bookmark_folder
user_experience_metrics.num_folders_in_other_bookmark_folder
user_experience_metrics.num_keywords
extensions.disabled
plugins.disable_plugin_finder
extensions.browseractions.container.width
extensions.allowed_install_sites
extensions.install.allowlist
extensions.install.denylist
extensions.alerts.initialized
extensions.install.forcelist
extensions.autoupdate.last_check
extensions.autoupdate.next_check
extensions.blacklistupdate.version
ntp.collapsed_foreign_sessions
ntp.most_visited_blacklist
ntp.promo_resource_cache_update
ntp.tips_resource_server
ntp.date_resource_server
ntp.shown_bookmarks_folder
ntp.shown_page
ntp.promo_desktop_session_found
ntp.webstore_enabled
ntp.app_page_names
ntp.game_page_names
devtools.disabled
devtools.dock_side
devtools.edited_files
devtools.split_location
devtools.open_docked
sync.last_synced_time
sync.has_setup_completed
sync.keep_everything_synced
sync.bookmarks
sync.passwords
sync.preferences
sync.app_notifications
sync.app_settings
sync.apps
sync.autofill
sync.autofill_profile
sync.themes
sync.typed_urls
sync.extensions
sync.extension_settings
sync.search_engines
sync.sessions
sync.managed
sync.suppress_start
sync.acknowledged_types
sync.max_invalidation_versions
sync.session_sync_guid
invalidator.invalidation_state
invalidator.max_invalidation_versions
sync.encryption_bootstrap_token
sync.keystore_encryption_bootstrap_token
sync.using_secondary_passphrase
google.services.username
google.services.username_pattern
sync_promo.startup_count
sync_promo.view_count
sync_promo.user_skipped
sync_promo.show_on_first_run_allowed
sync_promo.show_ntp_bubble
profile.gaia_info_update_time
profile.gaia_info_picture_url
browser.web_app.create_on_desktop
browser.web_app.create_in_apps_menu
browser.web_app.create_in_quick_launch_bar
geolocation.access_token
remote_access.host_firewall_traversal
remote_access.host_require_two_factor
remote_access.host_domain
remote_access.host_talkgadget_prefix
remote_access.host_require_curtain
printing.print_preview_sticky_settings
cloud_print.service_url
cloud_print.signin_url
cloud_print.dialog_size.width
cloud_print.dialog_size.height
cloud_print.signin_dialog_size.width
cloud_print.signin_dialog_size.height
chrome_to_mobile.device_list
background_contents.registered
browser.shown_autolaunch_infobar
auth.schemes
auth.disable_negotiate_cname_lookup
auth.enable_negotiate_port
auth.server_whitelist
auth.negotiate_delegate_whitelist
auth.gssapi_library_name
auth.spdyproxy.origin
auth.allow_cross_origin_prompt
browser.clear_lso_data_enabled
browser.pepper_flash_settings_enabled
browser.disk_cache_dir
browser.disk_cache_size
browser.media_cache_size
cros.system.releaseChannel
policy.load_cloud_policy_on_signin
cloud_print.enabled
cloud_print.proxy_id
cloud_print.auth_token
cloud_print.xmpp_auth_token
cloud_print.email
cloud_print.print_system_settings
cloud_print.enable_job_poll
cloud_print.robot_refresh_token
cloud_print.robot_email
cloud_print.connect_new_printers
cloud_print.printer_blacklist
cloud_print.submit_enabled
net.max_connections_per_proxy
profile.managed_default_content_settings.cookies
profile.managed_default_content_settings.images
profile.managed_default_content_settings.javascript
profile.managed_default_content_settings.plugins
profile.managed_default_content_settings.popups
profile.managed_default_content_settings.geolocation
profile.managed_default_content_settings.notifications
profile.managed_default_content_settings.media_stream
profile.managed_cookies_allowed_for_urls
profile.managed_cookies_blocked_for_urls
profile.managed_cookies_sessiononly_for_urls
profile.managed_images_allowed_for_urls
profile.managed_images_blocked_for_urls
profile.managed_javascript_allowed_for_urls
profile.managed_javascript_blocked_for_urls
profile.managed_plugins_allowed_for_urls
profile.managed_plugins_blocked_for_urls
profile.managed_popups_allowed_for_urls
profile.managed_popups_blocked_for_urls
profile.managed_notifications_allowed_for_urls
profile.managed_notifications_blocked_for_urls
profile.managed_auto_select_certificate_for_urls
background_mode.user_created_login_item
background_mode.user_removed_login_item
background_mode.enabled
custom_handlers.registered_protocol_handlers
custom_handlers.ignored_protocol_handlers
custom_handlers.enabled
policy.device_refresh_rate
policy.user_refresh_rate
recovery_component.version
component_updater.state
webintents.enabled
media_galleries.gallery_id
media_galleries.remembered_galleries
network_profile.warnings_left
network_profile.last_warning_time
policy.last_statistics_update
chrome.googleechotest.com
hXXp://pipelining.googleechotest.com/
allow-webui-compositing
disable-webgl
blacklist-webgl
disable-image-transport-surface
speech-service-key
disable-webaudio
disable-web-security
disable-web-sockets
enable-experimental-webkit-features
disable-web-media-player-ms
enable-privileged-webgl-extensions
enable-tcp-fastopen
enable-viewport
in-process-webgl
remote-debugging-port
renderer-cmd-prefix
testing-fixed-http-port
testing-fixed-https-port
utility-cmd-prefix
webcore-log-channels
zygote-cmd-prefix
Visual C CRT: Not enough memory to complete call to strerror.
?#%X.y
Broken pipe
Inappropriate I/O control operation
Operation not permitted
portuguese-brazilian
GetProcessWindowStation
operator
SHELL32.dll
ole32.dll
C:\quickrr\chromium\src\build\Release\chrome_exe.pdb
ShellExecuteW
SHLWAPI.dll
KERNEL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WINMM.dll
GetWindowsDirectoryW
CreateIoCompletionPort
WaitNamedPipeW
TransactNamedPipe
SetNamedPipeHandleState
GetProcessHandleCount
GetProcessHeap
GetCPInfo
CloseWindowStation
CreateWindowStationW
SetProcessWindowStation
RegQueryInfoKeyW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
PlayFreeBrowser.exe
SetActiveURL
zcÁ
bd.tvt
]"kL:%s!
C$Ö
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD0T1;2c2?3d3
8 8*8>8~8
<$<9<[<{<3 3$3(3<7
6,7074787<7
:':-:5:=:
8$8(8,8084888<8@8
9(9/94989<9]9
9&:,:0:4:8:
8.9;9[9':>:
8&9.969>9~9
3(7,7074787
> >$>8><>
? ?$?(?,?0?4?
5 5$5(5,50545
?$?,?4?<?
\\.\pipe\GoogleCrashServices\
\\.\pipe\ChromeCrashServices
error %u
hurl-chunk-%i
prn-info-%d
0.0.0.0-devel
Chrome
ChromeFrame
Software\Google\ChromeFrame
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}ChromeCanary
registering_chrome
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser
hXXp://VVV.playfree.org/en/uninstall.html?utm_source=[%ORIGIN%]_[%SOURCE_SITE%]&utm_medium=uninstall
%d.%d.%d
ed-d-d
hXXp://update.playfree.org/browser/updatechecker/?
{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}{00337EA4-7B9A-44a6-B45B-B1722CD4343E}MPCBrowserUpdate.exe
CFEndTempOptOutCmd
CFOptInCmd
CFOptOutCmd
CFTempOptOutCmd
UninstallCmdLine
WebAccessible
app_host.exe
PlayFreeBrowser.dll
npchrome_frame.dll
chrome_frame_helper.exe
ChromeFrameHelperWindowClass
ChromeFrameReadyMode
chrome_launcher.exe
new_chrome.exe
old_chrome.exe
delegate_execute.exe
nacl64.exe
setup.exe
InstallerSuccessLaunchCmdLine
-chrome
-chromeframe
{5C65F4B0-3651-4514-B207-D10CB699B14B}hXXps://clients4.google.com/firefox/metrics/collect
{8BA986DA-5100-405E-AA35-86F34A02ACBF}Google Chrome Frame
Google\Chrome Frame
Chrome in a Frame.
Uninstall Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}Google Chrome App Host
A standalone platform for Chrome apps.
.Uninstall Chrome App Host
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome App Host
debug_message.exe
debug.log
.\debug.log
Software\Microsoft\Windows\CurrentVersion\Run
\StringFileInfo\xx\%ls
ckernel32.dll
psapi.dll
Chrome_MessagePumpWindow
%s\%s.dmp
rpcrt4.dll
dbghelp.dll
x-x-x-xx-xxxxxx
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_NLSTEXT
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
pipe\
ALPC Port
cntdll.dll
s0x%X
wow_helper.exe"
00000000
333333333333333333
333333333336
%%CollationBin
NPlayFreeBrowser.exe
metro_driver.dll
Chrome_StatusTrayWindow
Chrome_MessageWindow
Reported Crashes.txt
testing_interface.dll
Certificate Revocation Lists
Custom Dictionary.txt
Login Data
Origin Bound Certs
Cached Theme.pak
Web Applications
Web Data
pepflashplayer.dll
CHROME_METRO_NAV_SEARCH_REQUEST
CHROME_METRO_GET_CURRENT_TAB_INFO
mscoree.dll
ADVAPI32.DLL
nKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe
3.0.0.4
chrome_exe
PlayFreeBrowser.exe_3336_rwx_1630A000_00060000:
j.hmO
Ph%SR
PlayFreeBrowser.exe_3528:
.text
`.rdata
@.data
.rsrc
@.reloc
QPWSSh
>%u]2
Ht.Ht
tE<.tA<@t=
u.WSh
<.tW<@tS
xSSSh
FTPjKS
FtPj;S
C.PjRV
CHROME_METRO_DLL
app\hard_error_handler_win.cc
ntdll.dll
CHROME_BREAKPAD_PIPE_NAME
1.3.21.115
app\breakpad_win.cc
Check failed: index < kMaxReportedActiveExtensions.
Check failed: url_cstring.
info.size() <= kMaxReportedPrinterRecords
Could not find exported function
app\client_util.cc
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Failed to load Chrome DLL from
Could not get Chrome DLL version.
ChromeMain
installer\util\google_update_settings.cc
Removed multi-install failure key; switching to channel:
Removed incremental installer failure key; switching to channel:
Failed to write to application's ClientState key
installer\util\install_util.cc
C:\quickrr\chromium\src\base/win/scoped_handle.h
installer\util\browser_distribution.cc
C:\quickrr\chromium\src\base/string_util.h
Check failed: length == static_cast<int>(language.length() 1).
CHROME_BINARIES == type
auto-launch-chrome
chrome
chrome-frame
chrome-sxs
do-not-launch-chrome
make-chrome-default
new-setup-exe
register-chrome-browser
register-chrome-browser-suffix
register-url-protocol
rename-chrome-exe
remove-chrome-registration
update-setup-exe
toast-results-key
Check failed: key.
installer\util\channel_info.cc
installer\util\l10n_string_util.cc
installer\util\app_commands.cc
Skipping over key "
Failed to open key "
Cannot initialize AppCommands from an invalid key.
googlechromeframe
installer\util\chrome_app_host_distribution.cc
This should never be accessed as Chrome App Host is not a
This should never be accessed as Chrome App Host has no
googlechromeapphost
installer\util\chromium_binaries_distribution.cc
installer\util\master_preferences.cc
Check failed: master_dictionary_.get().
: Bad boy, the buffer passed to placement new is not aligned!
C:\quickrr\chromium\src\base/lazy_instance.h
installer\util\language_selector.cc
Cannot initialize an AppCommand from an invalid key.
installer\util\app_command.cc
auto_launch_chrome
chrome_frame
chrome_shortcut_icon_index
import_bookmarks
import_bookmarks_from_file
import_history
import_home_page
import_search_engine
do_not_launch_chrome
make_chrome_default
make_chrome_default_for_user
extensions.settings
app\image_pre_reader_win.cc
Check failed: pe_image.VerifyMagic().
reinterpret_cast<const uint8*>(section 1) <= &headers[0] headers.size()
section == pe_image.GetImageSectionFromAddr(start length - 1)
section == pe_image.GetImageSectionFromAddr(start)
ERROR_REPORT
logging.cc
string_util.cc
Check failed: IsWprintfFormatPortable(format).
C:\quickrr\chromium\src\base/string_util_win.h
Check failed: rootkey && subkey && access && disposition.
win\registry.cc
Check failed: rootkey && subkey && access.
Check failed: key_.
Check failed: !subkey.
utf_string_conversions.cc
Check failed: other.IsValid().
version.cc
command_line.cc
user.js
file_path.cc
Check failed: data_.get().
file_version_info_win.cc
string_split.cc
Adebug\trace_event_impl.cc
at_exit.cc
time_win.cc
Check failed: it != outbuf.begin().
string_number_conversions.cc
Check failed: path.empty().
key >= base::DIR_CURRENT
path_service.cc
win\windows_version.cc
version_number_.minor == 2
win\scoped_handle.cc
values.cc
Check failed: (current_entry == dictionary_.end()) || current_entry->second.
Check failed: IsStringUTF8(key).
ins_res.first->second != in_value
json\json_file_value_serializer.cc
win\i18n.cc
kernel32.dll not found.
debug\trace_event_win.cc
callback_internal.cc
threading\thread_local_win.cc
0123456789
C:\quickrr\chromium\src\base/win/scoped_co_mem.h
json\json_writer.cc
win\scoped_process_information.cc
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
json\json_reader.cc
.syzygy
.thunks
Check failed: image.VerifyMagic().
debug\profiler.cc
tracked_objects.cc
\uX
json\json_parser.cc
Line: %i, column: %i, %s
CHROME_PROFILER_TIME
Check failed: !TlsGetValue(g_native_tls_key).
Check failed: value != TLS_OUT_OF_INDEXES.
threading\thread_local_storage_win.cc
kernel32.dll
win\src\sandbox_utils.cc
win\src\win_utils.cc
Check failed: !path.empty().
win\src\broker_services.cc
win\src\sharedmem_ipc_client.cc
Check failed: name.second.
win\src\handle_closer_agent.cc
win\src\restricted_token_utils.cc
win\src\sandbox_policy_base.cc
Check failed: !appcontainer_list_.get().
win\src\app_container.cc
Check failed: attributes_.empty().
Check failed: !capabilities_.AppContainerSid.
win\src\handle_closer.cc
win\src\restricted_token.cc
win\src\sid.cc
win\src\sharedmem_ipc_server.cc
win\src\interception.cc
win\src\window.cc
NtOpenKey
NtCreateKey
win\src\registry_policy.cc
win\src\sync_policy.cc
win\src\filesystem_policy.cc
win\src\crosscall_server.cc
NtOpenKeyEx
win\src\process_thread_dispatcher.cc
CreateNamedPipeW
win\src\acl.cc
win\src\service_resolver.cc
win\src\Wow64.cc
AutoSelectCertificateForUrls
CloudPrintProxyEnabled
CloudPrintSubmitEnabled
CookiesAllowedForUrls
CookiesBlockedForUrls
CookiesSessionOnlyForUrls
DefaultSearchProviderAlternateURLs
DefaultSearchProviderIconURL
DefaultSearchProviderInstantURL
DefaultSearchProviderKeyword
DefaultSearchProviderSearchURL
DefaultSearchProviderSuggestURL
EnableAuthNegotiatePort
EnableOriginBoundCerts
EnterpriseWebStoreName
EnterpriseWebStoreURL
HideWebStorePromo
ImagesAllowedForUrls
ImagesBlockedForUrls
ImportBookmarks
ImportHistory
ImportHomepage
ImportSavedPasswords
ImportSearchEngine
JavaScriptAllowedForUrls
JavaScriptBlockedForUrls
MetricsReportingEnabled
NotificationsAllowedForUrls
NotificationsBlockedForUrls
PasswordManagerAllowShowPasswords
PasswordManagerEnabled
PluginsAllowedForUrls
PluginsBlockedForUrls
PopupsAllowedForUrls
PopupsBlockedForUrls
ProxyBypassList
ProxyPacUrl
RemoteAccessHostDomain
RemoteAccessHostFirewallTraversal
RemoteAccessHostRequireCurtain
RemoteAccessHostRequireTwoFactor
RemoteAccessHostTalkGadgetPrefix
RestoreOnStartupURLs
URLBlacklist
URLWhitelist
ChromeFrameContentTypes
ChromeFrameRendererSettings
ChromeOsLockOnIdleSuspend
ChromeOsReleaseChannel
ChromeOsReleaseChannelDelegated
DeviceLoginScreenSaverId
DeviceLoginScreenSaverTimeout
DeviceMetricsReportingEnabled
DeviceStartUpUrls
RenderInChromeFrameList
ReportDeviceActivityTimes
ReportDeviceBootMode
ReportDeviceLocation
ReportDeviceVersionInfo
full-memory-crash-report
https
0123456789:
?456789:;<=
!"#$%&'()* ,-./0123
windows-936
windows-950
windows-949
windows-932
windows-874
windows-1254
windows-1251
windows-1256
windows-1255
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
windows-%d
!$*);^-/
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones
ucol_nextSortKeyPart
ucol_getSortKey
Returns %d.
Returns. Status = %d.
Returns %d. Status = %d.
Returns %d. Status = %p.
keyMap
keyTypeData
Keys
>CHROME_PRE_READ_EXPERIMENT
CHROME_HEADLESS
CHROME_LOG_FILE
CHROMEOS_SESSION_LOG_DIR
CHROME_CRASHED
CHROME_RESTART
allow-http-background-page
app-notify-channel-server-url
apps-checkout-url
apps-gallery-download-url
apps-gallery-url
apps-gallery-update-url
chrome-frame-shutdown-delay
chrome-version
device-management-url
disable-extensions-http-throttling
disable-sync-passwords
disable-sync-typed-urls
disable-web-resources
disable-website-settings
enable-auth-negotiate-port
enable-autologin
enable-crxless-web-apps
enable-http-pipelining
enable-metrics-reporting-for-testing
enable-npn-http
enable-password-generation
enable-websocket-over-spdy
explicitly-allowed-ports
google-search-domain-check-url
import
import-from-file
install-from-webstore
instant-url
nacl-loader-cmd-prefix
pack-extension-key
promo-server-url
proxy-bypass-list
proxy-pac-url
safebrowsing-url-prefix
sync-invalidate-xmpp-login
sync-keystore-encryption
sync-notification-host-port
sync-url
sync-try-ssltcp-first-for-xmpp
try-chrome-again
ignore-certificate-errors
variations-server-url
visit-urls
thumbnail-urls
web-intents-native-services-enabled
winhttp-proxy-resolver
plugins-metadata-server-url
profile.exited_cleanly
profile.exit_type
session.restore_on_startup
session.urls_to_restore_on_startup
session.restore_on_startup_migrated
intl.app_locale
intl.charset_default
intl.accept_languages
intl.static_encodings
intl.global.charset_default
webkit.webprefs.global.default_font_size
webkit.webprefs.global.default_fixed_font_size
webkit.webprefs.global.minimum_font_size
webkit.webprefs.global.minimum_logical_font_size
webkit.webprefs.global.javascript_can_open_windows_automatically
webkit.webprefs.global.javascript_enabled
webkit.webprefs.global.loads_images_automatically
webkit.webprefs.global.plugins_enabled
webkit.webprefs.global.standard_font_family
webkit.webprefs.global.fixed_font_family
webkit.webprefs.global.serif_font_family
webkit.webprefs.global.sansserif_font_family
webkit.webprefs.global.cursive_font_family
webkit.webprefs.global.fantasy_font_family
webkit.webprefs.standard_font_family
webkit.webprefs.fixed_font_family
webkit.webprefs.serif_font_family
webkit.webprefs.sansserif_font_family
webkit.webprefs.cursive_font_family
webkit.webprefs.fantasy_font_family
webkit.webprefs.fonts.standard
webkit.webprefs.fonts.fixed
webkit.webprefs.fonts.serif
webkit.webprefs.fonts.sansserif
webkit.webprefs.fonts.cursive
webkit.webprefs.fonts.fantasy
webkit.webprefs.fonts.pictograph
webkit.webprefs.fonts.standard.Arab
webkit.webprefs.fonts.fixed.Arab
webkit.webprefs.fonts.serif.Arab
webkit.webprefs.fonts.sansserif.Arab
webkit.webprefs.fonts.standard.Cyrl
webkit.webprefs.fonts.fixed.Cyrl
webkit.webprefs.fonts.serif.Cyrl
webkit.webprefs.fonts.sansserif.Cyrl
webkit.webprefs.fonts.standard.Grek
webkit.webprefs.fonts.fixed.Grek
webkit.webprefs.fonts.serif.Grek
webkit.webprefs.fonts.sansserif.Grek
webkit.webprefs.fonts.standard.Jpan
webkit.webprefs.fonts.fixed.Jpan
webkit.webprefs.fonts.serif.Jpan
webkit.webprefs.fonts.sansserif.Jpan
webkit.webprefs.fonts.standard.Hang
webkit.webprefs.fonts.fixed.Hang
webkit.webprefs.fonts.serif.Hang
webkit.webprefs.fonts.sansserif.Hang
webkit.webprefs.fonts.cursive.Hang
webkit.webprefs.fonts.standard.Hans
webkit.webprefs.fonts.fixed.Hans
webkit.webprefs.fonts.serif.Hans
webkit.webprefs.fonts.sansserif.Hans
webkit.webprefs.fonts.standard.Hant
webkit.webprefs.fonts.fixed.Hant
webkit.webprefs.fonts.serif.Hant
webkit.webprefs.fonts.sansserif.Hant
webkit.webprefs.web_security_enabled
webkit.webprefs.dom_paste_enabled
webkit.webprefs.shrinks_standalone_images_to_fit
webkit.webprefs.inspector_settings
webkit.webprefs.uses_universal_detector
webkit.webprefs.text_areas_are_resizable
webkit.webprefs.java_enabled
webkit.webprefs.tabs_to_links
webkit.webprefs.allow_displaying_insecure_content
webkit.webprefs.allow_running_insecure_content
webkit.webprefs.fonts.standard.Zyyy
webkit.webprefs.fonts.fixed.Zyyy
webkit.webprefs.fonts.serif.Zyyy
webkit.webprefs.fonts.sansserif.Zyyy
webkit.webprefs.fonts.cursive.Zyyy
webkit.webprefs.fonts.fantasy.Zyyy
webkit.webprefs.fonts.pictograph.Zyyy
webkit.webprefs.default_font_size
webkit.webprefs.default_fixed_font_size
webkit.webprefs.minimum_font_size
webkit.webprefs.minimum_logical_font_size
webkit.webprefs.javascript_enabled
webkit.webprefs.javascript_can_open_windows_automatically
webkit.webprefs.loads_images_automatically
webkit.webprefs.plugins_enabled
bookmark_bar.show_on_all_tabs
bookmark_editor.expanded_nodes
profile.password_manager_enabled
profile.password_manager_allow_show_passwords
password_generation.enabled
autologin.enabled
reverse_autologin.enabled
reverse_autologin.rejected_email_list
safebrowsing.enabled
safebrowsing.reporting_enabled
safebrowsing.proceed_anyway_disabled
incognito.mode_availability
search.suggest_enabled
browser.confirm_to_quit
security.cookie_behavior
default_search_provider.synced_guid
default_search_provider.enabled
default_search_provider.search_url
default_search_provider.suggest_url
default_search_provider.instant_url
default_search_provider.icon_url
default_search_provider.encodings
default_search_provider.name
default_search_provider.keyword
default_search_provider.id
default_search_provider.prepopulate_id
default_search_provider.alternate_urls
download.prompt_for_download
alternate_error_pages.enabled
dns_prefetching.startup_list
dns_prefetching.host_referral_list
spdy.disabled
net.http_server_properties
spdy.servers
spdy.alternate_protocol
protocol.disabled_schemes
policy.url_blacklist
policy.url_whitelist
instant.animation_scale_factor
instant.confirm_dialog_shown
instant.enabled
instant.experimental_zero_suggest_url_prefix
instant.show_search_provider_logo
instant.show_white_ntp
local_state.multiple_profile_prefs_version
dns_prefetching.enabled
browser.show_home_button
profile.recently_selected_encodings
browser.clear_data.browsing_history
browser.clear_data.download_history
browser.clear_data.cache
browser.clear_data.cookies
browser.clear_data.passwords
browser.clear_data.form_data
browser.clear_data.hosted_apps_data
browser.clear_data.content_licenses
browser.clear_data.time_period
browser.enable_spellchecking
browser.enabled_labs_experiments
browser.enable_autospellcorrect
browser.speechinput_censor_results
browser.speechinput_tray_notification_shown_contexts
history.saving_disabled
extensions.theme.pack
extensions.theme.id
extensions.theme.images
extensions.theme.colors
extensions.theme.tints
extensions.theme.properties
extensions.ui.developer_mode
extensions.toolbarsize
extensions.commands
plugins.last_internal_directory
plugins.plugins_list
plugins.plugins_disabled
plugins.plugins_disabled_exceptions
plugins.plugins_enabled
plugins.enabled_internal_pdf3
plugins.enabled_nacl
plugins.migrated_to_pepper_flash
plugins.show_details
plugins.allow_outdated
plugins.always_authorize
plugins.metadata
plugins.resource_cache_update
browser.check_default_browser
browser.suppress_switch_to_metro_mode_on_set_default
browser.default_browser_setting_enabled
browser.custom_chrome_frame
browser.show_omnibox_search_hint
profile.notifications_default_content_setting
profile.notification_allowed_sites
profile.notification_denied_sites
browser.desktop_notification_position
profile.default_content_settings
profile.content_settings.clear_on_exit_migrated
profile.content_settings.pref_version
profile.content_settings.patterns
profile.content_settings.pattern_pairs
profile.content_settings.whitelist_version
profile.content_settings.plugin_whitelist
profile.block_third_party_cookies
profile.clear_site_data_on_exit
profile.default_zoom_level
profile.per_host_zoom_levels
autofill.enabled
autofill.auxiliary_profiles_enabled
autofill.positive_upload_rate
autofill.negative_upload_rate
autofill.pdm.first_run
bookmarks.editing_enabled
translate.enabled
geolocation.default_content_setting
geolocation.content_settings
import_saved_passwords
webstore.enterprise_store_url
webstore.enterprise_store_name
profile.avatar_index
profile.name
printing.enabled
printing.print_preview_disabled
profile.last_used
profile.last_active_profiles
profile.profiles_created
profile.created_by_version
profile.info_cache
ssl.rev_checking.enabled
ssl.version_min
ssl.version_max
ssl.cipher_suites.blacklist
ssl.origin_bound_certs.enabled
ssl.ssl_record_splitting.disabled
user_experience_metrics.client_id
user_experience_metrics.session_id
user_experience_metrics.low_entropy_source
user_experience_metrics.client_id_timestamp
user_experience_metrics.reporting_enabled
user_experience_metrics.initial_logs
user_experience_metrics.initial_logs_as_protobufs
user_experience_metrics.ongoing_logs
user_experience_metrics.ongoing_logs_as_protobufs
user_experience_metrics.profiles
user_experience_metrics.stability.exited_cleanly
user_experience_metrics.stability.stats_version
user_experience_metrics.stability.stats_buildtime
user_experience_metrics.stability.session_end_completed
user_experience_metrics.stability.launch_count
user_experience_metrics.stability.crash_count
user_experience_metrics.stability.incomplete_session_end_count
user_experience_metrics.stability.page_load_count
user_experience_metrics.stability.renderer_crash_count
user_experience_metrics.stability.launch_time_sec
user_experience_metrics.stability.extension_renderer_crash_count
user_experience_metrics.stability.last_timestamp_sec
user_experience_metrics.stability.plugin_stats2
user_experience_metrics.stability.renderer_hang_count
user_experience_metrics.stability.child_process_crash_count
user_experience_metrics.stability.other_user_crash_count
user_experience_metrics.stability.kernel_crash_count
user_experience_metrics.stability.system_unclean_shutdowns
user_experience_metrics.stability.breakpad_registration_ok
user_experience_metrics.stability.breakpad_registration_fail
user_experience_metrics.stability.debugger_present
user_experience_metrics.stability.debugger_not_present
uninstall_metrics.page_load_count
uninstall_metrics.launch_count
uninstall_metrics.installation_date2
uninstall_metrics.uptime_sec
uninstall_metrics.last_launch_time_sec
uninstall_metrics.last_observed_running_time_sec
browser.window_placement
task_manager.window_placement
keyword_editor.window_placement
preferences.window_placement
renderer.memory_cache.size
download.default_directory
download.directory_upgrade
savefile.default_directory
savefile.type
selectfile.last_directory
select_file_dialogs.allowed
filebrowser.tasks.default_by_mime_type
filebrowser.tasks.default_by_suffix
download.extensions_to_open
browser.hung_plugin_detect_freq
browser.plugin_message_response_timeout
spellcheck.dictionary
spellcheck.confirm_dialog_shown
spellcheck.use_spelling_service
protocol_handler.excluded_schemes
safe_browsing.client_key
safe_browsing.wrapped_key
options_window.last_tab_index
content_settings_window.last_tab_index
certificate_manager_window.last_tab_index
browser.last_known_google_url
browser.last_prompted_google_url
browser.last_redirect_origin
shutdown.type
shutdown.num_processes
shutdown.num_processes_slow
restart.last.session.on.shutdown
was.restarted
restart.switch_mode
user_experience_metrics.num_bookmarks_on_bookmark_bar
user_experience_metrics.num_folders_on_bookmark_bar
user_experience_metrics.num_bookmarks_in_other_bookmark_folder
user_experience_metrics.num_folders_in_other_bookmark_folder
user_experience_metrics.num_keywords
extensions.disabled
plugins.disable_plugin_finder
extensions.browseractions.container.width
extensions.allowed_install_sites
extensions.install.allowlist
extensions.install.denylist
extensions.alerts.initialized
extensions.install.forcelist
extensions.autoupdate.last_check
extensions.autoupdate.next_check
extensions.blacklistupdate.version
ntp.collapsed_foreign_sessions
ntp.most_visited_blacklist
ntp.promo_resource_cache_update
ntp.tips_resource_server
ntp.date_resource_server
ntp.shown_bookmarks_folder
ntp.shown_page
ntp.promo_desktop_session_found
ntp.webstore_enabled
ntp.app_page_names
ntp.game_page_names
devtools.disabled
devtools.dock_side
devtools.edited_files
devtools.split_location
devtools.open_docked
sync.last_synced_time
sync.has_setup_completed
sync.keep_everything_synced
sync.bookmarks
sync.passwords
sync.preferences
sync.app_notifications
sync.app_settings
sync.apps
sync.autofill
sync.autofill_profile
sync.themes
sync.typed_urls
sync.extensions
sync.extension_settings
sync.search_engines
sync.sessions
sync.managed
sync.suppress_start
sync.acknowledged_types
sync.max_invalidation_versions
sync.session_sync_guid
invalidator.invalidation_state
invalidator.max_invalidation_versions
sync.encryption_bootstrap_token
sync.keystore_encryption_bootstrap_token
sync.using_secondary_passphrase
google.services.username
google.services.username_pattern
sync_promo.startup_count
sync_promo.view_count
sync_promo.user_skipped
sync_promo.show_on_first_run_allowed
sync_promo.show_ntp_bubble
profile.gaia_info_update_time
profile.gaia_info_picture_url
browser.web_app.create_on_desktop
browser.web_app.create_in_apps_menu
browser.web_app.create_in_quick_launch_bar
geolocation.access_token
remote_access.host_firewall_traversal
remote_access.host_require_two_factor
remote_access.host_domain
remote_access.host_talkgadget_prefix
remote_access.host_require_curtain
printing.print_preview_sticky_settings
cloud_print.service_url
cloud_print.signin_url
cloud_print.dialog_size.width
cloud_print.dialog_size.height
cloud_print.signin_dialog_size.width
cloud_print.signin_dialog_size.height
chrome_to_mobile.device_list
background_contents.registered
browser.shown_autolaunch_infobar
auth.schemes
auth.disable_negotiate_cname_lookup
auth.enable_negotiate_port
auth.server_whitelist
auth.negotiate_delegate_whitelist
auth.gssapi_library_name
auth.spdyproxy.origin
auth.allow_cross_origin_prompt
browser.clear_lso_data_enabled
browser.pepper_flash_settings_enabled
browser.disk_cache_dir
browser.disk_cache_size
browser.media_cache_size
cros.system.releaseChannel
policy.load_cloud_policy_on_signin
cloud_print.enabled
cloud_print.proxy_id
cloud_print.auth_token
cloud_print.xmpp_auth_token
cloud_print.email
cloud_print.print_system_settings
cloud_print.enable_job_poll
cloud_print.robot_refresh_token
cloud_print.robot_email
cloud_print.connect_new_printers
cloud_print.printer_blacklist
cloud_print.submit_enabled
net.max_connections_per_proxy
profile.managed_default_content_settings.cookies
profile.managed_default_content_settings.images
profile.managed_default_content_settings.javascript
profile.managed_default_content_settings.plugins
profile.managed_default_content_settings.popups
profile.managed_default_content_settings.geolocation
profile.managed_default_content_settings.notifications
profile.managed_default_content_settings.media_stream
profile.managed_cookies_allowed_for_urls
profile.managed_cookies_blocked_for_urls
profile.managed_cookies_sessiononly_for_urls
profile.managed_images_allowed_for_urls
profile.managed_images_blocked_for_urls
profile.managed_javascript_allowed_for_urls
profile.managed_javascript_blocked_for_urls
profile.managed_plugins_allowed_for_urls
profile.managed_plugins_blocked_for_urls
profile.managed_popups_allowed_for_urls
profile.managed_popups_blocked_for_urls
profile.managed_notifications_allowed_for_urls
profile.managed_notifications_blocked_for_urls
profile.managed_auto_select_certificate_for_urls
background_mode.user_created_login_item
background_mode.user_removed_login_item
background_mode.enabled
custom_handlers.registered_protocol_handlers
custom_handlers.ignored_protocol_handlers
custom_handlers.enabled
policy.device_refresh_rate
policy.user_refresh_rate
recovery_component.version
component_updater.state
webintents.enabled
media_galleries.gallery_id
media_galleries.remembered_galleries
network_profile.warnings_left
network_profile.last_warning_time
policy.last_statistics_update
chrome.googleechotest.com
hXXp://pipelining.googleechotest.com/
allow-webui-compositing
disable-webgl
blacklist-webgl
disable-image-transport-surface
speech-service-key
disable-webaudio
disable-web-security
disable-web-sockets
enable-experimental-webkit-features
disable-web-media-player-ms
enable-privileged-webgl-extensions
enable-tcp-fastopen
enable-viewport
in-process-webgl
remote-debugging-port
renderer-cmd-prefix
testing-fixed-http-port
testing-fixed-https-port
utility-cmd-prefix
webcore-log-channels
zygote-cmd-prefix
Visual C CRT: Not enough memory to complete call to strerror.
?#%X.y
Broken pipe
Inappropriate I/O control operation
Operation not permitted
portuguese-brazilian
GetProcessWindowStation
operator
SHELL32.dll
ole32.dll
C:\quickrr\chromium\src\build\Release\chrome_exe.pdb
ShellExecuteW
SHLWAPI.dll
KERNEL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WINMM.dll
GetWindowsDirectoryW
CreateIoCompletionPort
WaitNamedPipeW
TransactNamedPipe
SetNamedPipeHandleState
GetProcessHandleCount
GetProcessHeap
GetCPInfo
CloseWindowStation
CreateWindowStationW
SetProcessWindowStation
RegQueryInfoKeyW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
PlayFreeBrowser.exe
SetActiveURL
zcÁ
bd.tvt
]"kL:%s!
C$Ö
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD0T1;2c2?3d3
8 8*8>8~8
<$<9<[<{<3 3$3(3<7
6,7074787<7
:':-:5:=:
8$8(8,8084888<8@8
9(9/94989<9]9
9&:,:0:4:8:
8.9;9[9':>:
8&9.969>9~9
3(7,7074787
> >$>8><>
? ?$?(?,?0?4?
5 5$5(5,50545
?$?,?4?<?
\\.\pipe\GoogleCrashServices\
\\.\pipe\ChromeCrashServices
error %u
hurl-chunk-%i
prn-info-%d
0.0.0.0-devel
Chrome
ChromeFrame
Software\Google\ChromeFrame
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}ChromeCanary
registering_chrome
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser
hXXp://VVV.playfree.org/en/uninstall.html?utm_source=[%ORIGIN%]_[%SOURCE_SITE%]&utm_medium=uninstall
%d.%d.%d
ed-d-d
hXXp://update.playfree.org/browser/updatechecker/?
{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}{00337EA4-7B9A-44a6-B45B-B1722CD4343E}MPCBrowserUpdate.exe
CFEndTempOptOutCmd
CFOptInCmd
CFOptOutCmd
CFTempOptOutCmd
UninstallCmdLine
WebAccessible
app_host.exe
PlayFreeBrowser.dll
npchrome_frame.dll
chrome_frame_helper.exe
ChromeFrameHelperWindowClass
ChromeFrameReadyMode
chrome_launcher.exe
new_chrome.exe
old_chrome.exe
delegate_execute.exe
nacl64.exe
setup.exe
InstallerSuccessLaunchCmdLine
-chrome
-chromeframe
{5C65F4B0-3651-4514-B207-D10CB699B14B}hXXps://clients4.google.com/firefox/metrics/collect
{8BA986DA-5100-405E-AA35-86F34A02ACBF}Google Chrome Frame
Google\Chrome Frame
Chrome in a Frame.
Uninstall Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}Google Chrome App Host
A standalone platform for Chrome apps.
.Uninstall Chrome App Host
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome App Host
debug_message.exe
debug.log
.\debug.log
Software\Microsoft\Windows\CurrentVersion\Run
\StringFileInfo\xx\%ls
ckernel32.dll
psapi.dll
Chrome_MessagePumpWindow
%s\%s.dmp
rpcrt4.dll
dbghelp.dll
x-x-x-xx-xxxxxx
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_NLSTEXT
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
pipe\
ALPC Port
cntdll.dll
s0x%X
wow_helper.exe"
00000000
333333333333333333
333333333336
%%CollationBin
NPlayFreeBrowser.exe
metro_driver.dll
Chrome_StatusTrayWindow
Chrome_MessageWindow
Reported Crashes.txt
testing_interface.dll
Certificate Revocation Lists
Custom Dictionary.txt
Login Data
Origin Bound Certs
Cached Theme.pak
Web Applications
Web Data
pepflashplayer.dll
CHROME_METRO_NAV_SEARCH_REQUEST
CHROME_METRO_GET_CURRENT_TAB_INFO
mscoree.dll
ADVAPI32.DLL
nKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe
3.0.0.4
chrome_exe
PlayFreeBrowser.exe_3528_rwx_36B0A000_00060000:
j.hmO
PlayFreeBrowser.exe_3540:
.text
`.rdata
@.data
.rsrc
@.reloc
QPWSSh
>%u]2
Ht.Ht
tE<.tA<@t=
u.WSh
<.tW<@tS
xSSSh
FTPjKS
FtPj;S
C.PjRV
CHROME_METRO_DLL
app\hard_error_handler_win.cc
ntdll.dll
CHROME_BREAKPAD_PIPE_NAME
1.3.21.115
app\breakpad_win.cc
Check failed: index < kMaxReportedActiveExtensions.
Check failed: url_cstring.
info.size() <= kMaxReportedPrinterRecords
Could not find exported function
app\client_util.cc
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Failed to load Chrome DLL from
Could not get Chrome DLL version.
ChromeMain
installer\util\google_update_settings.cc
Removed multi-install failure key; switching to channel:
Removed incremental installer failure key; switching to channel:
Failed to write to application's ClientState key
installer\util\install_util.cc
C:\quickrr\chromium\src\base/win/scoped_handle.h
installer\util\browser_distribution.cc
C:\quickrr\chromium\src\base/string_util.h
Check failed: length == static_cast<int>(language.length() 1).
CHROME_BINARIES == type
auto-launch-chrome
chrome
chrome-frame
chrome-sxs
do-not-launch-chrome
make-chrome-default
new-setup-exe
register-chrome-browser
register-chrome-browser-suffix
register-url-protocol
rename-chrome-exe
remove-chrome-registration
update-setup-exe
toast-results-key
Check failed: key.
installer\util\channel_info.cc
installer\util\l10n_string_util.cc
installer\util\app_commands.cc
Skipping over key "
Failed to open key "
Cannot initialize AppCommands from an invalid key.
googlechromeframe
installer\util\chrome_app_host_distribution.cc
This should never be accessed as Chrome App Host is not a
This should never be accessed as Chrome App Host has no
googlechromeapphost
installer\util\chromium_binaries_distribution.cc
installer\util\master_preferences.cc
Check failed: master_dictionary_.get().
: Bad boy, the buffer passed to placement new is not aligned!
C:\quickrr\chromium\src\base/lazy_instance.h
installer\util\language_selector.cc
Cannot initialize an AppCommand from an invalid key.
installer\util\app_command.cc
auto_launch_chrome
chrome_frame
chrome_shortcut_icon_index
import_bookmarks
import_bookmarks_from_file
import_history
import_home_page
import_search_engine
do_not_launch_chrome
make_chrome_default
make_chrome_default_for_user
extensions.settings
app\image_pre_reader_win.cc
Check failed: pe_image.VerifyMagic().
reinterpret_cast<const uint8*>(section 1) <= &headers[0] headers.size()
section == pe_image.GetImageSectionFromAddr(start length - 1)
section == pe_image.GetImageSectionFromAddr(start)
ERROR_REPORT
logging.cc
string_util.cc
Check failed: IsWprintfFormatPortable(format).
C:\quickrr\chromium\src\base/string_util_win.h
Check failed: rootkey && subkey && access && disposition.
win\registry.cc
Check failed: rootkey && subkey && access.
Check failed: key_.
Check failed: !subkey.
utf_string_conversions.cc
Check failed: other.IsValid().
version.cc
command_line.cc
user.js
file_path.cc
Check failed: data_.get().
file_version_info_win.cc
string_split.cc
Adebug\trace_event_impl.cc
at_exit.cc
time_win.cc
Check failed: it != outbuf.begin().
string_number_conversions.cc
Check failed: path.empty().
key >= base::DIR_CURRENT
path_service.cc
win\windows_version.cc
version_number_.minor == 2
win\scoped_handle.cc
values.cc
Check failed: (current_entry == dictionary_.end()) || current_entry->second.
Check failed: IsStringUTF8(key).
ins_res.first->second != in_value
json\json_file_value_serializer.cc
win\i18n.cc
kernel32.dll not found.
debug\trace_event_win.cc
callback_internal.cc
threading\thread_local_win.cc
0123456789
C:\quickrr\chromium\src\base/win/scoped_co_mem.h
json\json_writer.cc
win\scoped_process_information.cc
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
json\json_reader.cc
.syzygy
.thunks
Check failed: image.VerifyMagic().
debug\profiler.cc
tracked_objects.cc
\uX
json\json_parser.cc
Line: %i, column: %i, %s
CHROME_PROFILER_TIME
Check failed: !TlsGetValue(g_native_tls_key).
Check failed: value != TLS_OUT_OF_INDEXES.
threading\thread_local_storage_win.cc
kernel32.dll
win\src\sandbox_utils.cc
win\src\win_utils.cc
Check failed: !path.empty().
win\src\broker_services.cc
win\src\sharedmem_ipc_client.cc
Check failed: name.second.
win\src\handle_closer_agent.cc
win\src\restricted_token_utils.cc
win\src\sandbox_policy_base.cc
Check failed: !appcontainer_list_.get().
win\src\app_container.cc
Check failed: attributes_.empty().
Check failed: !capabilities_.AppContainerSid.
win\src\handle_closer.cc
win\src\restricted_token.cc
win\src\sid.cc
win\src\sharedmem_ipc_server.cc
win\src\interception.cc
win\src\window.cc
NtOpenKey
NtCreateKey
win\src\registry_policy.cc
win\src\sync_policy.cc
win\src\filesystem_policy.cc
win\src\crosscall_server.cc
NtOpenKeyEx
win\src\process_thread_dispatcher.cc
CreateNamedPipeW
win\src\acl.cc
win\src\service_resolver.cc
win\src\Wow64.cc
AutoSelectCertificateForUrls
CloudPrintProxyEnabled
CloudPrintSubmitEnabled
CookiesAllowedForUrls
CookiesBlockedForUrls
CookiesSessionOnlyForUrls
DefaultSearchProviderAlternateURLs
DefaultSearchProviderIconURL
DefaultSearchProviderInstantURL
DefaultSearchProviderKeyword
DefaultSearchProviderSearchURL
DefaultSearchProviderSuggestURL
EnableAuthNegotiatePort
EnableOriginBoundCerts
EnterpriseWebStoreName
EnterpriseWebStoreURL
HideWebStorePromo
ImagesAllowedForUrls
ImagesBlockedForUrls
ImportBookmarks
ImportHistory
ImportHomepage
ImportSavedPasswords
ImportSearchEngine
JavaScriptAllowedForUrls
JavaScriptBlockedForUrls
MetricsReportingEnabled
NotificationsAllowedForUrls
NotificationsBlockedForUrls
PasswordManagerAllowShowPasswords
PasswordManagerEnabled
PluginsAllowedForUrls
PluginsBlockedForUrls
PopupsAllowedForUrls
PopupsBlockedForUrls
ProxyBypassList
ProxyPacUrl
RemoteAccessHostDomain
RemoteAccessHostFirewallTraversal
RemoteAccessHostRequireCurtain
RemoteAccessHostRequireTwoFactor
RemoteAccessHostTalkGadgetPrefix
RestoreOnStartupURLs
URLBlacklist
URLWhitelist
ChromeFrameContentTypes
ChromeFrameRendererSettings
ChromeOsLockOnIdleSuspend
ChromeOsReleaseChannel
ChromeOsReleaseChannelDelegated
DeviceLoginScreenSaverId
DeviceLoginScreenSaverTimeout
DeviceMetricsReportingEnabled
DeviceStartUpUrls
RenderInChromeFrameList
ReportDeviceActivityTimes
ReportDeviceBootMode
ReportDeviceLocation
ReportDeviceVersionInfo
full-memory-crash-report
https
0123456789:
?456789:;<=
!"#$%&'()* ,-./0123
windows-936
windows-950
windows-949
windows-932
windows-874
windows-1254
windows-1251
windows-1256
windows-1255
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
windows-%d
!$*);^-/
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones
ucol_nextSortKeyPart
ucol_getSortKey
Returns %d.
Returns. Status = %d.
Returns %d. Status = %d.
Returns %d. Status = %p.
keyMap
keyTypeData
Keys
>CHROME_PRE_READ_EXPERIMENT
CHROME_HEADLESS
CHROME_LOG_FILE
CHROMEOS_SESSION_LOG_DIR
CHROME_CRASHED
CHROME_RESTART
allow-http-background-page
app-notify-channel-server-url
apps-checkout-url
apps-gallery-download-url
apps-gallery-url
apps-gallery-update-url
chrome-frame-shutdown-delay
chrome-version
device-management-url
disable-extensions-http-throttling
disable-sync-passwords
disable-sync-typed-urls
disable-web-resources
disable-website-settings
enable-auth-negotiate-port
enable-autologin
enable-crxless-web-apps
enable-http-pipelining
enable-metrics-reporting-for-testing
enable-npn-http
enable-password-generation
enable-websocket-over-spdy
explicitly-allowed-ports
google-search-domain-check-url
import
import-from-file
install-from-webstore
instant-url
nacl-loader-cmd-prefix
pack-extension-key
promo-server-url
proxy-bypass-list
proxy-pac-url
safebrowsing-url-prefix
sync-invalidate-xmpp-login
sync-keystore-encryption
sync-notification-host-port
sync-url
sync-try-ssltcp-first-for-xmpp
try-chrome-again
ignore-certificate-errors
variations-server-url
visit-urls
thumbnail-urls
web-intents-native-services-enabled
winhttp-proxy-resolver
plugins-metadata-server-url
profile.exited_cleanly
profile.exit_type
session.restore_on_startup
session.urls_to_restore_on_startup
session.restore_on_startup_migrated
intl.app_locale
intl.charset_default
intl.accept_languages
intl.static_encodings
intl.global.charset_default
webkit.webprefs.global.default_font_size
webkit.webprefs.global.default_fixed_font_size
webkit.webprefs.global.minimum_font_size
webkit.webprefs.global.minimum_logical_font_size
webkit.webprefs.global.javascript_can_open_windows_automatically
webkit.webprefs.global.javascript_enabled
webkit.webprefs.global.loads_images_automatically
webkit.webprefs.global.plugins_enabled
webkit.webprefs.global.standard_font_family
webkit.webprefs.global.fixed_font_family
webkit.webprefs.global.serif_font_family
webkit.webprefs.global.sansserif_font_family
webkit.webprefs.global.cursive_font_family
webkit.webprefs.global.fantasy_font_family
webkit.webprefs.standard_font_family
webkit.webprefs.fixed_font_family
webkit.webprefs.serif_font_family
webkit.webprefs.sansserif_font_family
webkit.webprefs.cursive_font_family
webkit.webprefs.fantasy_font_family
webkit.webprefs.fonts.standard
webkit.webprefs.fonts.fixed
webkit.webprefs.fonts.serif
webkit.webprefs.fonts.sansserif
webkit.webprefs.fonts.cursive
webkit.webprefs.fonts.fantasy
webkit.webprefs.fonts.pictograph
webkit.webprefs.fonts.standard.Arab
webkit.webprefs.fonts.fixed.Arab
webkit.webprefs.fonts.serif.Arab
webkit.webprefs.fonts.sansserif.Arab
webkit.webprefs.fonts.standard.Cyrl
webkit.webprefs.fonts.fixed.Cyrl
webkit.webprefs.fonts.serif.Cyrl
webkit.webprefs.fonts.sansserif.Cyrl
webkit.webprefs.fonts.standard.Grek
webkit.webprefs.fonts.fixed.Grek
webkit.webprefs.fonts.serif.Grek
webkit.webprefs.fonts.sansserif.Grek
webkit.webprefs.fonts.standard.Jpan
webkit.webprefs.fonts.fixed.Jpan
webkit.webprefs.fonts.serif.Jpan
webkit.webprefs.fonts.sansserif.Jpan
webkit.webprefs.fonts.standard.Hang
webkit.webprefs.fonts.fixed.Hang
webkit.webprefs.fonts.serif.Hang
webkit.webprefs.fonts.sansserif.Hang
webkit.webprefs.fonts.cursive.Hang
webkit.webprefs.fonts.standard.Hans
webkit.webprefs.fonts.fixed.Hans
webkit.webprefs.fonts.serif.Hans
webkit.webprefs.fonts.sansserif.Hans
webkit.webprefs.fonts.standard.Hant
webkit.webprefs.fonts.fixed.Hant
webkit.webprefs.fonts.serif.Hant
webkit.webprefs.fonts.sansserif.Hant
webkit.webprefs.web_security_enabled
webkit.webprefs.dom_paste_enabled
webkit.webprefs.shrinks_standalone_images_to_fit
webkit.webprefs.inspector_settings
webkit.webprefs.uses_universal_detector
webkit.webprefs.text_areas_are_resizable
webkit.webprefs.java_enabled
webkit.webprefs.tabs_to_links
webkit.webprefs.allow_displaying_insecure_content
webkit.webprefs.allow_running_insecure_content
webkit.webprefs.fonts.standard.Zyyy
webkit.webprefs.fonts.fixed.Zyyy
webkit.webprefs.fonts.serif.Zyyy
webkit.webprefs.fonts.sansserif.Zyyy
webkit.webprefs.fonts.cursive.Zyyy
webkit.webprefs.fonts.fantasy.Zyyy
webkit.webprefs.fonts.pictograph.Zyyy
webkit.webprefs.default_font_size
webkit.webprefs.default_fixed_font_size
webkit.webprefs.minimum_font_size
webkit.webprefs.minimum_logical_font_size
webkit.webprefs.javascript_enabled
webkit.webprefs.javascript_can_open_windows_automatically
webkit.webprefs.loads_images_automatically
webkit.webprefs.plugins_enabled
bookmark_bar.show_on_all_tabs
bookmark_editor.expanded_nodes
profile.password_manager_enabled
profile.password_manager_allow_show_passwords
password_generation.enabled
autologin.enabled
reverse_autologin.enabled
reverse_autologin.rejected_email_list
safebrowsing.enabled
safebrowsing.reporting_enabled
safebrowsing.proceed_anyway_disabled
incognito.mode_availability
search.suggest_enabled
browser.confirm_to_quit
security.cookie_behavior
default_search_provider.synced_guid
default_search_provider.enabled
default_search_provider.search_url
default_search_provider.suggest_url
default_search_provider.instant_url
default_search_provider.icon_url
default_search_provider.encodings
default_search_provider.name
default_search_provider.keyword
default_search_provider.id
default_search_provider.prepopulate_id
default_search_provider.alternate_urls
download.prompt_for_download
alternate_error_pages.enabled
dns_prefetching.startup_list
dns_prefetching.host_referral_list
spdy.disabled
net.http_server_properties
spdy.servers
spdy.alternate_protocol
protocol.disabled_schemes
policy.url_blacklist
policy.url_whitelist
instant.animation_scale_factor
instant.confirm_dialog_shown
instant.enabled
instant.experimental_zero_suggest_url_prefix
instant.show_search_provider_logo
instant.show_white_ntp
local_state.multiple_profile_prefs_version
dns_prefetching.enabled
browser.show_home_button
profile.recently_selected_encodings
browser.clear_data.browsing_history
browser.clear_data.download_history
browser.clear_data.cache
browser.clear_data.cookies
browser.clear_data.passwords
browser.clear_data.form_data
browser.clear_data.hosted_apps_data
browser.clear_data.content_licenses
browser.clear_data.time_period
browser.enable_spellchecking
browser.enabled_labs_experiments
browser.enable_autospellcorrect
browser.speechinput_censor_results
browser.speechinput_tray_notification_shown_contexts
history.saving_disabled
extensions.theme.pack
extensions.theme.id
extensions.theme.images
extensions.theme.colors
extensions.theme.tints
extensions.theme.properties
extensions.ui.developer_mode
extensions.toolbarsize
extensions.commands
plugins.last_internal_directory
plugins.plugins_list
plugins.plugins_disabled
plugins.plugins_disabled_exceptions
plugins.plugins_enabled
plugins.enabled_internal_pdf3
plugins.enabled_nacl
plugins.migrated_to_pepper_flash
plugins.show_details
plugins.allow_outdated
plugins.always_authorize
plugins.metadata
plugins.resource_cache_update
browser.check_default_browser
browser.suppress_switch_to_metro_mode_on_set_default
browser.default_browser_setting_enabled
browser.custom_chrome_frame
browser.show_omnibox_search_hint
profile.notifications_default_content_setting
profile.notification_allowed_sites
profile.notification_denied_sites
browser.desktop_notification_position
profile.default_content_settings
profile.content_settings.clear_on_exit_migrated
profile.content_settings.pref_version
profile.content_settings.patterns
profile.content_settings.pattern_pairs
profile.content_settings.whitelist_version
profile.content_settings.plugin_whitelist
profile.block_third_party_cookies
profile.clear_site_data_on_exit
profile.default_zoom_level
profile.per_host_zoom_levels
autofill.enabled
autofill.auxiliary_profiles_enabled
autofill.positive_upload_rate
autofill.negative_upload_rate
autofill.pdm.first_run
bookmarks.editing_enabled
translate.enabled
geolocation.default_content_setting
geolocation.content_settings
import_saved_passwords
webstore.enterprise_store_url
webstore.enterprise_store_name
profile.avatar_index
profile.name
printing.enabled
printing.print_preview_disabled
profile.last_used
profile.last_active_profiles
profile.profiles_created
profile.created_by_version
profile.info_cache
ssl.rev_checking.enabled
ssl.version_min
ssl.version_max
ssl.cipher_suites.blacklist
ssl.origin_bound_certs.enabled
ssl.ssl_record_splitting.disabled
user_experience_metrics.client_id
user_experience_metrics.session_id
user_experience_metrics.low_entropy_source
user_experience_metrics.client_id_timestamp
user_experience_metrics.reporting_enabled
user_experience_metrics.initial_logs
user_experience_metrics.initial_logs_as_protobufs
user_experience_metrics.ongoing_logs
user_experience_metrics.ongoing_logs_as_protobufs
user_experience_metrics.profiles
user_experience_metrics.stability.exited_cleanly
user_experience_metrics.stability.stats_version
user_experience_metrics.stability.stats_buildtime
user_experience_metrics.stability.session_end_completed
user_experience_metrics.stability.launch_count
user_experience_metrics.stability.crash_count
user_experience_metrics.stability.incomplete_session_end_count
user_experience_metrics.stability.page_load_count
user_experience_metrics.stability.renderer_crash_count
user_experience_metrics.stability.launch_time_sec
user_experience_metrics.stability.extension_renderer_crash_count
user_experience_metrics.stability.last_timestamp_sec
user_experience_metrics.stability.plugin_stats2
user_experience_metrics.stability.renderer_hang_count
user_experience_metrics.stability.child_process_crash_count
user_experience_metrics.stability.other_user_crash_count
user_experience_metrics.stability.kernel_crash_count
user_experience_metrics.stability.system_unclean_shutdowns
user_experience_metrics.stability.breakpad_registration_ok
user_experience_metrics.stability.breakpad_registration_fail
user_experience_metrics.stability.debugger_present
user_experience_metrics.stability.debugger_not_present
uninstall_metrics.page_load_count
uninstall_metrics.launch_count
uninstall_metrics.installation_date2
uninstall_metrics.uptime_sec
uninstall_metrics.last_launch_time_sec
uninstall_metrics.last_observed_running_time_sec
browser.window_placement
task_manager.window_placement
keyword_editor.window_placement
preferences.window_placement
renderer.memory_cache.size
download.default_directory
download.directory_upgrade
savefile.default_directory
savefile.type
selectfile.last_directory
select_file_dialogs.allowed
filebrowser.tasks.default_by_mime_type
filebrowser.tasks.default_by_suffix
download.extensions_to_open
browser.hung_plugin_detect_freq
browser.plugin_message_response_timeout
spellcheck.dictionary
spellcheck.confirm_dialog_shown
spellcheck.use_spelling_service
protocol_handler.excluded_schemes
safe_browsing.client_key
safe_browsing.wrapped_key
options_window.last_tab_index
content_settings_window.last_tab_index
certificate_manager_window.last_tab_index
browser.last_known_google_url
browser.last_prompted_google_url
browser.last_redirect_origin
shutdown.type
shutdown.num_processes
shutdown.num_processes_slow
restart.last.session.on.shutdown
was.restarted
restart.switch_mode
user_experience_metrics.num_bookmarks_on_bookmark_bar
user_experience_metrics.num_folders_on_bookmark_bar
user_experience_metrics.num_bookmarks_in_other_bookmark_folder
user_experience_metrics.num_folders_in_other_bookmark_folder
user_experience_metrics.num_keywords
extensions.disabled
plugins.disable_plugin_finder
extensions.browseractions.container.width
extensions.allowed_install_sites
extensions.install.allowlist
extensions.install.denylist
extensions.alerts.initialized
extensions.install.forcelist
extensions.autoupdate.last_check
extensions.autoupdate.next_check
extensions.blacklistupdate.version
ntp.collapsed_foreign_sessions
ntp.most_visited_blacklist
ntp.promo_resource_cache_update
ntp.tips_resource_server
ntp.date_resource_server
ntp.shown_bookmarks_folder
ntp.shown_page
ntp.promo_desktop_session_found
ntp.webstore_enabled
ntp.app_page_names
ntp.game_page_names
devtools.disabled
devtools.dock_side
devtools.edited_files
devtools.split_location
devtools.open_docked
sync.last_synced_time
sync.has_setup_completed
sync.keep_everything_synced
sync.bookmarks
sync.passwords
sync.preferences
sync.app_notifications
sync.app_settings
sync.apps
sync.autofill
sync.autofill_profile
sync.themes
sync.typed_urls
sync.extensions
sync.extension_settings
sync.search_engines
sync.sessions
sync.managed
sync.suppress_start
sync.acknowledged_types
sync.max_invalidation_versions
sync.session_sync_guid
invalidator.invalidation_state
invalidator.max_invalidation_versions
sync.encryption_bootstrap_token
sync.keystore_encryption_bootstrap_token
sync.using_secondary_passphrase
google.services.username
google.services.username_pattern
sync_promo.startup_count
sync_promo.view_count
sync_promo.user_skipped
sync_promo.show_on_first_run_allowed
sync_promo.show_ntp_bubble
profile.gaia_info_update_time
profile.gaia_info_picture_url
browser.web_app.create_on_desktop
browser.web_app.create_in_apps_menu
browser.web_app.create_in_quick_launch_bar
geolocation.access_token
remote_access.host_firewall_traversal
remote_access.host_require_two_factor
remote_access.host_domain
remote_access.host_talkgadget_prefix
remote_access.host_require_curtain
printing.print_preview_sticky_settings
cloud_print.service_url
cloud_print.signin_url
cloud_print.dialog_size.width
cloud_print.dialog_size.height
cloud_print.signin_dialog_size.width
cloud_print.signin_dialog_size.height
chrome_to_mobile.device_list
background_contents.registered
browser.shown_autolaunch_infobar
auth.schemes
auth.disable_negotiate_cname_lookup
auth.enable_negotiate_port
auth.server_whitelist
auth.negotiate_delegate_whitelist
auth.gssapi_library_name
auth.spdyproxy.origin
auth.allow_cross_origin_prompt
browser.clear_lso_data_enabled
browser.pepper_flash_settings_enabled
browser.disk_cache_dir
browser.disk_cache_size
browser.media_cache_size
cros.system.releaseChannel
policy.load_cloud_policy_on_signin
cloud_print.enabled
cloud_print.proxy_id
cloud_print.auth_token
cloud_print.xmpp_auth_token
cloud_print.email
cloud_print.print_system_settings
cloud_print.enable_job_poll
cloud_print.robot_refresh_token
cloud_print.robot_email
cloud_print.connect_new_printers
cloud_print.printer_blacklist
cloud_print.submit_enabled
net.max_connections_per_proxy
profile.managed_default_content_settings.cookies
profile.managed_default_content_settings.images
profile.managed_default_content_settings.javascript
profile.managed_default_content_settings.plugins
profile.managed_default_content_settings.popups
profile.managed_default_content_settings.geolocation
profile.managed_default_content_settings.notifications
profile.managed_default_content_settings.media_stream
profile.managed_cookies_allowed_for_urls
profile.managed_cookies_blocked_for_urls
profile.managed_cookies_sessiononly_for_urls
profile.managed_images_allowed_for_urls
profile.managed_images_blocked_for_urls
profile.managed_javascript_allowed_for_urls
profile.managed_javascript_blocked_for_urls
profile.managed_plugins_allowed_for_urls
profile.managed_plugins_blocked_for_urls
profile.managed_popups_allowed_for_urls
profile.managed_popups_blocked_for_urls
profile.managed_notifications_allowed_for_urls
profile.managed_notifications_blocked_for_urls
profile.managed_auto_select_certificate_for_urls
background_mode.user_created_login_item
background_mode.user_removed_login_item
background_mode.enabled
custom_handlers.registered_protocol_handlers
custom_handlers.ignored_protocol_handlers
custom_handlers.enabled
policy.device_refresh_rate
policy.user_refresh_rate
recovery_component.version
component_updater.state
webintents.enabled
media_galleries.gallery_id
media_galleries.remembered_galleries
network_profile.warnings_left
network_profile.last_warning_time
policy.last_statistics_update
chrome.googleechotest.com
hXXp://pipelining.googleechotest.com/
allow-webui-compositing
disable-webgl
blacklist-webgl
disable-image-transport-surface
speech-service-key
disable-webaudio
disable-web-security
disable-web-sockets
enable-experimental-webkit-features
disable-web-media-player-ms
enable-privileged-webgl-extensions
enable-tcp-fastopen
enable-viewport
in-process-webgl
remote-debugging-port
renderer-cmd-prefix
testing-fixed-http-port
testing-fixed-https-port
utility-cmd-prefix
webcore-log-channels
zygote-cmd-prefix
Visual C CRT: Not enough memory to complete call to strerror.
?#%X.y
Broken pipe
Inappropriate I/O control operation
Operation not permitted
portuguese-brazilian
GetProcessWindowStation
operator
SHELL32.dll
ole32.dll
C:\quickrr\chromium\src\build\Release\chrome_exe.pdb
ShellExecuteW
SHLWAPI.dll
KERNEL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WINMM.dll
GetWindowsDirectoryW
CreateIoCompletionPort
WaitNamedPipeW
TransactNamedPipe
SetNamedPipeHandleState
GetProcessHandleCount
GetProcessHeap
GetCPInfo
CloseWindowStation
CreateWindowStationW
SetProcessWindowStation
RegQueryInfoKeyW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
PlayFreeBrowser.exe
SetActiveURL
zcÁ
bd.tvt
]"kL:%s!
C$Ö
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD0T1;2c2?3d3
8 8*8>8~8
<$<9<[<{<3 3$3(3<7
6,7074787<7
:':-:5:=:
8$8(8,8084888<8@8
9(9/94989<9]9
9&:,:0:4:8:
8.9;9[9':>:
8&9.969>9~9
3(7,7074787
> >$>8><>
? ?$?(?,?0?4?
5 5$5(5,50545
?$?,?4?<?
\\.\pipe\GoogleCrashServices\
\\.\pipe\ChromeCrashServices
error %u
hurl-chunk-%i
prn-info-%d
0.0.0.0-devel
Chrome
ChromeFrame
Software\Google\ChromeFrame
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}ChromeCanary
registering_chrome
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser
hXXp://VVV.playfree.org/en/uninstall.html?utm_source=[%ORIGIN%]_[%SOURCE_SITE%]&utm_medium=uninstall
%d.%d.%d
ed-d-d
hXXp://update.playfree.org/browser/updatechecker/?
{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}{00337EA4-7B9A-44a6-B45B-B1722CD4343E}MPCBrowserUpdate.exe
CFEndTempOptOutCmd
CFOptInCmd
CFOptOutCmd
CFTempOptOutCmd
UninstallCmdLine
WebAccessible
app_host.exe
PlayFreeBrowser.dll
npchrome_frame.dll
chrome_frame_helper.exe
ChromeFrameHelperWindowClass
ChromeFrameReadyMode
chrome_launcher.exe
new_chrome.exe
old_chrome.exe
delegate_execute.exe
nacl64.exe
setup.exe
InstallerSuccessLaunchCmdLine
-chrome
-chromeframe
{5C65F4B0-3651-4514-B207-D10CB699B14B}hXXps://clients4.google.com/firefox/metrics/collect
{8BA986DA-5100-405E-AA35-86F34A02ACBF}Google Chrome Frame
Google\Chrome Frame
Chrome in a Frame.
Uninstall Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}Google Chrome App Host
A standalone platform for Chrome apps.
.Uninstall Chrome App Host
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome App Host
debug_message.exe
debug.log
.\debug.log
Software\Microsoft\Windows\CurrentVersion\Run
\StringFileInfo\xx\%ls
ckernel32.dll
psapi.dll
Chrome_MessagePumpWindow
%s\%s.dmp
rpcrt4.dll
dbghelp.dll
x-x-x-xx-xxxxxx
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_NLSTEXT
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
pipe\
ALPC Port
cntdll.dll
s0x%X
wow_helper.exe"
00000000
333333333333333333
333333333336
%%CollationBin
NPlayFreeBrowser.exe
metro_driver.dll
Chrome_StatusTrayWindow
Chrome_MessageWindow
Reported Crashes.txt
testing_interface.dll
Certificate Revocation Lists
Custom Dictionary.txt
Login Data
Origin Bound Certs
Cached Theme.pak
Web Applications
Web Data
pepflashplayer.dll
CHROME_METRO_NAV_SEARCH_REQUEST
CHROME_METRO_GET_CURRENT_TAB_INFO
mscoree.dll
ADVAPI32.DLL
nKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe
3.0.0.4
chrome_exe
PlayFreeBrowser.exe_3540_rwx_0E60A000_00060000:
j.hmO
VhQÆh
PlayFreeBrowser.exe_3592:
.text
`.rdata
@.data
.rsrc
@.reloc
QPWSSh
>%u]2
Ht.Ht
tE<.tA<@t=
u.WSh
<.tW<@tS
xSSSh
FTPjKS
FtPj;S
C.PjRV
CHROME_METRO_DLL
app\hard_error_handler_win.cc
ntdll.dll
CHROME_BREAKPAD_PIPE_NAME
1.3.21.115
app\breakpad_win.cc
Check failed: index < kMaxReportedActiveExtensions.
Check failed: url_cstring.
info.size() <= kMaxReportedPrinterRecords
Could not find exported function
app\client_util.cc
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Failed to load Chrome DLL from
Could not get Chrome DLL version.
ChromeMain
installer\util\google_update_settings.cc
Removed multi-install failure key; switching to channel:
Removed incremental installer failure key; switching to channel:
Failed to write to application's ClientState key
installer\util\install_util.cc
C:\quickrr\chromium\src\base/win/scoped_handle.h
installer\util\browser_distribution.cc
C:\quickrr\chromium\src\base/string_util.h
Check failed: length == static_cast<int>(language.length() 1).
CHROME_BINARIES == type
auto-launch-chrome
chrome
chrome-frame
chrome-sxs
do-not-launch-chrome
make-chrome-default
new-setup-exe
register-chrome-browser
register-chrome-browser-suffix
register-url-protocol
rename-chrome-exe
remove-chrome-registration
update-setup-exe
toast-results-key
Check failed: key.
installer\util\channel_info.cc
installer\util\l10n_string_util.cc
installer\util\app_commands.cc
Skipping over key "
Failed to open key "
Cannot initialize AppCommands from an invalid key.
googlechromeframe
installer\util\chrome_app_host_distribution.cc
This should never be accessed as Chrome App Host is not a
This should never be accessed as Chrome App Host has no
googlechromeapphost
installer\util\chromium_binaries_distribution.cc
installer\util\master_preferences.cc
Check failed: master_dictionary_.get().
: Bad boy, the buffer passed to placement new is not aligned!
C:\quickrr\chromium\src\base/lazy_instance.h
installer\util\language_selector.cc
Cannot initialize an AppCommand from an invalid key.
installer\util\app_command.cc
auto_launch_chrome
chrome_frame
chrome_shortcut_icon_index
import_bookmarks
import_bookmarks_from_file
import_history
import_home_page
import_search_engine
do_not_launch_chrome
make_chrome_default
make_chrome_default_for_user
extensions.settings
app\image_pre_reader_win.cc
Check failed: pe_image.VerifyMagic().
reinterpret_cast<const uint8*>(section 1) <= &headers[0] headers.size()
section == pe_image.GetImageSectionFromAddr(start length - 1)
section == pe_image.GetImageSectionFromAddr(start)
ERROR_REPORT
logging.cc
string_util.cc
Check failed: IsWprintfFormatPortable(format).
C:\quickrr\chromium\src\base/string_util_win.h
Check failed: rootkey && subkey && access && disposition.
win\registry.cc
Check failed: rootkey && subkey && access.
Check failed: key_.
Check failed: !subkey.
utf_string_conversions.cc
Check failed: other.IsValid().
version.cc
command_line.cc
user.js
file_path.cc
Check failed: data_.get().
file_version_info_win.cc
string_split.cc
Adebug\trace_event_impl.cc
at_exit.cc
time_win.cc
Check failed: it != outbuf.begin().
string_number_conversions.cc
Check failed: path.empty().
key >= base::DIR_CURRENT
path_service.cc
win\windows_version.cc
version_number_.minor == 2
win\scoped_handle.cc
values.cc
Check failed: (current_entry == dictionary_.end()) || current_entry->second.
Check failed: IsStringUTF8(key).
ins_res.first->second != in_value
json\json_file_value_serializer.cc
win\i18n.cc
kernel32.dll not found.
debug\trace_event_win.cc
callback_internal.cc
threading\thread_local_win.cc
0123456789
C:\quickrr\chromium\src\base/win/scoped_co_mem.h
json\json_writer.cc
win\scoped_process_information.cc
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
json\json_reader.cc
.syzygy
.thunks
Check failed: image.VerifyMagic().
debug\profiler.cc
tracked_objects.cc
\uX
json\json_parser.cc
Line: %i, column: %i, %s
CHROME_PROFILER_TIME
Check failed: !TlsGetValue(g_native_tls_key).
Check failed: value != TLS_OUT_OF_INDEXES.
threading\thread_local_storage_win.cc
kernel32.dll
win\src\sandbox_utils.cc
win\src\win_utils.cc
Check failed: !path.empty().
win\src\broker_services.cc
win\src\sharedmem_ipc_client.cc
Check failed: name.second.
win\src\handle_closer_agent.cc
win\src\restricted_token_utils.cc
win\src\sandbox_policy_base.cc
Check failed: !appcontainer_list_.get().
win\src\app_container.cc
Check failed: attributes_.empty().
Check failed: !capabilities_.AppContainerSid.
win\src\handle_closer.cc
win\src\restricted_token.cc
win\src\sid.cc
win\src\sharedmem_ipc_server.cc
win\src\interception.cc
win\src\window.cc
NtOpenKey
NtCreateKey
win\src\registry_policy.cc
win\src\sync_policy.cc
win\src\filesystem_policy.cc
win\src\crosscall_server.cc
NtOpenKeyEx
win\src\process_thread_dispatcher.cc
CreateNamedPipeW
win\src\acl.cc
win\src\service_resolver.cc
win\src\Wow64.cc
AutoSelectCertificateForUrls
CloudPrintProxyEnabled
CloudPrintSubmitEnabled
CookiesAllowedForUrls
CookiesBlockedForUrls
CookiesSessionOnlyForUrls
DefaultSearchProviderAlternateURLs
DefaultSearchProviderIconURL
DefaultSearchProviderInstantURL
DefaultSearchProviderKeyword
DefaultSearchProviderSearchURL
DefaultSearchProviderSuggestURL
EnableAuthNegotiatePort
EnableOriginBoundCerts
EnterpriseWebStoreName
EnterpriseWebStoreURL
HideWebStorePromo
ImagesAllowedForUrls
ImagesBlockedForUrls
ImportBookmarks
ImportHistory
ImportHomepage
ImportSavedPasswords
ImportSearchEngine
JavaScriptAllowedForUrls
JavaScriptBlockedForUrls
MetricsReportingEnabled
NotificationsAllowedForUrls
NotificationsBlockedForUrls
PasswordManagerAllowShowPasswords
PasswordManagerEnabled
PluginsAllowedForUrls
PluginsBlockedForUrls
PopupsAllowedForUrls
PopupsBlockedForUrls
ProxyBypassList
ProxyPacUrl
RemoteAccessHostDomain
RemoteAccessHostFirewallTraversal
RemoteAccessHostRequireCurtain
RemoteAccessHostRequireTwoFactor
RemoteAccessHostTalkGadgetPrefix
RestoreOnStartupURLs
URLBlacklist
URLWhitelist
ChromeFrameContentTypes
ChromeFrameRendererSettings
ChromeOsLockOnIdleSuspend
ChromeOsReleaseChannel
ChromeOsReleaseChannelDelegated
DeviceLoginScreenSaverId
DeviceLoginScreenSaverTimeout
DeviceMetricsReportingEnabled
DeviceStartUpUrls
RenderInChromeFrameList
ReportDeviceActivityTimes
ReportDeviceBootMode
ReportDeviceLocation
ReportDeviceVersionInfo
full-memory-crash-report
https
0123456789:
?456789:;<=
!"#$%&'()* ,-./0123
windows-936
windows-950
windows-949
windows-932
windows-874
windows-1254
windows-1251
windows-1256
windows-1255
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
windows-%d
!$*);^-/
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones
ucol_nextSortKeyPart
ucol_getSortKey
Returns %d.
Returns. Status = %d.
Returns %d. Status = %d.
Returns %d. Status = %p.
keyMap
keyTypeData
Keys
>CHROME_PRE_READ_EXPERIMENT
CHROME_HEADLESS
CHROME_LOG_FILE
CHROMEOS_SESSION_LOG_DIR
CHROME_CRASHED
CHROME_RESTART
allow-http-background-page
app-notify-channel-server-url
apps-checkout-url
apps-gallery-download-url
apps-gallery-url
apps-gallery-update-url
chrome-frame-shutdown-delay
chrome-version
device-management-url
disable-extensions-http-throttling
disable-sync-passwords
disable-sync-typed-urls
disable-web-resources
disable-website-settings
enable-auth-negotiate-port
enable-autologin
enable-crxless-web-apps
enable-http-pipelining
enable-metrics-reporting-for-testing
enable-npn-http
enable-password-generation
enable-websocket-over-spdy
explicitly-allowed-ports
google-search-domain-check-url
import
import-from-file
install-from-webstore
instant-url
nacl-loader-cmd-prefix
pack-extension-key
promo-server-url
proxy-bypass-list
proxy-pac-url
safebrowsing-url-prefix
sync-invalidate-xmpp-login
sync-keystore-encryption
sync-notification-host-port
sync-url
sync-try-ssltcp-first-for-xmpp
try-chrome-again
ignore-certificate-errors
variations-server-url
visit-urls
thumbnail-urls
web-intents-native-services-enabled
winhttp-proxy-resolver
plugins-metadata-server-url
profile.exited_cleanly
profile.exit_type
session.restore_on_startup
session.urls_to_restore_on_startup
session.restore_on_startup_migrated
intl.app_locale
intl.charset_default
intl.accept_languages
intl.static_encodings
intl.global.charset_default
webkit.webprefs.global.default_font_size
webkit.webprefs.global.default_fixed_font_size
webkit.webprefs.global.minimum_font_size
webkit.webprefs.global.minimum_logical_font_size
webkit.webprefs.global.javascript_can_open_windows_automatically
webkit.webprefs.global.javascript_enabled
webkit.webprefs.global.loads_images_automatically
webkit.webprefs.global.plugins_enabled
webkit.webprefs.global.standard_font_family
webkit.webprefs.global.fixed_font_family
webkit.webprefs.global.serif_font_family
webkit.webprefs.global.sansserif_font_family
webkit.webprefs.global.cursive_font_family
webkit.webprefs.global.fantasy_font_family
webkit.webprefs.standard_font_family
webkit.webprefs.fixed_font_family
webkit.webprefs.serif_font_family
webkit.webprefs.sansserif_font_family
webkit.webprefs.cursive_font_family
webkit.webprefs.fantasy_font_family
webkit.webprefs.fonts.standard
webkit.webprefs.fonts.fixed
webkit.webprefs.fonts.serif
webkit.webprefs.fonts.sansserif
webkit.webprefs.fonts.cursive
webkit.webprefs.fonts.fantasy
webkit.webprefs.fonts.pictograph
webkit.webprefs.fonts.standard.Arab
webkit.webprefs.fonts.fixed.Arab
webkit.webprefs.fonts.serif.Arab
webkit.webprefs.fonts.sansserif.Arab
webkit.webprefs.fonts.standard.Cyrl
webkit.webprefs.fonts.fixed.Cyrl
webkit.webprefs.fonts.serif.Cyrl
webkit.webprefs.fonts.sansserif.Cyrl
webkit.webprefs.fonts.standard.Grek
webkit.webprefs.fonts.fixed.Grek
webkit.webprefs.fonts.serif.Grek
webkit.webprefs.fonts.sansserif.Grek
webkit.webprefs.fonts.standard.Jpan
webkit.webprefs.fonts.fixed.Jpan
webkit.webprefs.fonts.serif.Jpan
webkit.webprefs.fonts.sansserif.Jpan
webkit.webprefs.fonts.standard.Hang
webkit.webprefs.fonts.fixed.Hang
webkit.webprefs.fonts.serif.Hang
webkit.webprefs.fonts.sansserif.Hang
webkit.webprefs.fonts.cursive.Hang
webkit.webprefs.fonts.standard.Hans
webkit.webprefs.fonts.fixed.Hans
webkit.webprefs.fonts.serif.Hans
webkit.webprefs.fonts.sansserif.Hans
webkit.webprefs.fonts.standard.Hant
webkit.webprefs.fonts.fixed.Hant
webkit.webprefs.fonts.serif.Hant
webkit.webprefs.fonts.sansserif.Hant
webkit.webprefs.web_security_enabled
webkit.webprefs.dom_paste_enabled
webkit.webprefs.shrinks_standalone_images_to_fit
webkit.webprefs.inspector_settings
webkit.webprefs.uses_universal_detector
webkit.webprefs.text_areas_are_resizable
webkit.webprefs.java_enabled
webkit.webprefs.tabs_to_links
webkit.webprefs.allow_displaying_insecure_content
webkit.webprefs.allow_running_insecure_content
webkit.webprefs.fonts.standard.Zyyy
webkit.webprefs.fonts.fixed.Zyyy
webkit.webprefs.fonts.serif.Zyyy
webkit.webprefs.fonts.sansserif.Zyyy
webkit.webprefs.fonts.cursive.Zyyy
webkit.webprefs.fonts.fantasy.Zyyy
webkit.webprefs.fonts.pictograph.Zyyy
webkit.webprefs.default_font_size
webkit.webprefs.default_fixed_font_size
webkit.webprefs.minimum_font_size
webkit.webprefs.minimum_logical_font_size
webkit.webprefs.javascript_enabled
webkit.webprefs.javascript_can_open_windows_automatically
webkit.webprefs.loads_images_automatically
webkit.webprefs.plugins_enabled
bookmark_bar.show_on_all_tabs
bookmark_editor.expanded_nodes
profile.password_manager_enabled
profile.password_manager_allow_show_passwords
password_generation.enabled
autologin.enabled
reverse_autologin.enabled
reverse_autologin.rejected_email_list
safebrowsing.enabled
safebrowsing.reporting_enabled
safebrowsing.proceed_anyway_disabled
incognito.mode_availability
search.suggest_enabled
browser.confirm_to_quit
security.cookie_behavior
default_search_provider.synced_guid
default_search_provider.enabled
default_search_provider.search_url
default_search_provider.suggest_url
default_search_provider.instant_url
default_search_provider.icon_url
default_search_provider.encodings
default_search_provider.name
default_search_provider.keyword
default_search_provider.id
default_search_provider.prepopulate_id
default_search_provider.alternate_urls
download.prompt_for_download
alternate_error_pages.enabled
dns_prefetching.startup_list
dns_prefetching.host_referral_list
spdy.disabled
net.http_server_properties
spdy.servers
spdy.alternate_protocol
protocol.disabled_schemes
policy.url_blacklist
policy.url_whitelist
instant.animation_scale_factor
instant.confirm_dialog_shown
instant.enabled
instant.experimental_zero_suggest_url_prefix
instant.show_search_provider_logo
instant.show_white_ntp
local_state.multiple_profile_prefs_version
dns_prefetching.enabled
browser.show_home_button
profile.recently_selected_encodings
browser.clear_data.browsing_history
browser.clear_data.download_history
browser.clear_data.cache
browser.clear_data.cookies
browser.clear_data.passwords
browser.clear_data.form_data
browser.clear_data.hosted_apps_data
browser.clear_data.content_licenses
browser.clear_data.time_period
browser.enable_spellchecking
browser.enabled_labs_experiments
browser.enable_autospellcorrect
browser.speechinput_censor_results
browser.speechinput_tray_notification_shown_contexts
history.saving_disabled
extensions.theme.pack
extensions.theme.id
extensions.theme.images
extensions.theme.colors
extensions.theme.tints
extensions.theme.properties
extensions.ui.developer_mode
extensions.toolbarsize
extensions.commands
plugins.last_internal_directory
plugins.plugins_list
plugins.plugins_disabled
plugins.plugins_disabled_exceptions
plugins.plugins_enabled
plugins.enabled_internal_pdf3
plugins.enabled_nacl
plugins.migrated_to_pepper_flash
plugins.show_details
plugins.allow_outdated
plugins.always_authorize
plugins.metadata
plugins.resource_cache_update
browser.check_default_browser
browser.suppress_switch_to_metro_mode_on_set_default
browser.default_browser_setting_enabled
browser.custom_chrome_frame
browser.show_omnibox_search_hint
profile.notifications_default_content_setting
profile.notification_allowed_sites
profile.notification_denied_sites
browser.desktop_notification_position
profile.default_content_settings
profile.content_settings.clear_on_exit_migrated
profile.content_settings.pref_version
profile.content_settings.patterns
profile.content_settings.pattern_pairs
profile.content_settings.whitelist_version
profile.content_settings.plugin_whitelist
profile.block_third_party_cookies
profile.clear_site_data_on_exit
profile.default_zoom_level
profile.per_host_zoom_levels
autofill.enabled
autofill.auxiliary_profiles_enabled
autofill.positive_upload_rate
autofill.negative_upload_rate
autofill.pdm.first_run
bookmarks.editing_enabled
translate.enabled
geolocation.default_content_setting
geolocation.content_settings
import_saved_passwords
webstore.enterprise_store_url
webstore.enterprise_store_name
profile.avatar_index
profile.name
printing.enabled
printing.print_preview_disabled
profile.last_used
profile.last_active_profiles
profile.profiles_created
profile.created_by_version
profile.info_cache
ssl.rev_checking.enabled
ssl.version_min
ssl.version_max
ssl.cipher_suites.blacklist
ssl.origin_bound_certs.enabled
ssl.ssl_record_splitting.disabled
user_experience_metrics.client_id
user_experience_metrics.session_id
user_experience_metrics.low_entropy_source
user_experience_metrics.client_id_timestamp
user_experience_metrics.reporting_enabled
user_experience_metrics.initial_logs
user_experience_metrics.initial_logs_as_protobufs
user_experience_metrics.ongoing_logs
user_experience_metrics.ongoing_logs_as_protobufs
user_experience_metrics.profiles
user_experience_metrics.stability.exited_cleanly
user_experience_metrics.stability.stats_version
user_experience_metrics.stability.stats_buildtime
user_experience_metrics.stability.session_end_completed
user_experience_metrics.stability.launch_count
user_experience_metrics.stability.crash_count
user_experience_metrics.stability.incomplete_session_end_count
user_experience_metrics.stability.page_load_count
user_experience_metrics.stability.renderer_crash_count
user_experience_metrics.stability.launch_time_sec
user_experience_metrics.stability.extension_renderer_crash_count
user_experience_metrics.stability.last_timestamp_sec
user_experience_metrics.stability.plugin_stats2
user_experience_metrics.stability.renderer_hang_count
user_experience_metrics.stability.child_process_crash_count
user_experience_metrics.stability.other_user_crash_count
user_experience_metrics.stability.kernel_crash_count
user_experience_metrics.stability.system_unclean_shutdowns
user_experience_metrics.stability.breakpad_registration_ok
user_experience_metrics.stability.breakpad_registration_fail
user_experience_metrics.stability.debugger_present
user_experience_metrics.stability.debugger_not_present
uninstall_metrics.page_load_count
uninstall_metrics.launch_count
uninstall_metrics.installation_date2
uninstall_metrics.uptime_sec
uninstall_metrics.last_launch_time_sec
uninstall_metrics.last_observed_running_time_sec
browser.window_placement
task_manager.window_placement
keyword_editor.window_placement
preferences.window_placement
renderer.memory_cache.size
download.default_directory
download.directory_upgrade
savefile.default_directory
savefile.type
selectfile.last_directory
select_file_dialogs.allowed
filebrowser.tasks.default_by_mime_type
filebrowser.tasks.default_by_suffix
download.extensions_to_open
browser.hung_plugin_detect_freq
browser.plugin_message_response_timeout
spellcheck.dictionary
spellcheck.confirm_dialog_shown
spellcheck.use_spelling_service
protocol_handler.excluded_schemes
safe_browsing.client_key
safe_browsing.wrapped_key
options_window.last_tab_index
content_settings_window.last_tab_index
certificate_manager_window.last_tab_index
browser.last_known_google_url
browser.last_prompted_google_url
browser.last_redirect_origin
shutdown.type
shutdown.num_processes
shutdown.num_processes_slow
restart.last.session.on.shutdown
was.restarted
restart.switch_mode
user_experience_metrics.num_bookmarks_on_bookmark_bar
user_experience_metrics.num_folders_on_bookmark_bar
user_experience_metrics.num_bookmarks_in_other_bookmark_folder
user_experience_metrics.num_folders_in_other_bookmark_folder
user_experience_metrics.num_keywords
extensions.disabled
plugins.disable_plugin_finder
extensions.browseractions.container.width
extensions.allowed_install_sites
extensions.install.allowlist
extensions.install.denylist
extensions.alerts.initialized
extensions.install.forcelist
extensions.autoupdate.last_check
extensions.autoupdate.next_check
extensions.blacklistupdate.version
ntp.collapsed_foreign_sessions
ntp.most_visited_blacklist
ntp.promo_resource_cache_update
ntp.tips_resource_server
ntp.date_resource_server
ntp.shown_bookmarks_folder
ntp.shown_page
ntp.promo_desktop_session_found
ntp.webstore_enabled
ntp.app_page_names
ntp.game_page_names
devtools.disabled
devtools.dock_side
devtools.edited_files
devtools.split_location
devtools.open_docked
sync.last_synced_time
sync.has_setup_completed
sync.keep_everything_synced
sync.bookmarks
sync.passwords
sync.preferences
sync.app_notifications
sync.app_settings
sync.apps
sync.autofill
sync.autofill_profile
sync.themes
sync.typed_urls
sync.extensions
sync.extension_settings
sync.search_engines
sync.sessions
sync.managed
sync.suppress_start
sync.acknowledged_types
sync.max_invalidation_versions
sync.session_sync_guid
invalidator.invalidation_state
invalidator.max_invalidation_versions
sync.encryption_bootstrap_token
sync.keystore_encryption_bootstrap_token
sync.using_secondary_passphrase
google.services.username
google.services.username_pattern
sync_promo.startup_count
sync_promo.view_count
sync_promo.user_skipped
sync_promo.show_on_first_run_allowed
sync_promo.show_ntp_bubble
profile.gaia_info_update_time
profile.gaia_info_picture_url
browser.web_app.create_on_desktop
browser.web_app.create_in_apps_menu
browser.web_app.create_in_quick_launch_bar
geolocation.access_token
remote_access.host_firewall_traversal
remote_access.host_require_two_factor
remote_access.host_domain
remote_access.host_talkgadget_prefix
remote_access.host_require_curtain
printing.print_preview_sticky_settings
cloud_print.service_url
cloud_print.signin_url
cloud_print.dialog_size.width
cloud_print.dialog_size.height
cloud_print.signin_dialog_size.width
cloud_print.signin_dialog_size.height
chrome_to_mobile.device_list
background_contents.registered
browser.shown_autolaunch_infobar
auth.schemes
auth.disable_negotiate_cname_lookup
auth.enable_negotiate_port
auth.server_whitelist
auth.negotiate_delegate_whitelist
auth.gssapi_library_name
auth.spdyproxy.origin
auth.allow_cross_origin_prompt
browser.clear_lso_data_enabled
browser.pepper_flash_settings_enabled
browser.disk_cache_dir
browser.disk_cache_size
browser.media_cache_size
cros.system.releaseChannel
policy.load_cloud_policy_on_signin
cloud_print.enabled
cloud_print.proxy_id
cloud_print.auth_token
cloud_print.xmpp_auth_token
cloud_print.email
cloud_print.print_system_settings
cloud_print.enable_job_poll
cloud_print.robot_refresh_token
cloud_print.robot_email
cloud_print.connect_new_printers
cloud_print.printer_blacklist
cloud_print.submit_enabled
net.max_connections_per_proxy
profile.managed_default_content_settings.cookies
profile.managed_default_content_settings.images
profile.managed_default_content_settings.javascript
profile.managed_default_content_settings.plugins
profile.managed_default_content_settings.popups
profile.managed_default_content_settings.geolocation
profile.managed_default_content_settings.notifications
profile.managed_default_content_settings.media_stream
profile.managed_cookies_allowed_for_urls
profile.managed_cookies_blocked_for_urls
profile.managed_cookies_sessiononly_for_urls
profile.managed_images_allowed_for_urls
profile.managed_images_blocked_for_urls
profile.managed_javascript_allowed_for_urls
profile.managed_javascript_blocked_for_urls
profile.managed_plugins_allowed_for_urls
profile.managed_plugins_blocked_for_urls
profile.managed_popups_allowed_for_urls
profile.managed_popups_blocked_for_urls
profile.managed_notifications_allowed_for_urls
profile.managed_notifications_blocked_for_urls
profile.managed_auto_select_certificate_for_urls
background_mode.user_created_login_item
background_mode.user_removed_login_item
background_mode.enabled
custom_handlers.registered_protocol_handlers
custom_handlers.ignored_protocol_handlers
custom_handlers.enabled
policy.device_refresh_rate
policy.user_refresh_rate
recovery_component.version
component_updater.state
webintents.enabled
media_galleries.gallery_id
media_galleries.remembered_galleries
network_profile.warnings_left
network_profile.last_warning_time
policy.last_statistics_update
chrome.googleechotest.com
hXXp://pipelining.googleechotest.com/
allow-webui-compositing
disable-webgl
blacklist-webgl
disable-image-transport-surface
speech-service-key
disable-webaudio
disable-web-security
disable-web-sockets
enable-experimental-webkit-features
disable-web-media-player-ms
enable-privileged-webgl-extensions
enable-tcp-fastopen
enable-viewport
in-process-webgl
remote-debugging-port
renderer-cmd-prefix
testing-fixed-http-port
testing-fixed-https-port
utility-cmd-prefix
webcore-log-channels
zygote-cmd-prefix
Visual C CRT: Not enough memory to complete call to strerror.
?#%X.y
Broken pipe
Inappropriate I/O control operation
Operation not permitted
portuguese-brazilian
GetProcessWindowStation
operator
SHELL32.dll
ole32.dll
C:\quickrr\chromium\src\build\Release\chrome_exe.pdb
ShellExecuteW
SHLWAPI.dll
KERNEL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WINMM.dll
GetWindowsDirectoryW
CreateIoCompletionPort
WaitNamedPipeW
TransactNamedPipe
SetNamedPipeHandleState
GetProcessHandleCount
GetProcessHeap
GetCPInfo
CloseWindowStation
CreateWindowStationW
SetProcessWindowStation
RegQueryInfoKeyW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
PlayFreeBrowser.exe
SetActiveURL
zcÁ
bd.tvt
]"kL:%s!
C$Ö
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD0T1;2c2?3d3
8 8*8>8~8
<$<9<[<{<3 3$3(3<7
6,7074787<7
:':-:5:=:
8$8(8,8084888<8@8
9(9/94989<9]9
9&:,:0:4:8:
8.9;9[9':>:
8&9.969>9~9
3(7,7074787
> >$>8><>
? ?$?(?,?0?4?
5 5$5(5,50545
?$?,?4?<?
\\.\pipe\GoogleCrashServices\
\\.\pipe\ChromeCrashServices
error %u
hurl-chunk-%i
prn-info-%d
0.0.0.0-devel
Chrome
ChromeFrame
Software\Google\ChromeFrame
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}ChromeCanary
registering_chrome
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser
hXXp://VVV.playfree.org/en/uninstall.html?utm_source=[%ORIGIN%]_[%SOURCE_SITE%]&utm_medium=uninstall
%d.%d.%d
ed-d-d
hXXp://update.playfree.org/browser/updatechecker/?
{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}{00337EA4-7B9A-44a6-B45B-B1722CD4343E}MPCBrowserUpdate.exe
CFEndTempOptOutCmd
CFOptInCmd
CFOptOutCmd
CFTempOptOutCmd
UninstallCmdLine
WebAccessible
app_host.exe
PlayFreeBrowser.dll
npchrome_frame.dll
chrome_frame_helper.exe
ChromeFrameHelperWindowClass
ChromeFrameReadyMode
chrome_launcher.exe
new_chrome.exe
old_chrome.exe
delegate_execute.exe
nacl64.exe
setup.exe
InstallerSuccessLaunchCmdLine
-chrome
-chromeframe
{5C65F4B0-3651-4514-B207-D10CB699B14B}hXXps://clients4.google.com/firefox/metrics/collect
{8BA986DA-5100-405E-AA35-86F34A02ACBF}Google Chrome Frame
Google\Chrome Frame
Chrome in a Frame.
Uninstall Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}Google Chrome App Host
A standalone platform for Chrome apps.
.Uninstall Chrome App Host
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome App Host
debug_message.exe
debug.log
.\debug.log
Software\Microsoft\Windows\CurrentVersion\Run
\StringFileInfo\xx\%ls
ckernel32.dll
psapi.dll
Chrome_MessagePumpWindow
%s\%s.dmp
rpcrt4.dll
dbghelp.dll
x-x-x-xx-xxxxxx
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_NLSTEXT
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
pipe\
ALPC Port
cntdll.dll
s0x%X
wow_helper.exe"
00000000
333333333333333333
333333333336
%%CollationBin
NPlayFreeBrowser.exe
metro_driver.dll
Chrome_StatusTrayWindow
Chrome_MessageWindow
Reported Crashes.txt
testing_interface.dll
Certificate Revocation Lists
Custom Dictionary.txt
Login Data
Origin Bound Certs
Cached Theme.pak
Web Applications
Web Data
pepflashplayer.dll
CHROME_METRO_NAV_SEARCH_REQUEST
CHROME_METRO_GET_CURRENT_TAB_INFO
mscoree.dll
ADVAPI32.DLL
nKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe
3.0.0.4
chrome_exe
PlayFreeBrowser.exe_3592_rwx_1E70A000_00060000:
j.hmO
PlayFreeBrowser.exe_3740:
.text
`.rdata
@.data
.rsrc
@.reloc
QPWSSh
>%u]2
Ht.Ht
tE<.tA<@t=
u.WSh
<.tW<@tS
xSSSh
FTPjKS
FtPj;S
C.PjRV
CHROME_METRO_DLL
app\hard_error_handler_win.cc
ntdll.dll
CHROME_BREAKPAD_PIPE_NAME
1.3.21.115
app\breakpad_win.cc
Check failed: index < kMaxReportedActiveExtensions.
Check failed: url_cstring.
info.size() <= kMaxReportedPrinterRecords
Could not find exported function
app\client_util.cc
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Failed to load Chrome DLL from
Could not get Chrome DLL version.
ChromeMain
installer\util\google_update_settings.cc
Removed multi-install failure key; switching to channel:
Removed incremental installer failure key; switching to channel:
Failed to write to application's ClientState key
installer\util\install_util.cc
C:\quickrr\chromium\src\base/win/scoped_handle.h
installer\util\browser_distribution.cc
C:\quickrr\chromium\src\base/string_util.h
Check failed: length == static_cast<int>(language.length() 1).
CHROME_BINARIES == type
auto-launch-chrome
chrome
chrome-frame
chrome-sxs
do-not-launch-chrome
make-chrome-default
new-setup-exe
register-chrome-browser
register-chrome-browser-suffix
register-url-protocol
rename-chrome-exe
remove-chrome-registration
update-setup-exe
toast-results-key
Check failed: key.
installer\util\channel_info.cc
installer\util\l10n_string_util.cc
installer\util\app_commands.cc
Skipping over key "
Failed to open key "
Cannot initialize AppCommands from an invalid key.
googlechromeframe
installer\util\chrome_app_host_distribution.cc
This should never be accessed as Chrome App Host is not a
This should never be accessed as Chrome App Host has no
googlechromeapphost
installer\util\chromium_binaries_distribution.cc
installer\util\master_preferences.cc
Check failed: master_dictionary_.get().
: Bad boy, the buffer passed to placement new is not aligned!
C:\quickrr\chromium\src\base/lazy_instance.h
installer\util\language_selector.cc
Cannot initialize an AppCommand from an invalid key.
installer\util\app_command.cc
auto_launch_chrome
chrome_frame
chrome_shortcut_icon_index
import_bookmarks
import_bookmarks_from_file
import_history
import_home_page
import_search_engine
do_not_launch_chrome
make_chrome_default
make_chrome_default_for_user
extensions.settings
app\image_pre_reader_win.cc
Check failed: pe_image.VerifyMagic().
reinterpret_cast<const uint8*>(section 1) <= &headers[0] headers.size()
section == pe_image.GetImageSectionFromAddr(start length - 1)
section == pe_image.GetImageSectionFromAddr(start)
ERROR_REPORT
logging.cc
string_util.cc
Check failed: IsWprintfFormatPortable(format).
C:\quickrr\chromium\src\base/string_util_win.h
Check failed: rootkey && subkey && access && disposition.
win\registry.cc
Check failed: rootkey && subkey && access.
Check failed: key_.
Check failed: !subkey.
utf_string_conversions.cc
Check failed: other.IsValid().
version.cc
command_line.cc
user.js
file_path.cc
Check failed: data_.get().
file_version_info_win.cc
string_split.cc
Adebug\trace_event_impl.cc
at_exit.cc
time_win.cc
Check failed: it != outbuf.begin().
string_number_conversions.cc
Check failed: path.empty().
key >= base::DIR_CURRENT
path_service.cc
win\windows_version.cc
version_number_.minor == 2
win\scoped_handle.cc
values.cc
Check failed: (current_entry == dictionary_.end()) || current_entry->second.
Check failed: IsStringUTF8(key).
ins_res.first->second != in_value
json\json_file_value_serializer.cc
win\i18n.cc
kernel32.dll not found.
debug\trace_event_win.cc
callback_internal.cc
threading\thread_local_win.cc
0123456789
C:\quickrr\chromium\src\base/win/scoped_co_mem.h
json\json_writer.cc
win\scoped_process_information.cc
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
json\json_reader.cc
.syzygy
.thunks
Check failed: image.VerifyMagic().
debug\profiler.cc
tracked_objects.cc
\uX
json\json_parser.cc
Line: %i, column: %i, %s
CHROME_PROFILER_TIME
Check failed: !TlsGetValue(g_native_tls_key).
Check failed: value != TLS_OUT_OF_INDEXES.
threading\thread_local_storage_win.cc
kernel32.dll
win\src\sandbox_utils.cc
win\src\win_utils.cc
Check failed: !path.empty().
win\src\broker_services.cc
win\src\sharedmem_ipc_client.cc
Check failed: name.second.
win\src\handle_closer_agent.cc
win\src\restricted_token_utils.cc
win\src\sandbox_policy_base.cc
Check failed: !appcontainer_list_.get().
win\src\app_container.cc
Check failed: attributes_.empty().
Check failed: !capabilities_.AppContainerSid.
win\src\handle_closer.cc
win\src\restricted_token.cc
win\src\sid.cc
win\src\sharedmem_ipc_server.cc
win\src\interception.cc
win\src\window.cc
NtOpenKey
NtCreateKey
win\src\registry_policy.cc
win\src\sync_policy.cc
win\src\filesystem_policy.cc
win\src\crosscall_server.cc
NtOpenKeyEx
win\src\process_thread_dispatcher.cc
CreateNamedPipeW
win\src\acl.cc
win\src\service_resolver.cc
win\src\Wow64.cc
AutoSelectCertificateForUrls
CloudPrintProxyEnabled
CloudPrintSubmitEnabled
CookiesAllowedForUrls
CookiesBlockedForUrls
CookiesSessionOnlyForUrls
DefaultSearchProviderAlternateURLs
DefaultSearchProviderIconURL
DefaultSearchProviderInstantURL
DefaultSearchProviderKeyword
DefaultSearchProviderSearchURL
DefaultSearchProviderSuggestURL
EnableAuthNegotiatePort
EnableOriginBoundCerts
EnterpriseWebStoreName
EnterpriseWebStoreURL
HideWebStorePromo
ImagesAllowedForUrls
ImagesBlockedForUrls
ImportBookmarks
ImportHistory
ImportHomepage
ImportSavedPasswords
ImportSearchEngine
JavaScriptAllowedForUrls
JavaScriptBlockedForUrls
MetricsReportingEnabled
NotificationsAllowedForUrls
NotificationsBlockedForUrls
PasswordManagerAllowShowPasswords
PasswordManagerEnabled
PluginsAllowedForUrls
PluginsBlockedForUrls
PopupsAllowedForUrls
PopupsBlockedForUrls
ProxyBypassList
ProxyPacUrl
RemoteAccessHostDomain
RemoteAccessHostFirewallTraversal
RemoteAccessHostRequireCurtain
RemoteAccessHostRequireTwoFactor
RemoteAccessHostTalkGadgetPrefix
RestoreOnStartupURLs
URLBlacklist
URLWhitelist
ChromeFrameContentTypes
ChromeFrameRendererSettings
ChromeOsLockOnIdleSuspend
ChromeOsReleaseChannel
ChromeOsReleaseChannelDelegated
DeviceLoginScreenSaverId
DeviceLoginScreenSaverTimeout
DeviceMetricsReportingEnabled
DeviceStartUpUrls
RenderInChromeFrameList
ReportDeviceActivityTimes
ReportDeviceBootMode
ReportDeviceLocation
ReportDeviceVersionInfo
full-memory-crash-report
https
0123456789:
?456789:;<=
!"#$%&'()* ,-./0123
windows-936
windows-950
windows-949
windows-932
windows-874
windows-1254
windows-1251
windows-1256
windows-1255
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
windows-%d
!$*);^-/
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones\
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT
SOFTWARE\Microsoft\Windows\CurrentVersion\Time Zones
ucol_nextSortKeyPart
ucol_getSortKey
Returns %d.
Returns. Status = %d.
Returns %d. Status = %d.
Returns %d. Status = %p.
keyMap
keyTypeData
Keys
>CHROME_PRE_READ_EXPERIMENT
CHROME_HEADLESS
CHROME_LOG_FILE
CHROMEOS_SESSION_LOG_DIR
CHROME_CRASHED
CHROME_RESTART
allow-http-background-page
app-notify-channel-server-url
apps-checkout-url
apps-gallery-download-url
apps-gallery-url
apps-gallery-update-url
chrome-frame-shutdown-delay
chrome-version
device-management-url
disable-extensions-http-throttling
disable-sync-passwords
disable-sync-typed-urls
disable-web-resources
disable-website-settings
enable-auth-negotiate-port
enable-autologin
enable-crxless-web-apps
enable-http-pipelining
enable-metrics-reporting-for-testing
enable-npn-http
enable-password-generation
enable-websocket-over-spdy
explicitly-allowed-ports
google-search-domain-check-url
import
import-from-file
install-from-webstore
instant-url
nacl-loader-cmd-prefix
pack-extension-key
promo-server-url
proxy-bypass-list
proxy-pac-url
safebrowsing-url-prefix
sync-invalidate-xmpp-login
sync-keystore-encryption
sync-notification-host-port
sync-url
sync-try-ssltcp-first-for-xmpp
try-chrome-again
ignore-certificate-errors
variations-server-url
visit-urls
thumbnail-urls
web-intents-native-services-enabled
winhttp-proxy-resolver
plugins-metadata-server-url
profile.exited_cleanly
profile.exit_type
session.restore_on_startup
session.urls_to_restore_on_startup
session.restore_on_startup_migrated
intl.app_locale
intl.charset_default
intl.accept_languages
intl.static_encodings
intl.global.charset_default
webkit.webprefs.global.default_font_size
webkit.webprefs.global.default_fixed_font_size
webkit.webprefs.global.minimum_font_size
webkit.webprefs.global.minimum_logical_font_size
webkit.webprefs.global.javascript_can_open_windows_automatically
webkit.webprefs.global.javascript_enabled
webkit.webprefs.global.loads_images_automatically
webkit.webprefs.global.plugins_enabled
webkit.webprefs.global.standard_font_family
webkit.webprefs.global.fixed_font_family
webkit.webprefs.global.serif_font_family
webkit.webprefs.global.sansserif_font_family
webkit.webprefs.global.cursive_font_family
webkit.webprefs.global.fantasy_font_family
webkit.webprefs.standard_font_family
webkit.webprefs.fixed_font_family
webkit.webprefs.serif_font_family
webkit.webprefs.sansserif_font_family
webkit.webprefs.cursive_font_family
webkit.webprefs.fantasy_font_family
webkit.webprefs.fonts.standard
webkit.webprefs.fonts.fixed
webkit.webprefs.fonts.serif
webkit.webprefs.fonts.sansserif
webkit.webprefs.fonts.cursive
webkit.webprefs.fonts.fantasy
webkit.webprefs.fonts.pictograph
webkit.webprefs.fonts.standard.Arab
webkit.webprefs.fonts.fixed.Arab
webkit.webprefs.fonts.serif.Arab
webkit.webprefs.fonts.sansserif.Arab
webkit.webprefs.fonts.standard.Cyrl
webkit.webprefs.fonts.fixed.Cyrl
webkit.webprefs.fonts.serif.Cyrl
webkit.webprefs.fonts.sansserif.Cyrl
webkit.webprefs.fonts.standard.Grek
webkit.webprefs.fonts.fixed.Grek
webkit.webprefs.fonts.serif.Grek
webkit.webprefs.fonts.sansserif.Grek
webkit.webprefs.fonts.standard.Jpan
webkit.webprefs.fonts.fixed.Jpan
webkit.webprefs.fonts.serif.Jpan
webkit.webprefs.fonts.sansserif.Jpan
webkit.webprefs.fonts.standard.Hang
webkit.webprefs.fonts.fixed.Hang
webkit.webprefs.fonts.serif.Hang
webkit.webprefs.fonts.sansserif.Hang
webkit.webprefs.fonts.cursive.Hang
webkit.webprefs.fonts.standard.Hans
webkit.webprefs.fonts.fixed.Hans
webkit.webprefs.fonts.serif.Hans
webkit.webprefs.fonts.sansserif.Hans
webkit.webprefs.fonts.standard.Hant
webkit.webprefs.fonts.fixed.Hant
webkit.webprefs.fonts.serif.Hant
webkit.webprefs.fonts.sansserif.Hant
webkit.webprefs.web_security_enabled
webkit.webprefs.dom_paste_enabled
webkit.webprefs.shrinks_standalone_images_to_fit
webkit.webprefs.inspector_settings
webkit.webprefs.uses_universal_detector
webkit.webprefs.text_areas_are_resizable
webkit.webprefs.java_enabled
webkit.webprefs.tabs_to_links
webkit.webprefs.allow_displaying_insecure_content
webkit.webprefs.allow_running_insecure_content
webkit.webprefs.fonts.standard.Zyyy
webkit.webprefs.fonts.fixed.Zyyy
webkit.webprefs.fonts.serif.Zyyy
webkit.webprefs.fonts.sansserif.Zyyy
webkit.webprefs.fonts.cursive.Zyyy
webkit.webprefs.fonts.fantasy.Zyyy
webkit.webprefs.fonts.pictograph.Zyyy
webkit.webprefs.default_font_size
webkit.webprefs.default_fixed_font_size
webkit.webprefs.minimum_font_size
webkit.webprefs.minimum_logical_font_size
webkit.webprefs.javascript_enabled
webkit.webprefs.javascript_can_open_windows_automatically
webkit.webprefs.loads_images_automatically
webkit.webprefs.plugins_enabled
bookmark_bar.show_on_all_tabs
bookmark_editor.expanded_nodes
profile.password_manager_enabled
profile.password_manager_allow_show_passwords
password_generation.enabled
autologin.enabled
reverse_autologin.enabled
reverse_autologin.rejected_email_list
safebrowsing.enabled
safebrowsing.reporting_enabled
safebrowsing.proceed_anyway_disabled
incognito.mode_availability
search.suggest_enabled
browser.confirm_to_quit
security.cookie_behavior
default_search_provider.synced_guid
default_search_provider.enabled
default_search_provider.search_url
default_search_provider.suggest_url
default_search_provider.instant_url
default_search_provider.icon_url
default_search_provider.encodings
default_search_provider.name
default_search_provider.keyword
default_search_provider.id
default_search_provider.prepopulate_id
default_search_provider.alternate_urls
download.prompt_for_download
alternate_error_pages.enabled
dns_prefetching.startup_list
dns_prefetching.host_referral_list
spdy.disabled
net.http_server_properties
spdy.servers
spdy.alternate_protocol
protocol.disabled_schemes
policy.url_blacklist
policy.url_whitelist
instant.animation_scale_factor
instant.confirm_dialog_shown
instant.enabled
instant.experimental_zero_suggest_url_prefix
instant.show_search_provider_logo
instant.show_white_ntp
local_state.multiple_profile_prefs_version
dns_prefetching.enabled
browser.show_home_button
profile.recently_selected_encodings
browser.clear_data.browsing_history
browser.clear_data.download_history
browser.clear_data.cache
browser.clear_data.cookies
browser.clear_data.passwords
browser.clear_data.form_data
browser.clear_data.hosted_apps_data
browser.clear_data.content_licenses
browser.clear_data.time_period
browser.enable_spellchecking
browser.enabled_labs_experiments
browser.enable_autospellcorrect
browser.speechinput_censor_results
browser.speechinput_tray_notification_shown_contexts
history.saving_disabled
extensions.theme.pack
extensions.theme.id
extensions.theme.images
extensions.theme.colors
extensions.theme.tints
extensions.theme.properties
extensions.ui.developer_mode
extensions.toolbarsize
extensions.commands
plugins.last_internal_directory
plugins.plugins_list
plugins.plugins_disabled
plugins.plugins_disabled_exceptions
plugins.plugins_enabled
plugins.enabled_internal_pdf3
plugins.enabled_nacl
plugins.migrated_to_pepper_flash
plugins.show_details
plugins.allow_outdated
plugins.always_authorize
plugins.metadata
plugins.resource_cache_update
browser.check_default_browser
browser.suppress_switch_to_metro_mode_on_set_default
browser.default_browser_setting_enabled
browser.custom_chrome_frame
browser.show_omnibox_search_hint
profile.notifications_default_content_setting
profile.notification_allowed_sites
profile.notification_denied_sites
browser.desktop_notification_position
profile.default_content_settings
profile.content_settings.clear_on_exit_migrated
profile.content_settings.pref_version
profile.content_settings.patterns
profile.content_settings.pattern_pairs
profile.content_settings.whitelist_version
profile.content_settings.plugin_whitelist
profile.block_third_party_cookies
profile.clear_site_data_on_exit
profile.default_zoom_level
profile.per_host_zoom_levels
autofill.enabled
autofill.auxiliary_profiles_enabled
autofill.positive_upload_rate
autofill.negative_upload_rate
autofill.pdm.first_run
bookmarks.editing_enabled
translate.enabled
geolocation.default_content_setting
geolocation.content_settings
import_saved_passwords
webstore.enterprise_store_url
webstore.enterprise_store_name
profile.avatar_index
profile.name
printing.enabled
printing.print_preview_disabled
profile.last_used
profile.last_active_profiles
profile.profiles_created
profile.created_by_version
profile.info_cache
ssl.rev_checking.enabled
ssl.version_min
ssl.version_max
ssl.cipher_suites.blacklist
ssl.origin_bound_certs.enabled
ssl.ssl_record_splitting.disabled
user_experience_metrics.client_id
user_experience_metrics.session_id
user_experience_metrics.low_entropy_source
user_experience_metrics.client_id_timestamp
user_experience_metrics.reporting_enabled
user_experience_metrics.initial_logs
user_experience_metrics.initial_logs_as_protobufs
user_experience_metrics.ongoing_logs
user_experience_metrics.ongoing_logs_as_protobufs
user_experience_metrics.profiles
user_experience_metrics.stability.exited_cleanly
user_experience_metrics.stability.stats_version
user_experience_metrics.stability.stats_buildtime
user_experience_metrics.stability.session_end_completed
user_experience_metrics.stability.launch_count
user_experience_metrics.stability.crash_count
user_experience_metrics.stability.incomplete_session_end_count
user_experience_metrics.stability.page_load_count
user_experience_metrics.stability.renderer_crash_count
user_experience_metrics.stability.launch_time_sec
user_experience_metrics.stability.extension_renderer_crash_count
user_experience_metrics.stability.last_timestamp_sec
user_experience_metrics.stability.plugin_stats2
user_experience_metrics.stability.renderer_hang_count
user_experience_metrics.stability.child_process_crash_count
user_experience_metrics.stability.other_user_crash_count
user_experience_metrics.stability.kernel_crash_count
user_experience_metrics.stability.system_unclean_shutdowns
user_experience_metrics.stability.breakpad_registration_ok
user_experience_metrics.stability.breakpad_registration_fail
user_experience_metrics.stability.debugger_present
user_experience_metrics.stability.debugger_not_present
uninstall_metrics.page_load_count
uninstall_metrics.launch_count
uninstall_metrics.installation_date2
uninstall_metrics.uptime_sec
uninstall_metrics.last_launch_time_sec
uninstall_metrics.last_observed_running_time_sec
browser.window_placement
task_manager.window_placement
keyword_editor.window_placement
preferences.window_placement
renderer.memory_cache.size
download.default_directory
download.directory_upgrade
savefile.default_directory
savefile.type
selectfile.last_directory
select_file_dialogs.allowed
filebrowser.tasks.default_by_mime_type
filebrowser.tasks.default_by_suffix
download.extensions_to_open
browser.hung_plugin_detect_freq
browser.plugin_message_response_timeout
spellcheck.dictionary
spellcheck.confirm_dialog_shown
spellcheck.use_spelling_service
protocol_handler.excluded_schemes
safe_browsing.client_key
safe_browsing.wrapped_key
options_window.last_tab_index
content_settings_window.last_tab_index
certificate_manager_window.last_tab_index
browser.last_known_google_url
browser.last_prompted_google_url
browser.last_redirect_origin
shutdown.type
shutdown.num_processes
shutdown.num_processes_slow
restart.last.session.on.shutdown
was.restarted
restart.switch_mode
user_experience_metrics.num_bookmarks_on_bookmark_bar
user_experience_metrics.num_folders_on_bookmark_bar
user_experience_metrics.num_bookmarks_in_other_bookmark_folder
user_experience_metrics.num_folders_in_other_bookmark_folder
user_experience_metrics.num_keywords
extensions.disabled
plugins.disable_plugin_finder
extensions.browseractions.container.width
extensions.allowed_install_sites
extensions.install.allowlist
extensions.install.denylist
extensions.alerts.initialized
extensions.install.forcelist
extensions.autoupdate.last_check
extensions.autoupdate.next_check
extensions.blacklistupdate.version
ntp.collapsed_foreign_sessions
ntp.most_visited_blacklist
ntp.promo_resource_cache_update
ntp.tips_resource_server
ntp.date_resource_server
ntp.shown_bookmarks_folder
ntp.shown_page
ntp.promo_desktop_session_found
ntp.webstore_enabled
ntp.app_page_names
ntp.game_page_names
devtools.disabled
devtools.dock_side
devtools.edited_files
devtools.split_location
devtools.open_docked
sync.last_synced_time
sync.has_setup_completed
sync.keep_everything_synced
sync.bookmarks
sync.passwords
sync.preferences
sync.app_notifications
sync.app_settings
sync.apps
sync.autofill
sync.autofill_profile
sync.themes
sync.typed_urls
sync.extensions
sync.extension_settings
sync.search_engines
sync.sessions
sync.managed
sync.suppress_start
sync.acknowledged_types
sync.max_invalidation_versions
sync.session_sync_guid
invalidator.invalidation_state
invalidator.max_invalidation_versions
sync.encryption_bootstrap_token
sync.keystore_encryption_bootstrap_token
sync.using_secondary_passphrase
google.services.username
google.services.username_pattern
sync_promo.startup_count
sync_promo.view_count
sync_promo.user_skipped
sync_promo.show_on_first_run_allowed
sync_promo.show_ntp_bubble
profile.gaia_info_update_time
profile.gaia_info_picture_url
browser.web_app.create_on_desktop
browser.web_app.create_in_apps_menu
browser.web_app.create_in_quick_launch_bar
geolocation.access_token
remote_access.host_firewall_traversal
remote_access.host_require_two_factor
remote_access.host_domain
remote_access.host_talkgadget_prefix
remote_access.host_require_curtain
printing.print_preview_sticky_settings
cloud_print.service_url
cloud_print.signin_url
cloud_print.dialog_size.width
cloud_print.dialog_size.height
cloud_print.signin_dialog_size.width
cloud_print.signin_dialog_size.height
chrome_to_mobile.device_list
background_contents.registered
browser.shown_autolaunch_infobar
auth.schemes
auth.disable_negotiate_cname_lookup
auth.enable_negotiate_port
auth.server_whitelist
auth.negotiate_delegate_whitelist
auth.gssapi_library_name
auth.spdyproxy.origin
auth.allow_cross_origin_prompt
browser.clear_lso_data_enabled
browser.pepper_flash_settings_enabled
browser.disk_cache_dir
browser.disk_cache_size
browser.media_cache_size
cros.system.releaseChannel
policy.load_cloud_policy_on_signin
cloud_print.enabled
cloud_print.proxy_id
cloud_print.auth_token
cloud_print.xmpp_auth_token
cloud_print.email
cloud_print.print_system_settings
cloud_print.enable_job_poll
cloud_print.robot_refresh_token
cloud_print.robot_email
cloud_print.connect_new_printers
cloud_print.printer_blacklist
cloud_print.submit_enabled
net.max_connections_per_proxy
profile.managed_default_content_settings.cookies
profile.managed_default_content_settings.images
profile.managed_default_content_settings.javascript
profile.managed_default_content_settings.plugins
profile.managed_default_content_settings.popups
profile.managed_default_content_settings.geolocation
profile.managed_default_content_settings.notifications
profile.managed_default_content_settings.media_stream
profile.managed_cookies_allowed_for_urls
profile.managed_cookies_blocked_for_urls
profile.managed_cookies_sessiononly_for_urls
profile.managed_images_allowed_for_urls
profile.managed_images_blocked_for_urls
profile.managed_javascript_allowed_for_urls
profile.managed_javascript_blocked_for_urls
profile.managed_plugins_allowed_for_urls
profile.managed_plugins_blocked_for_urls
profile.managed_popups_allowed_for_urls
profile.managed_popups_blocked_for_urls
profile.managed_notifications_allowed_for_urls
profile.managed_notifications_blocked_for_urls
profile.managed_auto_select_certificate_for_urls
background_mode.user_created_login_item
background_mode.user_removed_login_item
background_mode.enabled
custom_handlers.registered_protocol_handlers
custom_handlers.ignored_protocol_handlers
custom_handlers.enabled
policy.device_refresh_rate
policy.user_refresh_rate
recovery_component.version
component_updater.state
webintents.enabled
media_galleries.gallery_id
media_galleries.remembered_galleries
network_profile.warnings_left
network_profile.last_warning_time
policy.last_statistics_update
chrome.googleechotest.com
hXXp://pipelining.googleechotest.com/
allow-webui-compositing
disable-webgl
blacklist-webgl
disable-image-transport-surface
speech-service-key
disable-webaudio
disable-web-security
disable-web-sockets
enable-experimental-webkit-features
disable-web-media-player-ms
enable-privileged-webgl-extensions
enable-tcp-fastopen
enable-viewport
in-process-webgl
remote-debugging-port
renderer-cmd-prefix
testing-fixed-http-port
testing-fixed-https-port
utility-cmd-prefix
webcore-log-channels
zygote-cmd-prefix
Visual C CRT: Not enough memory to complete call to strerror.
?#%X.y
Broken pipe
Inappropriate I/O control operation
Operation not permitted
portuguese-brazilian
GetProcessWindowStation
operator
SHELL32.dll
ole32.dll
C:\quickrr\chromium\src\build\Release\chrome_exe.pdb
ShellExecuteW
SHLWAPI.dll
KERNEL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WINMM.dll
GetWindowsDirectoryW
CreateIoCompletionPort
WaitNamedPipeW
TransactNamedPipe
SetNamedPipeHandleState
GetProcessHandleCount
GetProcessHeap
GetCPInfo
CloseWindowStation
CreateWindowStationW
SetProcessWindowStation
RegQueryInfoKeyW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
PlayFreeBrowser.exe
SetActiveURL
zcÁ
bd.tvt
]"kL:%s!
C$Ö
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD0T1;2c2?3d3
8 8*8>8~8
<$<9<[<{<3 3$3(3<7
6,7074787<7
:':-:5:=:
8$8(8,8084888<8@8
9(9/94989<9]9
9&:,:0:4:8:
8.9;9[9':>:
8&9.969>9~9
3(7,7074787
> >$>8><>
? ?$?(?,?0?4?
5 5$5(5,50545
?$?,?4?<?
\\.\pipe\GoogleCrashServices\
\\.\pipe\ChromeCrashServices
error %u
hurl-chunk-%i
prn-info-%d
0.0.0.0-devel
Chrome
ChromeFrame
Software\Google\ChromeFrame
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}ChromeCanary
registering_chrome
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayFreeBrowser
hXXp://VVV.playfree.org/en/uninstall.html?utm_source=[%ORIGIN%]_[%SOURCE_SITE%]&utm_medium=uninstall
%d.%d.%d
ed-d-d
hXXp://update.playfree.org/browser/updatechecker/?
{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}{00337EA4-7B9A-44a6-B45B-B1722CD4343E}MPCBrowserUpdate.exe
CFEndTempOptOutCmd
CFOptInCmd
CFOptOutCmd
CFTempOptOutCmd
UninstallCmdLine
WebAccessible
app_host.exe
PlayFreeBrowser.dll
npchrome_frame.dll
chrome_frame_helper.exe
ChromeFrameHelperWindowClass
ChromeFrameReadyMode
chrome_launcher.exe
new_chrome.exe
old_chrome.exe
delegate_execute.exe
nacl64.exe
setup.exe
InstallerSuccessLaunchCmdLine
-chrome
-chromeframe
{5C65F4B0-3651-4514-B207-D10CB699B14B}hXXps://clients4.google.com/firefox/metrics/collect
{8BA986DA-5100-405E-AA35-86F34A02ACBF}Google Chrome Frame
Google\Chrome Frame
Chrome in a Frame.
Uninstall Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{FDA71E6F-AC4C-4a00-8B70-9958A68906BF}Google Chrome App Host
A standalone platform for Chrome apps.
.Uninstall Chrome App Host
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome App Host
debug_message.exe
debug.log
.\debug.log
Software\Microsoft\Windows\CurrentVersion\Run
\StringFileInfo\xx\%ls
ckernel32.dll
psapi.dll
Chrome_MessagePumpWindow
%s\%s.dmp
rpcrt4.dll
dbghelp.dll
x-x-x-xx-xxxxxx
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_NLSTEXT
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
pipe\
ALPC Port
cntdll.dll
s0x%X
wow_helper.exe"
00000000
333333333333333333
333333333336
%%CollationBin
NPlayFreeBrowser.exe
metro_driver.dll
Chrome_StatusTrayWindow
Chrome_MessageWindow
Reported Crashes.txt
testing_interface.dll
Certificate Revocation Lists
Custom Dictionary.txt
Login Data
Origin Bound Certs
Cached Theme.pak
Web Applications
Web Data
pepflashplayer.dll
CHROME_METRO_NAV_SEARCH_REQUEST
CHROME_METRO_GET_CURRENT_TAB_INFO
mscoree.dll
ADVAPI32.DLL
nKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe
3.0.0.4
chrome_exe
PlayFreeBrowser.exe_3740_rwx_1CF0A000_00060000:
%X!?Z
j.hmO
PVh%s
Ph%C"?
PlayFreeBrowser.exe_992_rwx_0730A000_00060000:
%X15Z
j.hmO
=WWW.
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
GoogleUpdate.exe:1652
GoogleUpdate.exe:3992
GoogleUpdate.exe:2400
PlayFreeBrowser.exe:3128
PlayFreeBrowser.exe:556
PlayFreeBrowser.exe:3036
PlayFreeBrowser.exe:3100
PlayFreeBrowser.exe:3708
PlayFreeBrowser.exe:2056
PlayFreeBrowser.exe:3136
PlayFreeBrowser.exe:3120
PlayFreeBrowser.exe:2900
PlayFreeBrowser.exe:1688
PlayFreeBrowser.exe:1884
PlayFreeBrowser.exe:3080
42.0.2311.135_chrome_installer.exe:3312
%original file name%.exe:2636
taskeng.exe:3936
taskeng.exe:3464
MPCBrowserUpdater.exe:1108
MPCBrowserCrashHandler.exe:3684
setup.exe:272
setup.exe:2056
MPCBrowserUpdate.exe:1128
MPCBrowserUpdate.exe:3788
MPCBrowserUpdate.exe:1860
MPCBrowserUpdate.exe:1500
MPCBrowserUpdate.exe:1872
MPCBrowserUpdate.exe:1116
MPCBrowserUpdate.exe:3724
MPCBrowserUpdate.exe:1760
MPCBrowserUpdate.exe:3188
MPCBrowserUpdate.exe:1448 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Program Files% (x86)\Google\Update\Install\{09D3F8A5-EB89-4712-A03A-55808701600F}\42.0.2311.135_chrome_installer.exe (336195 bytes)
%Program Files% (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\42.0.2311.135\42.0.2311.135_chrome_installer.exe (317324 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\pdfHandler-local.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\en-US\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-comment.svg (860 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\patch-worker.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\findbarButton-previous.png (371 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-help.svg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-viewThumbnail.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\DECODED_IMAGES (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\tr\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\viewer.js (7784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\pt-BR\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\da\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-newparagraph.svg (403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ru\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon128.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\viewer.html (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\l10n.js (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-paragraph.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon16.png (726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-menuArrows.png (237 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-note.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\vi\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-pageDown.png (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\viewer.css (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-bookmark.png (244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-download.png (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ko\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-presentationMode.png (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\findbarButton-next.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\zh-TW\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\fi\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-pageDown-rtl.png (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\pdfHandler.html (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\hide-xhtml-error.css (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\findbarButton-previous-rtl.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-pageUp.png (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\loading-icon.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\insertviewer.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\shadow.png (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-insert.svg (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-zoomOut.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ja\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\pdfHandler.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\es\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\fr\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\zh-CN\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\findbarButton-next-rtl.png (371 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\sr\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-openFile.png (417 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-pageUp-rtl.png (426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\pl\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\sv\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\lt\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\loading-small.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\cs\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ro\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-search.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-check.svg (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\he\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-viewOutline.png (300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\manifest.json (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\icon48.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-sidebarToggle.png (349 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ar\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-print.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\build\pdf.js (84591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\nl\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\de\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\debugger.js (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\it\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\toolbarButton-zoomIn.png (228 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\locale\ca\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\texture.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\DECODED_MESSAGE_CATALOGS (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\CRX_INSTALL\content\web\images\annotation-key.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\libglesv2.dll (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\viewer.js (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cookies (1858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\findbarButton-previous.png (371 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\images\login_button_fb.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\fsdata\logo_A.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-insert.svg (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Favicons (2040 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-comment.svg (860 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-download.png (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2170.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\scopes\scope_settings.xml (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\icon16.png (663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\000002.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-pageDown.png (353 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\AF0E.tmp (38551 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ko\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\_locales\en\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\NPSWF32_11_8_800_94.dll (122455 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5473Q0TAYPRDFX6NRM7H.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\game.exe (162302 bytes)
C:\Users\"%CurrentUserName%"\Downloads\farm_frenzy-lp_en.zip:Zone.Identifier (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\json2.js (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\loading-icon.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\CRX_INSTALL\manifest.json (445 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\html\pf_share.zip (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-viewOutline.png (300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\logo_login.png (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\MANIFEST-000002 (69 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2F0E.tmp (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\[clone9900] widget.iml (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History Index 2015-05-journal (15684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\jquery-1.7.2.min.js (1202 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\GRC.crx (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\sr\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-key.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\facebook.crx (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\pdfHandler.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_ToOd9BrbTNRlHTg (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\000F7F8FAB2D96E6F8CBD5C9A3B4EC90 (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\_locales\en\messages.json (481 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PQ2990XBF0WREJ1BPPTU.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\_locales\ru\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-newparagraph.svg (403 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\index (368 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Download_new (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9XN2GUMRF2E7XT4U8AO8.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2F2E.tmp (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-viewThumbnail.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\styles\style.css (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\twitter_ON.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Squall.dll (31584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\LOG (46 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon19.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ar\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\all.js (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\findbarButton-next.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\000001.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\icon128.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\FlashPlayer.crx (59260 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\es\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\de\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\patch-worker.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\WIA9QC2H6UG4IKTT8PJK.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\twitter_OFF.png (674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1C66.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\popup.js (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2EED.tmp (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\20A3.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CRX_75DAF8CB7768\manifest.json (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\modules.xml (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\pl\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\CRX_INSTALL\manifest.json (429 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\facebook_OFF.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Bookmarks.bak (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\login_button_tw.png (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Local Storage\chrome-extension_gjogodjmdfhjnoemjocfpcoddjgnjilo_0.localstorage (154 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\data_2 (1208 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RD91OO4GHMTH46CIP39P.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\data_0 (274556 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\data_1 (56088 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ru\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cookies-journal (11033 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\twitter_OFF.png (674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-check.svg (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\4437.tmp (298 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-pageDown-rtl.png (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\website.url (249 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\000002.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\33A2.tmp (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\scopes\scope_settings.xml (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\manifest.json (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon19_1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\encodings.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\it\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\share.crx (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\build\pdf.js (9605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Visited Links (376 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\images\loader.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1EOBDSCXEHINOCPLF9UO.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ja\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\back.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\User StyleSheets\Custom.css (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\workspace.xml (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\findbarButton-next-rtl.png (371 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\f_000001 (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1C46.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\f_000003 (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\styles\style.css (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\LOG (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Top Sites (1952 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\f_000002 (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ro\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\2DB0.tmp (317 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\lt\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\ml.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Favicons-journal (18810 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Certificate Revocation Lists (197 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Login Data (734 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\findbarButton-previous-rtl.png (381 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\4024.tmp (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\popup.htm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon128.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-zoomIn.png (228 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\script.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PlayFree Browser.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\styles\reset.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon16.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\_locales\en\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\zh-TW\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\GRC.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PL0GYJBHX4X0M5T5SKO2.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\manifest.json (875 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\vcs.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5X4OGA8088NXTMJ22A2U.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\shadow.png (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-zoomOut.png (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\en.pack (52424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-menuArrows.png (237 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\workspace.xml (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\texture.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\vcs.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\login_button_fb.png (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\images\logo_login.png (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\_locales\en\messages.json (567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\manifest.json (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-pageUp.png (344 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-openFile.png (417 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2090.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\modules.xml (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\pt-BR\viewer.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\gl.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\contentscript_tw.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\l10n.js (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CRX_75DAF8CB7768\crl-set (12984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Shortcuts (304 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Web Data-journal (2898 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\scripts\popup.js (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Bloom Prefix Set (2196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_R3BJM8AkQLyOEoA (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-help.svg (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\_locales\en\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\facebook_OFF.png (653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\icon48.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\D723.tmp (317 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\styles\reset.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2EFE.tmp (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\locale.properties (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\debugger.js (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Current Tabs (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\fsdata\splash2.jpg (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\README (186 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\icon48.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-search.png (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\[clone9900] widget.iml (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\background.html (300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2DD0.tmp (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\zh-CN\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\47A1.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\popup.htm (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\5AB5.tmp (37 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Shortcuts-journal (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\MANIFEST-000001 (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Cookies-journal (2799 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Current Session (15183 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\cs\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\play.exe (58761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\_locales\ru\messages.json (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-pageUp-rtl.png (426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Login Data-journal (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_ckRoEQSaVK0G9OY (1644 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\A095.tmp (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\207F.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-bookmark.png (244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\facebook_ON.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\twitter.crx (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\game_icon.ico (392 bytes)
C:\Users\"%CurrentUserName%"\Desktop\Farm Frenzy.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\fsdata\logo_A.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\nl\viewer.properties (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DL50Z2U4JW7VRFSDMC25.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5NGZE6LEMNPGDMUSSE07.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\scripts\json2.js (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-presentationMode.png (491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\fi\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\vi\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\_locales\ru\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2141.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\fsdata\logo_NA.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_23680\pdfjs.crx (3361 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-sidebarToggle.png (349 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Preferences (521 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\data_3 (9112 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\main_share.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\JNGLoad.dll (25080 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\J4MOJVAMIWNH8CXGP7H1.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_FKtUz2u0dw8ZMH3 (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\.idea\misc.xml (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\scripts\jquery-1.7.2.min.js (601 bytes)
C:\Users\"%CurrentUserName%"\Desktop\PlayFree Browser.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\Downloads\favicon.ico:Zone.Identifier (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\hide-xhtml-error.css (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\manifest.json (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\contentscript.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\viewer.css (33 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\fsdata\splash2.jpg (5952 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\data.pack (971334 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Cache\f_000004 (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\tw.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History-journal (15448 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\pdfHandler-local.js (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\sv\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\2E9E.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\Data\fsdata\logo_NA.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MYZUQOY8LK28EWMSZ2PR.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\toolbarButton-print.png (474 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\tr\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1D34.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2091.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Top Sites-journal (6616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\ZeroClipboard.swf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\he\viewer.properties (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Bloom_new (345668 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\fb.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\en-US\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Local Storage\chrome-extension_gjogodjmdfhjnoemjocfpcoddjgnjilo_0.localstorage-journal (5109 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\background.html (139 bytes)
C:\Users\"%CurrentUserName%"\Downloads\Unconfirmed 761892.crdownload (669378 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\loading-small.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Download Whitelist_new (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\20A2.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\fb_logined.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Safe Browsing Csd Whitelist_new (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\loader.gif (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\fr\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\pdfHandler.html (666 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extensions\cmgompiogmpngbepkhaildjbcedihobe\2_0\GRC.dll (114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2130.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\Downloads\2B33.tmp (9586 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\1D14.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\body_bg.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extensions\kmafafaebkfagbfockogghbkjblelpbh\2_0\NPSWF32_11_8_800_94.dll (5823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\da\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\scripts\ZeroClipboard.min.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\000003.log (6147 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\encodings.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\First Run (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\contentscript_fb.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\_locales\ru\messages.json (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\.idea\misc.xml (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\insertviewer.js (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-paragraph.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\scripts\back.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Session Storage\000001.dbtmp (20 bytes)
C:\Users\"%CurrentUserName%"\Downloads\21EF.tmp (1651 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Games\farm_frenzy-lp_en\play.url (259 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\_locales\ru\messages.json (853 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18354\CRX_INSTALL\images\button_bg.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2XVWUNFBGLPKPOFZB0I7.temp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\images\annotation-note.svg (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\locale\ca\viewer.properties (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1CB5.tmp (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\000F7F8FAB2D96E6F8CBD5C9A3B4EC90 (784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18357\CRX_INSTALL\content\web\viewer.html (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\main_share.png (546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_sIpd8OdgdEGRWUc (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Temp\scoped_dir_2492_18351\CRX_INSTALL\images\login_button_tw.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\MANIFEST-000001 (41 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Extension State\MANIFEST-000002 (69 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\CRX_INSTALL\NPSWF32_11_8_800_94.dll (1038046 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\DECODED_MESSAGE_CATALOGS (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_17246\DECODED_IMAGES (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\DECODED_MESSAGE_CATALOGS (24 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\DECODED_IMAGES (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_18344\CRX_INSTALL\GRC.dll (7784 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\modules.xml (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\DECODED_IMAGES (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\popup.htm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\vcs.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\encodings.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\scopes\scope_settings.xml (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\scripts\back.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\fb_logined.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images\login_button_fb.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\[clone9900] widget.iml (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\scripts\popup.js (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\scripts\jquery-1.7.2.min.js (6984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images\logo_login.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\styles\style.css (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images\loader.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\facebook_ON.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\scripts\json2.js (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\images\login_button_tw.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\DECODED_MESSAGE_CATALOGS (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\styles\reset.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\contentscript_fb.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\background.html (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\misc.xml (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_1501\CRX_INSTALL\.idea\workspace.xml (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\DECODED_MESSAGE_CATALOGS (222 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\styles\style.css (858 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\scripts\jquery-1.7.2.min.js (6984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\scripts\back.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images\loader.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\DECODED_IMAGES (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images\login_button_tw.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\popup.htm (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\modules.xml (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images\login_button_fb.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\styles\reset.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\background.html (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\vcs.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\misc.xml (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\scripts\popup.js (938 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\workspace.xml (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\scopes\scope_settings.xml (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\contentscript_tw.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\twitter_ON.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\encodings.xml (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\.idea\[clone9900] widget.iml (283 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\scripts\json2.js (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_30389\CRX_INSTALL\images\logo_login.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\16C2.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1584.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\15F4.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_zJj6ftdxrva1cUX (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_wgLkRtD2zydu15D (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\14C8.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\16B2.tmp (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History Index 2015-04-journal (15480 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_VbhUrA3oYtzthvc (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\16C3.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\icudt.dll (437 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\16B1.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1498.tmp (463 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_fhZAxJ0OtwgLlzb (3636 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_oqh3IwbKNHmnt6N (536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\1595.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\History Provider Cache (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_Q2PnK9yoBhE4IbV (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Archived History-journal (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\playfreebrowser.dll (5823 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\Default\Network Action Predictor-journal (1690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\User Data\1604.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\jquery-1.7.2.min.js (6984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\ml.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\popup.htm (910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\login_button_tw.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\button_bg.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\all.js (11736 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\login_button_fb.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\contentscript.js (291 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\background.html (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon48.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon19.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\DECODED_IMAGES (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\json2.js (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\fb.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon19_1.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\tw.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\html\pf_share.zip (2696 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\styles\style.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\gl.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\back.js (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\ZeroClipboard.min.js (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\loader.gif (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\popup.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\body_bg.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon16.png (849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\icon128.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\images\logo_login.png (392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\script.js (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\CRX_INSTALL\scripts\ZeroClipboard.swf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scoped_dir_2492_20656\DECODED_MESSAGE_CATALOGS (1 bytes)
C:\Windows\Temp\CR_6C700.tmp\SETUP.EX_ (348 bytes)
C:\Windows\Temp\CR_6C700.tmp\setup.exe (18111 bytes)
C:\Windows\Temp\CR_6C700.tmp\CHROME.PACKED.7Z (45884 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\gameinfo[1].json (370 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\deedb4313c88b71db702d48308355009\EULA.txt (9084 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\deedb4313c88b71db702d48308355009\InstallLog_deedb4313c88b71db702d48308355009.txt (460558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\deedb4313c88b71db702d48308355009\PlayFreeBrowser_EULA.txt (9084 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GamePic.jpg (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\783GTYVS\customization[1].json (5576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\GUID (647 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\icon.png (980 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\3.0.0.4\setup.exe (10145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\3.0.0.4\MPCBrowserUpdater.exe (4670 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pf.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\{2F0B3EEC-E5EE-47c1-829C-ADE0D31F2DFC}\3.0.0.4\chrome.packed.7z (254922 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\Download\VERSION (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\master_preferences (521 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_te.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_bn.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_es-419.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ml.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_pt-PT.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_bg.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_zh-CN.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_id.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUTFF74.tmp (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_uk.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_mr.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_en-GB.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_th.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ur.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserUpdateOnDemand.exe (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserUpdateHelper.msi (45 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sv.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdate.dll (1702 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sk.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_hi.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_pl.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserCrashHandler.exe (120 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_fr.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_lt.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_vi.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\npGoogleUpdate3.dll (230 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\psuser.dll (162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_fil.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_da.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_hr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_is.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ro.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ru.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_zh-TW.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_nl.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ta.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_it.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_fa.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ja.dll (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_gu.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_kn.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_am.dll (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_hu.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserUpdateBroker.exe (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_cs.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ko.dll (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_en.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_fi.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_et.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_lv.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\psmachine.dll (162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\MPCBrowserUpdate.exe (242 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_iw.dll (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sw.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_es.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_de.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_no.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ms.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_sl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_tr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_pt-BR.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ar.dll (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_ca.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\GUMFF73.tmp\goopdateres_el.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\th.pak (324 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl_ipc_irt_x86_32.nexe (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\et.pak (160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\3.0.0.4\Installer\setup.exe (10864 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fa.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_frame_helper.exe (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\tr.pak (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\el.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\bg.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\et.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fil.pak (181 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fi.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\en-GB.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sk.pak (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\it.pak (174 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\delegate_execute.exe (939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ru.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlayFree Browser\PlayFree Browser.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ml.pak (414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\am.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\npchrome_frame.dll (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\te.pak (357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ar.pak (229 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\VisualElements\logo.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\uk.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sw.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_touch_100_percent.pak (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fa.pak (234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sv.pak (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\de.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\secondarytile.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hi.pak (328 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\GRC_PLUGIN.crx (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\VisualElements\smalllogo.png (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ar.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl64.exe (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\da.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fi.pak (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sl.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pt-BR.pak (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\icudt.dll (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_launcher.exe (80 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hu.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\bg.pak (273 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\VisualElementsManifest.xml (384 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\lt.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ru.pak (260 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\am.pak (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sr.pak (253 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\es.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ko.pak (181 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\share.crx (218 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sl.pak (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ca.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\lv.pak (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\mr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl_ipc_irt_x86_64.nexe (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ja.pak (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\wow_helper.exe (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\external_extensions.json (661 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\te.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ml.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\nl.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\tr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ro.pak (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\resources.pak (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\playfreebrowser.dll (64956 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ms.pak (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sv.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sk.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\gu.pak (319 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\th.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\es-419.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\bn.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\kn.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\nb.pak (165 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hu.pak (184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ca.pak (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\mr.pak (321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\lv.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\chrome.7z (188259 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\en-GB.pak (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\el.pak (298 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ms.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pt-PT.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\vi.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ta.pak (374 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\zh-CN.pak (151 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ko.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\lt.pak (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\chrome_installer.log (1539 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\VisualElements\splash-620x300.png (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl_irt_x86_64.nexe (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\zh-TW.pak (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\playfreebrowser.exe (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\vi.pak (195 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\he.pak (195 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pl.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\metro_driver.dll (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\FlashPlayer.crx (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PlayFree Browser.lnk (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\es-419.pak (178 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\libglesv2.dll (720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\en-US.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\gu.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\nl.pak (172 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\libegl.dll (130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hi.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\he.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\nb.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\de.pak (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\twitter.crx (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\en-US.pak (153 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\it.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pt-PT.pak (176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\app_host.exe (239 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\cs.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\ppgooglenaclpluginchrome.dll (574 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pt-BR.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\da.pak (164 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ro.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\kn.pak (364 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fil.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\cs.pak (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\hr.pak (170 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\es.pak (182 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\GRC.crx (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\id.pak (161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\facebook.crx (93 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\id.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ta.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\uk.pak (261 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\ja.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Extensions\pdfjs.crx (555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlayFree Browser\Uninstall PlayFree Browser.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\zh-CN.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_frame_helper.dll (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sr.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\sw.pak (156 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\fr.pak (187 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\pl.pak (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe (8330 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\nacl_irt_x86_32.nexe (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\chrome_100_percent.pak (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\zh-TW.dll (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Temp\source\Chrome-bin\3.0.0.4\Locales\bn.pak (332 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\tr.pak (596 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\fil.pak (611 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\VisualElements\smalllogo.png (21 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\d3dcompiler_47.dll (52 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\fr.pak (637 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\te.pak (1339 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\fi.pak (564 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\search.crx (54 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\secondarytile.png (641 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\kn.pak (1372 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ro.pak (611 bytes)
%Program Files% (x86)\Google\Chrome\Application\35.0.1916.114\default_apps (4 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\VisualElementsManifest.xml (403 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ko.pak (610 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sk.pak (621 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_elf.dll (268 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\hu.pak (635 bytes)
%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\chrmstp.exe (22090 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\PepperFlash\pepflashplayer.dll (63 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\uk.pak (932 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\pt-BR.pak (579 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\es-419.pak (602 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_watcher.dll (692 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\vi.pak (685 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sv.pak (553 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\gu.pak (1193 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\snapshot_blob.bin (1397 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ms.pak (456 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\widevinecdmadapter.dll (381 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\nacl64.exe (51 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\es.pak (612 bytes)
%Program Files% (x86)\Google\Chrome\Application\35.0.1916.114\Locales (8 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ru.pak (930 bytes)
%Program Files% (x86)\Google\Chrome\Application\chrome.exe (16874 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_200_percent.pak (50 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\drive.crx (53 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\nb.pak (545 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ml.pak (1570 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\docs.crx (12 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk (6 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sw.pak (505 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Extensions\external_extensions.json (103 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\nacl_irt_x86_64.nexe (52 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\42.0.2311.135.manifest (228 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\nacl_irt_x86_32.nexe (51 bytes)
C:\Windows\Temp\chrome_installer.log (129 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\youtube.crx (47 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\bg.pak (995 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\chrome.7z (259253 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\en-US.pak (498 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\icudtl.dat (59 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\da.pak (545 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\lt.pak (594 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\xinput1_3.dll (162 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\en-GB.pak (498 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ja.pak (720 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome.dll (27081 bytes)
%Program Files% (x86)\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe (22090 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\libglesv2.dll (50 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\et.pak (529 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\he.pak (692 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\natives_blob.bin (825 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\VisualElements\logo.png (7 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\mr.pak (1211 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\cs.pak (602 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\wow_helper.exe (146 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\nl.pak (579 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\libegl.dll (161 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ta.pak (1432 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\el.pak (1086 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\ffmpegsumo.dll (50 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sr.pak (907 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\delegate_execute.exe (1405 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\fa.pak (857 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_child.dll (41165 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\pl.pak (595 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\zh-TW.pak (489 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\de.pak (522 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\hi.pak (1232 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\sl.pak (554 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\external_extensions.json (5 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\zh-CN.pak (488 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\th.pak (1208 bytes)
C:\Users\Public\Desktop\Google Chrome.lnk (6 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\hr.pak (561 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\chrome.exe (1627 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\am.pak (826 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\id.pak (539 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\resources.pak (65 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\libexif.dll (621 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\lv.pak (604 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\bn.pak (1267 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\VisualElements\splash-620x300.png (22 bytes)
%Program Files% (x86)\Google\Chrome\Application\35.0.1916.114\VisualElements (4 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\PepperFlash\manifest.json (6 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ca.pak (603 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\it.pak (587 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\ar.pak (799 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\default_apps\gmail.crx (48 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\metro_driver.dll (955 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\chrome_100_percent.pak (50 bytes)
%Program Files% (x86)\Google\Chrome\Temp\source2056_23704\Chrome-bin\42.0.2311.135\Locales\pt-PT.pak (594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psuser.dll (163 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdate.dll (790 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_en.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ta.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\MPCBrowserUpdate.exe (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_no.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_th.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_et.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_is.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateOnDemand.exe (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_es.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sk.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_da.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_lt.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_nl.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_gu.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_cs.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_id.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_te.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pl.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserCrashHandler.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_am.dll (26 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_zh-TW.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateBroker.exe (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_de.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_iw.dll (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sv.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdateHelper.msi (45 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ur.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ar.dll (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ca.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hi.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fi.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hr.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pt-BR.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ms.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_hu.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fa.dll (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_lv.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_bn.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ru.dll (29 bytes)
C:\Windows\Tasks\MPCBrowserUpdateTaskUserS-1-5-21-2858020935-2156992550-3658131804-1003UA.job (940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sl.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_en-GB.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_tr.dll (30 bytes)
C:\Windows\Tasks\MPCBrowserUpdateTaskUserS-1-5-21-2858020935-2156992550-3658131804-1003Core.job (888 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_es-419.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fr.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ml.dll (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_fil.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\psmachine.dll (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\npGoogleUpdate3.dll (1514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ja.dll (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_bg.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_kn.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_mr.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_pt-PT.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_it.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_zh-CN.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_sw.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ro.dll (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_ko.dll (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\MPCBrowserUpdate.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_uk.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_vi.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\1.3.27.0\goopdateres_el.dll (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 (656 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarCEC.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabCEB.tmp (48 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"BrowserUid" = "C:\Users\"%CurrentUserName%"\AppData\Local\PlayFree Browser\Application\PlayFreeBrowser.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"MPCBrowser Update" = "C:\Users\"%CurrentUserName%"\AppData\Local\MPCBrowser\Update\MPCBrowserUpdate.exe /c" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.