Win32.Sality.3_3061facc81
Win32.Sality.3 (B) (Emsisoft), Win32.Sality.3 (AdAware), Trojan.Win32.Swrort.3.FD, Virus.Win32.Sality.FD, Virus.Win32.Sality.2.FD, VirusSality.YR, GenericAutorunWorm.YR, GenericInjector.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, Virus, WormAutorun
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 3061facc81ecc43bcb9976ef9cf4afc4
SHA1: a50f046db38ea844bea9f5a1101976eff271e9c1
SHA256: 445977f5c02270dcb522406b7311230d8f58015dda378b9024fa4e33baf7e07c
SSDeep: 6144:O Yg7hxLYEfuLjTnwkpbLM9ou1ah570ahpG4oSQtt6/KqedNV2aYK0ZJGc:OqYeajpvY4ouVoSQYnqNVTD8/
Size: 445792 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2014-11-18 11:36:00
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
| Behaviour | Description |
|---|---|
| WormAutorun | A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer. |
Process activity
The Trojan creates the following process(es):
No processes have been created.
The Trojan injects its code into the following process(es):
%original file name%.exe:176
Explorer.EXE:1684
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:176 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\1467b-753f8[1].js (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\moatad[1].js (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@softonic[2].txt (1849 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\ads.min[1].js (1709 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2d9b4-b586d[1].css (147 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[4].jpg (518 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@softonic[1].txt (2313 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\427b6-dd89a[1].js (421 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6d482-41450[1].js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\17ad7-e5cc5[1].js (403 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\pubads_impl_65[1].js (2144 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\universaldownloader-prefetch[1].htm (1525 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\measure.min[1].js (10 bytes)
C:\ermq.pif (103 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\CAILYHON.1435517394&ga_sid=1435517394&ga_hid=48384997&ga_wpids=UA-43493347-1 (8 bytes)
%Program Files%\Adobe\Reader 9.0\Reader\Reader_sl.exe (432 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (23040 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bid[1].com/35586/universaldownloader-prefetch&cb=9268520 (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\f[1].txt (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\adsense[2].js (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\hshegy.exe (741 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\textlink-ads[2].jpg (518 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\b5ae7-7a102[1].css (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\moatad[2].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\f[1].txt (7552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\px[1].js (346 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bid[1].com/35586/universaldownloader-prefetch&cb=6252925 (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\741c2-5ad42[1].js (4243 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\textlink-ads[1].jpg (518 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\OpenSans-CondBold-webfont[1].eot (907 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\font-icon[1].eot (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\universaldownloader-prefetch[1].htm (1525 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\font-icon[1].eot (8 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@doubleclick[1].txt (445 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\interface_sprite[1].png (5453 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\f[1].txt (5559 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\container[1].html (622 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[1].txt (207 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\universaldownloader-prefetch[1].htm (1525 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\4cd46-f5ea2[1].js (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\moatad[3].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\f[2].txt (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\icons_sprite[1].png (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\OpenSans-CondLight-webfont[1].eot (973 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\f[2].txt (776 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pagefair[1].txt (135 bytes)
%WinDir%\system.ini (72 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\OpenSans-CondBold-webfont[1].eot (907 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\f[3].txt (2873 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@revsci[2].txt (373 bytes)
C:\autorun.inf (250 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\ads.min[1].js (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gtm[1].js (2231 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\analytics[1].js (740 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\404[1].png (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\amzn_ads[1].js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\icons_sprite_ie6[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\container[1].htm (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\OpenSans-CondBold-webfont[1].eot (1357 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\font-icon[1].eot (8 bytes)
%Program Files%\Common Files\Java\Java Update\jusched.exe (856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\px[1].js (346 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\CASXEBKX.1435517394&ga_sid=1435517398&ga_hid=365457603&ga_wpids=UA-43493347-1 (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\f[2].txt (3300 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\CAKV81OB.1435517394&ga_sid=1435517394&ga_hid=48384997&ga_wpids=UA-43493347-1 (328 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\beacon[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\adsense[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pagefair[2].txt (276 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\OpenSans-CondLight-webfont[1].eot (973 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\adsense[3].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\measure.min[1].js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\universaldownloader-prefetch[2].htm (1525 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\f[1].txt (2158 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[3].jpg (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\a[1].js (46 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\font-icon[1].eot (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\90f12-4e468[1].css (4423 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (3557 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\10496[1].js (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\amzn_ads[2].js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\moatad[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (3011 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\f[2].txt (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\40c2e-79a51[1].js (6237 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\OpenSans-CondLight-webfont[1].eot (1465 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[1].jpg (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[2].jpg (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\adsense[1].js (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\moatad[2].js (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@doubleclick[2].txt (433 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bid[1].com/35586/universaldownloader-prefetch&cb=3747179 (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\softonic-logo-inline[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\7c7aa-ad7c7[1].js (807 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bid[1].com/35586/universaldownloader-prefetch&cb=4126714 (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\10496[1].js (7 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@revsci[1].txt (373 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[2].txt (370 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\f[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\adsense[2].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\OpenSans-CondBold-webfont[1].eot (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\moatad[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\f[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@softonic[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\ads.min[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\f[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[3].jpg (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@doubleclick[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[4].jpg (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@softonic[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\OpenSans-CondBold-webfont[1].eot (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\amzn_ads[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\hshegy.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\font-icon[1].eot (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@doubleclick[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\OpenSans-CondLight-webfont[1].eot (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[1].jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\OpenSans-CondBold-webfont[1].eot (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[2].jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\adsense[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\measure.min[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\font-icon[1].eot (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\f[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\adsense[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\OpenSans-CondLight-webfont[1].eot (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\f[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\font-icon[1].eot (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\10496[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@revsci[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pagefair[1].txt (0 bytes)
Registry activity
The process %original file name%.exe:176 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Aas]
"a4_440" = "3154413240"
"a2_348" = "2494845651"
"a2_349" = "2502017467"
"a2_346" = "2480517349"
"a2_347" = "2487687730"
"a2_344" = "2466183422"
"a2_345" = "2473351687"
"a2_342" = "2451834355"
"a2_343" = "2459002272"
"a2_340" = "2437509466"
"a2_341" = "2444667749"
"a2_180" = "1290439683"
"a2_181" = "1297605065"
"a2_182" = "1304774289"
"a2_183" = "1311957626"
"a2_184" = "1319123401"
"a2_185" = "1326289006"
"a2_186" = "1333457973"
"a2_187" = "1340624325"
"a2_188" = "1347792634"
"a2_189" = "1354957930"
"a4_444" = "3183089724"
[HKLM\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = "1"
[HKCU\Software\Aas]
"a3_78" = "542637991"
"a3_79" = "549622726"
"a3_72" = "533156193"
"a3_73" = "506656128"
"a3_70" = "485103791"
"a3_71" = "525712590"
"a3_76" = "561686245"
"a3_77" = "568613636"
"a3_74" = "513568291"
"a3_75" = "554631746"
"a3_259" = "1873798154"
"a3_258" = "1866220523"
"a1_435" = "3461472623"
"a1_434" = "282818383"
"a1_433" = "3079543768"
"a1_432" = "3263911918"
"a1_431" = "3490283265"
"a1_430" = "2294832208"
"a3_251" = "1782710578"
"a3_250" = "1809280147"
"a3_253" = "1830771188"
"a3_252" = "1789764949"
"a3_255" = "1844811446"
"a3_254" = "1837822487"
"a3_257" = "1825746760"
"a3_256" = "1818692393"
"a3_449" = "3202245640"
"a3_321" = "2284435336"
"a3_320" = "2310935401"
"a3_323" = "2332478538"
"a3_322" = "2291869739"
"a3_325" = "2346910988"
"a3_324" = "2339397869"
"a3_327" = "2327338446"
"a3_326" = "2320415151"
"a3_329" = "2375379584"
"a3_328" = "2368468577"
"a3_439" = "3130280062"
"a3_438" = "3123369951"
"a3_435" = "3101883130"
"a3_434" = "3094824539"
"a3_437" = "3149870012"
"a3_436" = "3142426397"
"a3_431" = "3106444646"
"a3_430" = "3065901255"
"a3_433" = "3087376952"
"a3_432" = "3113879961"
"a3_94" = "690598327"
"a3_95" = "698045910"
"a3_96" = "671534665"
"a3_97" = "678453992"
"a3_90" = "662052915"
"a3_91" = "669107282"
"a3_92" = "643004661"
"a3_93" = "649993492"
"a3_98" = "685967115"
"a3_99" = "726580138"
[HKLM\SOFTWARE\Microsoft\Security Center]
"FirewallOverride" = "1"
[HKCU\Software\Aas]
"a4_151" = "1082537271"
"a4_150" = "1075368150"
"a4_153" = "1096875513"
"a4_152" = "1089706392"
"a4_155" = "1111213755"
"a4_154" = "1104044634"
"a4_157" = "1125551997"
"a4_156" = "1118382876"
"a4_159" = "1139890239"
"a4_158" = "1132721118"
"a1_185" = "981359671"
"a1_184" = "374213500"
"a1_183" = "4282001412"
"a1_182" = "2037610566"
"a1_181" = "3764497990"
"a1_180" = "1154407818"
"a4_393" = "2817464553"
"a4_392" = "2810295432"
"a4_391" = "2803126311"
"a4_390" = "2795957190"
"a4_397" = "2846141037"
"a4_396" = "2838971916"
"a4_395" = "2831802795"
"a4_394" = "2824633674"
"a4_399" = "2860479279"
"a4_398" = "2853310158"
"a2_405" = "2903496898"
"a2_404" = "2896327067"
"a2_407" = "2917830088"
"a2_406" = "2910661693"
"a2_401" = "2874810595"
"a2_400" = "2867646445"
"a2_403" = "2889159247"
"a2_402" = "2881979017"
"a2_409" = "2932162677"
"a2_408" = "2924996134"
"a1_222" = "3351658835"
"a1_223" = "242272193"
"a1_220" = "2133550305"
"a1_221" = "130579584"
"a1_226" = "959515241"
"a1_227" = "1948634449"
"a1_224" = "375780754"
"a1_225" = "2381410098"
"a1_228" = "1212569302"
"a1_229" = "1273322670"
"a2_351" = "2516369088"
"a2_350" = "2509187053"
"a2_353" = "2530701774"
"a2_352" = "2523535011"
"a2_355" = "2545036304"
"a2_354" = "2537876501"
"a2_357" = "2559372847"
"a2_356" = "2552204571"
"a2_359" = "2573721387"
"a2_358" = "2566552172"
"a2_193" = "1383642390"
"a2_192" = "1376474768"
"a2_191" = "1369307581"
"a2_190" = "1362124943"
"a2_197" = "1412340062"
"a2_196" = "1405156011"
"a2_195" = "1397976079"
"a2_194" = "1390807135"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Aas]
"a2_199" = "1426657326"
"a2_198" = "1419492816"
"a1_89" = "732400340"
"a1_88" = "924143861"
"a1_85" = "3361139936"
"a1_84" = "1359834730"
"a1_87" = "3725792583"
"a1_86" = "1045317156"
"a1_81" = "4149595658"
"a1_80" = "1629949159"
"a1_83" = "1677607369"
"a1_82" = "3739052055"
"a1_67" = "3297352204"
"a1_66" = "1578503639"
"a1_65" = "3253642190"
"a3_133" = "970345548"
"a1_63" = "89542536"
"a3_135" = "950830350"
"a3_136" = "991836577"
"a1_60" = "3555177334"
"a3_138" = "1006335587"
"a3_139" = "979823234"
"a1_438" = "490685503"
"a1_69" = "1071673171"
"a1_68" = "3154112782"
"a3_228" = "1617824845"
"a3_229" = "1624875244"
"a3_224" = "1588903625"
"a3_225" = "1629901672"
"a3_226" = "1636956043"
"a3_227" = "1610836010"
"a3_220" = "1593911669"
"a3_221" = "1600966036"
"a3_222" = "1608410679"
"a3_223" = "1581849174"
"a1_408" = "4190967484"
"a1_409" = "3170277548"
"a1_402" = "3195528681"
"a1_403" = "1697525738"
"a1_400" = "4136877513"
"a1_401" = "680901179"
"a1_406" = "983568783"
"a1_407" = "1884470404"
"a1_404" = "2062619513"
"a1_405" = "2806918936"
"a3_354" = "2521277451"
"a3_355" = "2528204970"
"a3_356" = "2568813773"
"a3_357" = "2576322924"
"a3_350" = "2492225207"
"a3_351" = "2499791574"
"a3_352" = "2540269385"
"a3_353" = "2547254248"
"a3_358" = "2583246223"
"a3_359" = "2556735022"
"a4_37" = "265257477"
"a4_36" = "258088356"
"a4_35" = "250919235"
"a4_34" = "243750114"
"a4_33" = "236580993"
"a4_32" = "229411872"
"a4_31" = "222242751"
"a4_30" = "215073630"
"a4_144" = "1032353424"
"a4_39" = "279595719"
"a4_38" = "272426598"
"a3_142" = "1034864615"
[HKCU\Software\Aas\695404737]
"28676484" = "35"
[HKCU\Software\Aas]
"a3_448" = "3194799081"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Security Center\Svc]
"UacDisableNotify" = "1"
[HKCU\Software\Aas]
"a4_124" = "888971004"
"a4_125" = "896140125"
"a4_126" = "903309246"
"a4_127" = "910478367"
"a4_120" = "860294520"
"a4_121" = "867463641"
"a4_122" = "874632762"
"a4_123" = "881801883"
"a4_128" = "917647488"
"a4_129" = "924816609"
"a3_444" = "3166269973"
"a3_445" = "3206813364"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Aas]
"a4_238" = "1706250798"
"a4_239" = "1713419919"
"a4_230" = "1648897830"
"a4_231" = "1656066951"
"a4_232" = "1663236072"
"a4_233" = "1670405193"
"a4_234" = "1677574314"
"a4_235" = "1684743435"
"a4_236" = "1691912556"
"a4_237" = "1699081677"
"a1_158" = "558968333"
"a1_159" = "2015297781"
"a1_150" = "581043076"
"a1_151" = "4166001635"
"a1_152" = "666810602"
"a1_153" = "1264986155"
"a1_154" = "614885000"
"a1_155" = "1815526886"
"a1_156" = "1286957089"
"a1_157" = "3495490603"
"a1_235" = "1365079000"
"a1_234" = "1343791613"
"a1_237" = "1717700868"
"a1_236" = "3847362014"
"a1_231" = "3414358775"
"a1_230" = "284055924"
"a1_233" = "1525234949"
"a1_232" = "2592985777"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Aas]
"a1_239" = "2745915866"
"a1_238" = "1804245904"
"a2_210" = "1505511885"
"a2_211" = "1512678819"
"a2_212" = "1519859443"
"a2_213" = "1527028786"
"a2_214" = "1534197489"
"a2_215" = "1541363508"
"a2_216" = "1548522913"
"a2_217" = "1555694448"
"a2_218" = "1562859759"
"a2_219" = "1570031398"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Aas]
"a2_324" = "2322798042"
"a2_325" = "2329965642"
"a2_326" = "2337131339"
"a2_327" = "2344299908"
"a2_320" = "2294115504"
"a2_321" = "2301281182"
"a2_322" = "2308463394"
"a2_323" = "2315630702"
"a2_328" = "2351465839"
"a2_329" = "2358649234"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKCU\Software\Aas]
"a1_98" = "2669770493"
"a1_99" = "1945760578"
"a1_92" = "3810720277"
"a1_93" = "1914936907"
"a1_90" = "2560595306"
"a1_91" = "235614151"
"a1_96" = "2336434542"
"a1_97" = "2818693887"
"a1_94" = "692262629"
"a1_95" = "2799125424"
"a1_74" = "2338204493"
"a1_75" = "702325555"
"a1_76" = "2190593655"
"a1_77" = "2002831987"
"a1_70" = "300460082"
"a1_71" = "1471927772"
"a1_72" = "3870562633"
"a1_73" = "3845342573"
"a3_129" = "907869896"
"a3_128" = "934369961"
"a1_78" = "2894647600"
"a1_79" = "1199136662"
"a3_239" = "1730403494"
"a3_238" = "1689270279"
"a3_237" = "1682343908"
"a3_236" = "1708909381"
"a3_235" = "1701334818"
"a3_234" = "1660856963"
"a3_233" = "1653814880"
"a3_232" = "1646370241"
"a3_231" = "1672935854"
"a3_230" = "1665877263"
"a1_419" = "1529946261"
"a1_418" = "3703894789"
"a1_415" = "1403670857"
"a1_414" = "2882176877"
"a1_417" = "2618403955"
"a1_416" = "2144537618"
"a1_411" = "30448612"
"a1_410" = "571453959"
"a1_413" = "816218674"
"a1_412" = "1460998210"
"a3_347" = "2504287570"
"a3_346" = "2463809843"
"a3_345" = "2456759440"
"a3_344" = "2482866289"
"a3_343" = "2475825118"
"a3_342" = "2468836287"
"a3_341" = "2427838236"
"a3_340" = "2420783869"
"a3_349" = "2485301780"
"a3_348" = "2511804917"
"a2_360" = "2580876452"
"a2_361" = "2588055248"
"a2_362" = "2595219967"
"a4_24" = "172058904"
"a4_25" = "179228025"
"a4_26" = "186397146"
"a4_27" = "193566267"
"a4_20" = "143382420"
"a4_21" = "150551541"
"a4_22" = "157720662"
"a4_23" = "164889783"
"a2_364" = "2609556508"
"a4_28" = "200735388"
"a4_29" = "207904509"
"a2_365" = "2616724293"
"a2_366" = "2623904913"
"a2_367" = "2631072002"
"a2_168" = "1204406281"
"a2_169" = "1211586605"
"a2_160" = "1147050346"
"a2_161" = "1154235481"
"a4_137" = "982169577"
"a4_136" = "975000456"
"a4_135" = "967831335"
"a4_134" = "960662214"
"a4_133" = "953493093"
"a4_132" = "946323972"
"a4_131" = "939154851"
"a4_130" = "931985730"
"a4_139" = "996507819"
"a4_138" = "989338698"
"a2_455" = "3261942710"
"a4_229" = "1641728709"
"a4_228" = "1634559588"
"a4_223" = "1598713983"
"a4_222" = "1591544862"
"a4_221" = "1584375741"
"a4_220" = "1577206620"
"a4_227" = "1627390467"
"a4_226" = "1620221346"
"a4_225" = "1613052225"
"a4_224" = "1605883104"
"a2_459" = "3290623471"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Aas]
"a1_149" = "2225555653"
"a1_148" = "780091567"
"a1_143" = "3207238045"
"a1_142" = "2869153438"
"a1_141" = "3044417470"
"a1_140" = "2381290833"
"a1_147" = "1039958019"
"a1_146" = "1670859270"
"a1_145" = "2435701839"
"a1_144" = "3427059420"
"a2_203" = "1455326781"
"a2_202" = "1448161253"
"a2_201" = "1440991147"
"a2_200" = "1433828447"
"a2_207" = "1484010485"
"a2_206" = "1476841697"
"a2_205" = "1469676429"
"a2_204" = "1462495141"
"a2_209" = "1498343878"
"a2_208" = "1491178673"
"a2_337" = "2416000566"
"a2_336" = "2408818981"
"a2_335" = "2401648753"
"a2_334" = "2394477917"
"a2_333" = "2387315963"
"a2_332" = "2380139585"
"a2_331" = "2372981323"
"a2_330" = "2365816109"
"a3_242" = "1718323611"
"a2_339" = "2430333252"
"a2_338" = "2423171444"
"a3_243" = "1725243962"
"a1_398" = "2494544132"
"a1_399" = "1079982489"
"a1_392" = "512058945"
"a1_393" = "869785005"
"a1_390" = "1175608475"
"a1_391" = "1575115872"
"a1_396" = "134830717"
"a1_397" = "3985584151"
"a1_394" = "1894612817"
"a1_395" = "3123895326"
"a3_116" = "814879197"
"a3_117" = "821922428"
"a3_114" = "834001179"
"a3_115" = "807894458"
"a3_112" = "785940569"
"a3_113" = "826942712"
"a3_110" = "771902343"
"a3_111" = "778955814"
"a1_49" = "1658542892"
"a1_48" = "638793189"
"a3_118" = "862924447"
"a3_119" = "869974846"
"a3_202" = "1465015971"
"a3_203" = "1472066242"
"a3_200" = "1416954337"
"a3_201" = "1424013824"
"a3_206" = "1493543975"
"a3_207" = "1500987462"
"a3_204" = "1445500773"
"a3_205" = "1452936068"
"a1_197" = "2376717952"
"a3_208" = "1508041977"
"a3_209" = "1481480472"
"a1_191" = "1608729125"
"a2_17" = "121880052"
"a2_16" = "114713562"
"a2_15" = "107543439"
"a2_14" = "100363200"
"a2_13" = "93193917"
"a2_12" = "86026691"
"a2_11" = "78859692"
"a2_10" = "71693805"
"a2_19" = "136212087"
"a2_18" = "129044925"
"a4_11" = "78860331"
"a4_10" = "71691210"
"a4_13" = "93198573"
"a4_12" = "86029452"
"a4_15" = "107536815"
"a4_14" = "100367694"
"a4_17" = "121875057"
"a4_16" = "114705936"
"a4_19" = "136213299"
"a4_18" = "129044178"
"a3_378" = "2693094675"
"a3_379" = "2700145074"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKCU\Software\Aas]
"a3_372" = "2683746013"
"a3_373" = "2657102716"
"a3_370" = "2669182491"
"a3_371" = "2676691642"
"a3_376" = "2712142929"
"a3_377" = "2686171376"
"a3_374" = "2664681375"
"a3_375" = "2705154110"
"a3_127" = "927442486"
"a1_189" = "3437319632"
"a1_188" = "4192939078"
"a1_187" = "3633885316"
"a1_186" = "2085402793"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden" = "2"
[HKCU\Software\Aas]
"a4_218" = "1562868378"
"a4_219" = "1570037499"
"a4_216" = "1548530136"
"a4_217" = "1555699257"
"a4_214" = "1534191894"
"a4_215" = "1541361015"
"a4_212" = "1519853652"
"a4_213" = "1527022773"
"a4_210" = "1505515410"
"a4_211" = "1512684531"
"a4_458" = "3283457418"
"a4_459" = "3290626539"
"a4_108" = "774265068"
"a4_109" = "781434189"
"a4_102" = "731250342"
"a4_103" = "738419463"
"a4_100" = "716912100"
"a4_101" = "724081221"
"a4_106" = "759926826"
"a4_107" = "767095947"
"a4_104" = "745588584"
"a4_105" = "752757705"
"a1_178" = "47637547"
"a1_179" = "2469173155"
"a1_176" = "1149102790"
"a1_177" = "477424719"
"a1_174" = "1226782650"
"a1_175" = "649389090"
"a1_172" = "158342261"
"a1_173" = "1176352195"
"a1_170" = "1580148640"
"a1_171" = "1544563119"
"a2_236" = "1691920699"
"a2_237" = "1699082942"
"a2_234" = "1677581129"
"a2_235" = "1684746956"
"a2_232" = "1663230287"
"a2_233" = "1670412675"
"a2_230" = "1648900473"
"a2_231" = "1656064400"
"a2_238" = "1706250188"
"a2_239" = "1713417257"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKCU\Software\Aas]
"a2_308" = "2208092441"
"a2_309" = "2215263454"
"a2_302" = "2165076379"
"a2_303" = "2172244060"
"a2_300" = "2150741675"
"a2_301" = "2157910174"
"a2_306" = "2193745657"
"a2_307" = "2200925097"
"a2_304" = "2179411430"
"a2_305" = "2186579789"
"a1_389" = "1011911520"
"a1_388" = "2712140980"
"a1_385" = "1340297272"
"a1_384" = "2830315592"
"a1_387" = "2307921311"
"a1_386" = "1577407995"
"a1_381" = "3107351082"
"a1_380" = "1095336935"
"a1_383" = "2047508136"
"a1_382" = "594069248"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Aas]
"a1_58" = "3784951982"
"a1_59" = "978144006"
"a1_56" = "1036858116"
"a1_57" = "219286999"
"a1_54" = "244036137"
"a1_55" = "960187370"
"a1_52" = "1358589036"
"a1_53" = "2969575244"
"a1_50" = "938328271"
"a1_51" = "2454982662"
"a3_215" = "1524377438"
"a3_214" = "1517454143"
"a3_217" = "1572437008"
"a3_216" = "1565514737"
"a3_211" = "1529532890"
"a3_210" = "1488928187"
"a3_213" = "1510469276"
"a3_212" = "1536445053"
"a3_219" = "1553446098"
"a3_218" = "1545867443"
"a3_109" = "798021476"
"a3_108" = "790966981"
"a3_101" = "707522668"
"a3_100" = "733503437"
"a3_103" = "754977070"
"a3_102" = "714511503"
"a3_105" = "769475040"
"a3_104" = "762555713"
"a3_107" = "750493346"
"a3_106" = "742980099"
"a3_369" = "2628699640"
"a3_368" = "2621645145"
"a3_365" = "2600170596"
"a3_364" = "2592723909"
"a3_367" = "2647756070"
"a3_366" = "2640767111"
"a3_361" = "2604787424"
"a3_360" = "2564178497"
"a3_363" = "2585673634"
"a3_362" = "2611780355"
"a2_62" = "444486921"
"a2_63" = "451646997"
"a2_60" = "430154251"
"a2_61" = "437318877"
"a2_66" = "473169399"
"a2_67" = "480336722"
"a2_64" = "458821004"
"a2_65" = "465986046"
"a1_41" = "3093851100"
"a1_40" = "2110215062"
"a1_43" = "1885351430"
"a1_42" = "3592422032"
"a1_45" = "3595684131"
"a1_44" = "685537484"
"a1_47" = "3865220606"
"a1_46" = "1864682027"
"a4_201" = "1440993321"
"a4_200" = "1433824200"
"a4_203" = "1455331563"
"a4_202" = "1448162442"
"a4_205" = "1469669805"
"a4_204" = "1462500684"
"a4_207" = "1484008047"
"a4_206" = "1476838926"
"a4_209" = "1498346289"
"a4_208" = "1491177168"
"a4_449" = "3218935329"
"a4_448" = "3211766208"
"a4_119" = "853125399"
"a4_118" = "845956278"
"a4_115" = "824448915"
"a4_114" = "817279794"
"a4_117" = "838787157"
"a4_116" = "831618036"
"a4_111" = "795772431"
"a4_110" = "788603310"
"a4_113" = "810110673"
"a4_112" = "802941552"
"a1_161" = "1261486003"
"a1_160" = "1442569495"
"a1_163" = "1652170136"
"a1_162" = "3946216721"
"a1_165" = "4256833950"
"a1_164" = "3815006986"
"a1_167" = "3502219678"
"a1_166" = "1321067311"
"a1_169" = "596088503"
"a1_168" = "1356509058"
"a4_447" = "3204597087"
"a2_319" = "2286946892"
"a2_318" = "2279779205"
"a2_315" = "2258280102"
"a2_314" = "2251096856"
"a2_317" = "2272613644"
"a2_316" = "2265433253"
"a2_311" = "2229594342"
"a2_310" = "2222431224"
"a2_313" = "2243931354"
"a2_312" = "2236760251"
"a2_229" = "1641736401"
"a2_228" = "1634564864"
"a2_221" = "1584366700"
"a2_220" = "1577210123"
"a2_223" = "1598713391"
"a2_222" = "1591548182"
"a2_225" = "1613044875"
"a2_224" = "1605879902"
"a2_227" = "1627398670"
"a2_226" = "1620215530"
"a1_370" = "1288439049"
"a1_371" = "328861167"
"a1_372" = "311442728"
"a1_373" = "3694921576"
"a1_374" = "3992041967"
"a1_375" = "2907964434"
"a1_376" = "1350330563"
"a1_377" = "2197302373"
"a1_378" = "4172728726"
"a1_379" = "2064866026"
"a3_36" = "241268621"
"a3_37" = "248309804"
"a3_183" = "1328655230"
"a1_29" = "1968107954"
"a1_28" = "222642248"
"a1_23" = "2061462220"
"a1_22" = "3018230931"
"a1_21" = "2750775980"
"a1_20" = "4127514460"
"a1_27" = "149930885"
"a1_26" = "1985170837"
"a1_25" = "2959341687"
"a1_24" = "1416527692"
"a1_284" = "696798805"
"a1_285" = "3766209952"
"a1_286" = "3158634291"
"a1_287" = "273319328"
"a1_280" = "3131883216"
"a1_281" = "4118406087"
"a1_282" = "2560439567"
"a1_283" = "978677534"
"a3_31" = "205278614"
"a1_288" = "131047551"
"a1_289" = "241093583"
"a3_32" = "212854281"
"a3_178" = "1292673371"
"a3_179" = "1300121082"
"a3_174" = "1264145351"
"a3_175" = "1271198822"
"a3_176" = "1245079705"
"a3_177" = "1252068664"
"a3_170" = "1235731011"
"a3_171" = "1209100002"
"a3_172" = "1216092933"
"a3_173" = "1223671716"
"a2_31" = "222245589"
"a2_30" = "215078423"
"a2_33" = "236579822"
"a2_32" = "229413826"
"a2_35" = "250916318"
"a2_34" = "243745070"
"a2_37" = "265265071"
"a2_36" = "258083629"
"a2_39" = "279598713"
"a2_38" = "272430781"
"a4_79" = "566360559"
"a4_78" = "559191438"
"a4_73" = "523345833"
"a4_72" = "516176712"
"a4_71" = "509007591"
"a4_70" = "501838470"
"a4_77" = "552022317"
"a4_76" = "544853196"
"a4_75" = "537684075"
"a4_74" = "530514954"
"a3_390" = "2812641775"
"a3_391" = "2786540046"
"a3_392" = "2793594529"
"a3_393" = "2800513728"
"a3_394" = "2841581411"
"a3_395" = "2848623490"
"a3_396" = "2821991461"
"a3_397" = "2829566020"
"a3_398" = "2870043879"
"a3_399" = "2877036806"
[HKCU\Software\Aas\695404737]
"7169121" = "229"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Aas]
"a4_199" = "1426655079"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Aas]
"a2_363" = "2602385981"
"a4_274" = "1964339154"
"a4_275" = "1971508275"
"a4_276" = "1978677396"
"a4_277" = "1985846517"
"a4_270" = "1935662670"
"a4_271" = "1942831791"
"a4_272" = "1950000912"
"a4_273" = "1957170033"
"a4_278" = "1993015638"
"a4_279" = "2000184759"
"a4_308" = "2208089268"
"a4_309" = "2215258389"
"a4_300" = "2150736300"
"a4_301" = "2157905421"
"a4_302" = "2165074542"
"a4_303" = "2172243663"
"a4_304" = "2179412784"
"a4_305" = "2186581905"
"a4_306" = "2193751026"
"a4_307" = "2200920147"
"a1_114" = "1023963497"
"a1_115" = "4135769026"
"a1_116" = "2788412842"
"a1_117" = "1851034747"
"a1_110" = "832632567"
"a1_111" = "358745733"
"a1_112" = "1321590222"
"a1_113" = "3172315159"
"a1_118" = "1356701579"
"a1_119" = "3049324616"
"a2_258" = "1849636478"
"a2_259" = "1856809961"
"a2_254" = "1820965822"
"a2_255" = "1828118242"
"a2_256" = "1835286871"
"a2_257" = "1842469766"
"a2_250" = "1792283600"
"a2_251" = "1799451195"
"a2_252" = "1806619667"
"a2_253" = "1813778922"
"a1_363" = "800073393"
"a1_362" = "2792672665"
"a1_361" = "1820497764"
"a1_360" = "242595546"
"a1_367" = "2942508866"
"a1_366" = "2016354944"
"a1_365" = "3269579763"
"a1_364" = "122015812"
"a1_369" = "199511276"
"a1_368" = "689583050"
"a1_38" = "2017627608"
"a1_39" = "2968319097"
"a1_30" = "4167821357"
"a1_31" = "4162391147"
"a1_32" = "815718516"
"a1_33" = "6345697"
"a1_34" = "1666293168"
"a1_35" = "3499689981"
"a1_36" = "730321250"
"a1_37" = "3791829147"
"a1_297" = "2677179701"
"a1_296" = "1253680247"
"a1_295" = "2504889545"
"a1_294" = "2401861299"
"a1_293" = "491317364"
"a1_292" = "644984080"
"a1_291" = "2171613591"
"a1_290" = "2126554960"
"a1_299" = "1163158134"
"a1_298" = "757015949"
"a4_286" = "2050368606"
"a2_108" = "774260412"
"a2_109" = "781427283"
"a2_100" = "716909913"
"a2_101" = "724074857"
"a2_102" = "731244643"
"a2_103" = "738412237"
"a2_104" = "745593613"
"a2_105" = "752748772"
"a2_106" = "759924032"
"a2_107" = "767087952"
"a3_169" = "1228156448"
"a3_168" = "1187689857"
"a3_167" = "1180635502"
"a3_166" = "1206680783"
"a3_165" = "1199757484"
"a3_164" = "1192698893"
"a3_163" = "1151697898"
"a3_162" = "1144713035"
"a3_161" = "1171213096"
"a3_160" = "1163777673"
"a2_28" = "200731660"
"a2_29" = "207897834"
"a2_26" = "186396598"
"a2_27" = "193563450"
"a2_24" = "172050685"
"a2_25" = "179229014"
"a2_22" = "157728262"
"a2_23" = "164895968"
"a2_20" = "143379011"
"a2_21" = "150546354"
"a4_68" = "487500228"
"a4_69" = "494669349"
"a4_60" = "430147260"
"a4_61" = "437316381"
"a4_62" = "444485502"
"a4_63" = "451654623"
"a4_64" = "458823744"
"a4_65" = "465992865"
"a4_66" = "473161986"
"a4_67" = "480331107"
"a2_7" = "50174628"
"a2_6" = "43022699"
"a2_5" = "35842708"
"a2_4" = "28674204"
"a2_3" = "21499634"
"a2_2" = "14341480"
"a2_1" = "7174733"
"a2_0" = "8835"
"a3_389" = "2805656908"
"a3_388" = "2765048109"
"a2_9" = "64527246"
"a2_8" = "57345579"
"a4_5" = "35845605"
"a4_4" = "28676484"
"a4_7" = "50183847"
"a4_6" = "43014726"
"a4_1" = "7169121"
"a4_0" = "0"
"a4_3" = "21507363"
"a4_2" = "14338242"
"a4_9" = "64522089"
"a4_8" = "57352968"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BC 61 20 8A DE 6E 2B 25 E4 3C 8B 61 F6 E3 F7 96"
[HKCU\Software\Aas]
"a4_267" = "1914155307"
"a4_266" = "1906986186"
"a4_265" = "1899817065"
"a4_264" = "1892647944"
"a4_263" = "1885478823"
"a4_262" = "1878309702"
"a4_261" = "1871140581"
"a4_260" = "1863971460"
[HKCU\Software\Aas\695404737]
"43014726" = "0800687474703A2F2F6164696E61746862696F2E636F6D2F696D616765732F6C6F676F2E67696600687474703A2F2F6163746976652E637075742E61632E7A612F696D616765732F696D6167652E67696600687474703A2F2F666367616772612E67652F696D616765732F6C6F676F2E67696600687474703A2F2F696C6D6573746572732E6564752E706B2F696D616765732F626F74746F6D2E67696600687474703A2F2F646961786973706572752E636F6D2F626F74746F6D2E67696600687474703A2F2F6675726B616E62656469722E636F6D2F696D672F69636F6E732F626F74746F6D2E67696600687474703A2F2F61746C6173636F6272616E63612E636F6D2E62722F61746C6173636F6272616E636130312F626F74746F6D2E67696600687474703A2F2F726976696572612D70616C6163652E636F6D2F696D616765732F6C6F676F2E676966"
[HKCU\Software\Aas]
"a4_269" = "1928493549"
"a4_268" = "1921324428"
"a4_461" = "3304964781"
"a4_460" = "3297795660"
"a4_319" = "2286949599"
"a4_318" = "2279780478"
"a4_313" = "2243934873"
"a4_312" = "2236765752"
"a4_311" = "2229596631"
"a4_310" = "2222427510"
"a4_317" = "2272611357"
"a4_316" = "2265442236"
"a4_315" = "2258273115"
"a4_314" = "2251103994"
"a3_130" = "915379051"
"a3_131" = "922302346"
"a3_132" = "962897965"
"a1_107" = "1797555267"
"a1_106" = "202095193"
"a1_105" = "2762564215"
"a1_104" = "3503431869"
"a1_103" = "929993172"
"a1_102" = "750754793"
"a1_101" = "1414928748"
"a1_100" = "3994544345"
"a3_134" = "943841519"
"a1_109" = "3986417651"
"a1_62" = "3773203452"
"a1_61" = "1579102058"
"a3_137" = "998890944"
"a3_145" = "1022800088"
"a3_144" = "1015749817"
"a3_147" = "1070844314"
"a3_146" = "1063277947"
"a3_141" = "1027810116"
"a3_140" = "986812197"
"a3_143" = "1008236550"
"a2_249" = "1785117219"
"a2_248" = "1777935761"
"a2_247" = "1770770296"
"a2_246" = "1763631649"
"a2_245" = "1756443410"
"a2_244" = "1749269280"
"a2_243" = "1742099834"
"a2_242" = "1734933448"
"a2_241" = "1727751216"
"a2_240" = "1720582763"
"a1_356" = "2599609529"
"a1_357" = "3309746421"
"a1_354" = "3716406559"
"a1_355" = "2948552439"
"a1_352" = "1646084573"
"a1_353" = "790725047"
"a1_350" = "884891990"
"a1_351" = "3116157346"
"a1_358" = "466101747"
"a1_359" = "801235806"
"a2_119" = "853128220"
"a2_118" = "845961824"
"a2_113" = "810118640"
"a2_112" = "802944032"
"a2_111" = "795780776"
"a2_110" = "788608987"
"a2_117" = "838794460"
"a2_116" = "831611489"
"a2_115" = "824446340"
"a2_114" = "817278303"
"a3_152" = "1106310065"
"a3_153" = "1080268752"
"a3_150" = "1092336383"
"a3_151" = "1099259678"
"a3_156" = "1135231285"
"a3_157" = "1108731220"
"a3_154" = "1087178867"
"a3_155" = "1127787666"
"a3_158" = "1115724279"
"a3_159" = "1123168790"
"a2_59" = "422985552"
"a2_58" = "415800551"
"a2_53" = "379972404"
"a2_52" = "372785328"
"a2_51" = "365619389"
"a2_50" = "358463605"
"a2_57" = "408636498"
"a2_56" = "401468578"
"a2_55" = "394300732"
"a2_54" = "387124993"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKCU\Software\Aas]
"a4_55" = "394301655"
"a4_54" = "387132534"
"a4_57" = "408639897"
"a4_56" = "401470776"
"a4_51" = "365625171"
"a4_50" = "358456050"
"a4_53" = "379963413"
"a4_52" = "372794292"
"a3_440" = "3171413137"
"a3_441" = "3178398000"
"a3_442" = "3185321299"
"a3_443" = "3159349746"
"a4_59" = "422978139"
"a4_58" = "415809018"
"a3_446" = "3214379735"
"a3_447" = "3187748726"
[HKCU\Software\Aas\695404737]
"21507363" = "0"
[HKCU\Software\Aas]
"a3_459" = "3307312066"
"a3_458" = "3266772899"
"a3_451" = "3249847498"
"a3_450" = "3242793131"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "%original file name%.exe"
[HKCU\Software\Aas]
"a4_414" = "2968016094"
"a4_415" = "2975185215"
"a4_416" = "2982354336"
"a4_417" = "2989523457"
"a4_410" = "2939339610"
"a4_411" = "2946508731"
"a4_412" = "2953677852"
"a4_413" = "2960846973"
"a4_418" = "2996692578"
"a4_419" = "3003861699"
"a1_138" = "2505611904"
"a1_139" = "1737682640"
"a1_132" = "4211769038"
"a1_133" = "3673284441"
"a1_130" = "2426523931"
"a1_131" = "3541941499"
"a1_136" = "2093831261"
"a1_137" = "831110558"
"a1_134" = "453578010"
"a1_135" = "3547286379"
"a4_328" = "2351471688"
"a4_329" = "2358640809"
"a4_326" = "2337133446"
"a4_327" = "2344302567"
"a4_324" = "2322795204"
"a4_325" = "2329964325"
"a4_322" = "2308456962"
"a4_323" = "2315626083"
"a4_320" = "2294118720"
"a4_321" = "2301287841"
"a4_258" = "1849633218"
"a4_259" = "1856802339"
"a4_252" = "1806618492"
"a4_253" = "1813787613"
"a4_250" = "1792280250"
"a4_251" = "1799449371"
"a4_256" = "1835294976"
"a4_257" = "1842464097"
"a4_254" = "1820956734"
"a4_255" = "1828125855"
"a1_349" = "101022339"
"a1_348" = "4020896123"
"a1_341" = "3970582268"
"a1_340" = "2992333679"
"a1_343" = "2290527138"
"a1_342" = "2414354780"
"a1_345" = "630829278"
"a1_344" = "2409944582"
"a1_347" = "2354922276"
"a1_346" = "3495194663"
"a2_272" = "1949991527"
"a2_273" = "1957179166"
"a2_270" = "1935670969"
[HKLM\SOFTWARE\Microsoft\Security Center\Svc]
"UpdatesDisableNotify" = "1"
[HKCU\Software\Aas]
"a2_276" = "1978674653"
"a2_277" = "1985855362"
"a2_274" = "1964339797"
"a2_275" = "1971506415"
"a2_278" = "1993023629"
"a2_279" = "2000187613"
"a2_298" = "2136406568"
"a2_299" = "2143559308"
"a2_290" = "2079042597"
"a2_291" = "2086208356"
"a2_292" = "2093377329"
"a2_293" = "2100559742"
"a2_294" = "2107727109"
"a2_295" = "2114882209"
"a2_296" = "2122058382"
"a2_297" = "2129220890"
"a4_450" = "3226104450"
"a4_451" = "3233273571"
"a4_452" = "3240442692"
"a4_453" = "3247611813"
"a2_128" = "917645005"
"a2_129" = "924824882"
"a2_126" = "903300565"
"a2_127" = "910485532"
"a2_124" = "888966924"
"a2_125" = "896146047"
"a2_122" = "874629421"
"a2_123" = "881795941"
"a2_120" = "860301848"
"a2_121" = "867461396"
"a3_35" = "267899754"
"a4_456" = "3269119176"
"a4_457" = "3276288297"
"a1_12" = "2612473590"
"a1_13" = "1583991588"
"a1_10" = "660421777"
"a1_11" = "169026983"
"a1_16" = "1357116746"
"a1_17" = "1741872907"
"a1_14" = "3223102491"
"a1_15" = "63573752"
"a1_18" = "1008178344"
"a1_19" = "2966886907"
"a3_149" = "1051199068"
"a3_148" = "1044210237"
"a2_48" = "344116951"
"a2_49" = "351283382"
"a2_40" = "286765432"
"a2_41" = "293933042"
"a2_42" = "301099812"
"a2_43" = "308266449"
"a2_44" = "315447106"
"a2_45" = "322601159"
"a2_46" = "329788580"
"a2_47" = "336952194"
"a4_42" = "301103082"
"a4_43" = "308272203"
"a4_40" = "286764840"
"a4_41" = "293933961"
"a4_46" = "329779566"
"a4_47" = "336948687"
"a4_44" = "315441324"
"a4_45" = "322610445"
"a3_453" = "3230791052"
"a3_452" = "3223736685"
"a4_48" = "344117808"
"a4_49" = "351286929"
"a3_457" = "3259718400"
"a3_456" = "3285821153"
"a3_455" = "3278766670"
"a3_454" = "3271781935"
"a3_18" = "112354555"
"a3_19" = "152901914"
"a3_14" = "83367783"
"a3_15" = "124488582"
"a3_16" = "131411001"
"a3_17" = "104906840"
"a3_10" = "88506851"
"a3_11" = "95435266"
"a3_12" = "69459621"
"a3_13" = "76378820"
"a3_240" = "1737322713"
"a3_248" = "1761236945"
"a2_172" = "1233085027"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Aas]
"a4_454" = "3254780934"
"a4_407" = "2917832247"
"a4_406" = "2910663126"
"a4_405" = "2903494005"
"a4_404" = "2896324884"
"a4_403" = "2889155763"
"a4_402" = "2881986642"
"a4_401" = "2874817521"
"a4_400" = "2867648400"
"a4_409" = "2932170489"
"a4_408" = "2925001368"
"a1_129" = "49071766"
"a1_128" = "4061368570"
"a1_125" = "3704666416"
"a1_124" = "475607089"
"a1_127" = "3278647371"
"a1_126" = "266400213"
"a1_121" = "2968668176"
"a1_120" = "3121855174"
"a1_123" = "4225032614"
"a1_122" = "1615236097"
"a4_331" = "2372979051"
"a4_330" = "2365809930"
"a4_333" = "2387317293"
"a4_332" = "2380148172"
"a4_335" = "2401655535"
"a4_334" = "2394486414"
"a4_337" = "2415993777"
"a4_336" = "2408824656"
"a4_339" = "2430332019"
"a4_338" = "2423162898"
"a4_249" = "1785111129"
"a4_248" = "1777942008"
"a4_245" = "1756434645"
"a4_244" = "1749265524"
"a4_247" = "1770772887"
"a4_246" = "1763603766"
"a4_241" = "1727758161"
"a4_240" = "1720589040"
"a4_243" = "1742096403"
"a4_242" = "1734927282"
"a2_461" = "3304970690"
"a2_460" = "3297789810"
"a1_338" = "1416671403"
"a1_339" = "1884317480"
"a1_334" = "3078212036"
"a1_335" = "741907038"
"a1_336" = "3034150292"
"a1_337" = "2045369208"
"a1_330" = "1730775453"
"a1_331" = "2342644274"
"a1_332" = "1309123442"
"a1_333" = "1419799711"
"a3_30" = "231909751"
"a1_64" = "388742642"
"a2_265" = "1899808878"
"a2_264" = "1892652006"
"a2_267" = "1914152001"
"a2_266" = "1906990056"
"a2_261" = "1871148087"
"a2_260" = "1863969485"
"a2_263" = "1885472057"
"a2_262" = "1878303635"
"a2_269" = "1928485620"
"a2_268" = "1921322013"
"a2_289" = "2071873606"
"a2_288" = "2064709802"
"a2_283" = "2028855339"
"a2_282" = "2021691109"
"a2_281" = "2014523932"
"a2_280" = "2007356437"
"a2_287" = "2057540885"
"a2_286" = "2050375197"
"a2_285" = "2043192996"
"a2_284" = "2036038059"
"a4_446" = "3197427966"
"a1_240" = "448556455"
"a1_241" = "742366861"
"a1_242" = "86222348"
"a1_243" = "4015700698"
"a1_244" = "1643095236"
"a1_245" = "3730550171"
"a1_246" = "4069223236"
"a1_247" = "787002819"
"a1_248" = "3226615099"
"a1_249" = "1345678662"
"a4_445" = "3190258845"
"a2_131" = "939162890"
"a2_130" = "931980537"
"a2_133" = "953495878"
"a2_132" = "946332117"
"a2_135" = "967832760"
"a2_134" = "960666961"
"a2_137" = "982167198"
"a2_136" = "974998040"
"a2_139" = "996515256"
"a2_138" = "989332307"
"a2_79" = "566355888"
"a2_78" = "559200009"
"a3_288" = "2048100105"
"a3_289" = "2055027624"
"a3_184" = "1336102801"
"a3_282" = "2038692083"
"a3_283" = "2045680914"
"a3_280" = "1990631473"
"a3_281" = "2031109200"
"a3_286" = "2067091063"
"a3_287" = "2074141334"
"a3_284" = "2019045813"
"a3_285" = "2026624468"
"a3_198" = "1436076335"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = "0"
[HKCU\Software\Aas]
"a3_196" = "1388556397"
"a3_197" = "1429034124"
"a3_194" = "1407548331"
"a3_195" = "1380982730"
"a3_192" = "1393042153"
"a3_193" = "1400620808"
"a3_190" = "1345525207"
"a3_191" = "1352568438"
"a3_460" = "3314758757"
"a3_461" = "3321800836"
"a1_460" = "3975811345"
"a1_461" = "1194209388"
"a3_29" = "224867540"
"a3_28" = "183865525"
"a3_21" = "167399900"
"a3_20" = "159956413"
"a3_23" = "148336286"
"a3_22" = "140888703"
"a3_25" = "195929936"
"a3_24" = "188875569"
"a3_27" = "176880658"
"a3_26" = "169827315"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1416303360"
[HKCU\Software\Aas]
"a4_438" = "3140074998"
"a4_439" = "3147244119"
"a4_432" = "3097060272"
"a4_433" = "3104229393"
"a4_430" = "3082722030"
"a4_431" = "3089891151"
"a4_436" = "3125736756"
"a4_437" = "3132905877"
"a4_434" = "3111398514"
"a4_435" = "3118567635"
"a4_344" = "2466177624"
"a4_345" = "2473346745"
"a4_346" = "2480515866"
"a4_347" = "2487684987"
"a4_340" = "2437501140"
"a4_341" = "2444670261"
"a4_342" = "2451839382"
"a4_343" = "2459008503"
"a4_348" = "2494854108"
"a4_349" = "2502023229"
"a3_383" = "2729068342"
"a3_382" = "2721620631"
"a3_381" = "2748124788"
"a2_456" = "3269126425"
"a2_457" = "3276286131"
"a2_454" = "3254787385"
"a3_380" = "2741212629"
"a2_452" = "3240436186"
"a2_453" = "3247604766"
"a2_450" = "3226100992"
"a2_451" = "3233281886"
"a3_387" = "2757612682"
"a2_458" = "3283454992"
"a3_386" = "2784112747"
"a3_385" = "2776670152"
"a3_384" = "2769681321"
"a1_329" = "2398115095"
"a1_328" = "2653755540"
"a1_327" = "2948581043"
"a1_326" = "2726525114"
"a1_325" = "3779083113"
"a1_324" = "2694665338"
"a1_323" = "3681966092"
"a1_322" = "873041596"
"a1_321" = "2674605957"
"a1_320" = "519713416"
"a1_436" = "2941295970"
"a1_253" = "3426158438"
"a1_252" = "3099147783"
"a1_251" = "3545896788"
"a1_250" = "1631518977"
"a1_257" = "896161402"
"a1_256" = "2933919837"
"a1_255" = "232470682"
"a1_254" = "4270256118"
"a1_259" = "3848310546"
"a1_258" = "3950280367"
"a2_144" = "1032344410"
"a2_145" = "1039530640"
"a2_146" = "1046685641"
"a2_147" = "1053867404"
"a2_140" = "1003680668"
"a2_141" = "1010847936"
"a2_142" = "1018018509"
"a2_143" = "1025182650"
"a2_68" = "487503683"
"a2_69" = "494670365"
"a2_148" = "1061033406"
"a2_149" = "1068202617"
"a4_455" = "3261950055"
"a3_299" = "2126993250"
"a3_298" = "2119545539"
"a3_295" = "2131608046"
"a3_294" = "2091003215"
"a3_297" = "2146049696"
"a3_296" = "2139060737"
"a3_291" = "2103079018"
"a3_290" = "2062081995"
"a3_293" = "2083555628"
"a3_292" = "2110067853"
"a3_181" = "1280611004"
"a3_180" = "1307180573"
"a3_34" = "260325067"
"a3_182" = "1288058591"
"a3_185" = "1309597744"
"a3_33" = "253401768"
"a3_187" = "1324038386"
"a3_186" = "1316586579"
"a3_189" = "1371566516"
"a3_188" = "1364647189"
"a3_38" = "289377359"
"a3_39" = "296296686"
"a4_282" = "2021692122"
[HKLM\SOFTWARE\Microsoft\Security Center]
"UacDisableNotify" = "1"
[HKCU\Software\Aas]
"a2_151" = "1082532569"
"a2_150" = "1075367781"
"a2_271" = "1942838801"
"a2_159" = "1139887919"
"a2_158" = "1132719134"
"a3_80" = "590099577"
"a4_429" = "3075552909"
"a4_428" = "3068383788"
"a4_425" = "3046876425"
"a4_424" = "3039707304"
"a4_427" = "3061214667"
"a4_426" = "3054045546"
"a4_421" = "3018199941"
"a4_420" = "3011030820"
"a4_423" = "3032538183"
"a4_422" = "3025369062"
"a4_357" = "2559376197"
"a4_356" = "2552207076"
"a4_355" = "2545037955"
"a4_354" = "2537868834"
"a4_353" = "2530699713"
"a4_352" = "2523530592"
"a4_351" = "2516361471"
"a4_350" = "2509192350"
"a4_359" = "2573714439"
"a4_358" = "2566545318"
[HKCU\Software\Aas\695404737]
"50183847" = "48534F8DE3FCD7FC5CC72EE4D046038E95106F5D91F656697F77B615DCC1C82A3B8FF36C3FCDEA289F8180235906A0D215FBAB282B963FF69BA1C50D1C0202E847E23A57D44D4659DC5A4ECEA8C65FE6D076A8149FB1A88FDD9AD8A565ABBF3999CCB9569AD218C6CCD15610EE4C3D1479326795B2212A91D479769FAAE13435"
[HKCU\Software\Aas]
"a1_312" = "771558661"
"a1_313" = "3088880928"
"a1_310" = "2492003788"
"a1_311" = "1200220689"
"a1_316" = "4121672831"
"a1_317" = "1571340112"
"a1_314" = "891280975"
"a1_315" = "1049107989"
"a1_318" = "1103282722"
"a1_319" = "2181360324"
"a2_449" = "3218936898"
"a2_448" = "3211768315"
"a2_441" = "3161585462"
"a2_440" = "3154419490"
"a2_443" = "3175915916"
"a2_442" = "3168758448"
"a2_445" = "3190252775"
"a2_444" = "3183098343"
"a2_447" = "3204601812"
"a2_446" = "3197419981"
"a1_266" = "208648182"
"a1_267" = "2073180274"
"a1_264" = "181973332"
"a1_265" = "943376246"
"a1_262" = "3421748018"
"a1_263" = "3725230445"
"a1_260" = "1180529354"
"a1_261" = "3296325968"
"a1_268" = "674481058"
"a1_269" = "3225773974"
"a2_157" = "1125560182"
"a2_156" = "1118386259"
"a2_155" = "1111219604"
"a2_154" = "1104035954"
"a2_153" = "1096868666"
"a2_152" = "1089701643"
"a2_99" = "709741672"
"a2_98" = "702575822"
"a2_97" = "695408239"
"a2_96" = "688227851"
"a2_95" = "681060376"
"a2_94" = "673894145"
"a2_93" = "666725393"
"a2_92" = "659566940"
"a2_91" = "652392953"
"a2_90" = "645228855"
"a3_260" = "1847236781"
"a3_261" = "1854160076"
"a3_262" = "1861734767"
"a3_263" = "1902212494"
"a3_264" = "1909255713"
"a3_265" = "1883210304"
"a3_266" = "1890133731"
"a3_267" = "1930746626"
"a3_268" = "1938194341"
"a3_269" = "1945179076"
"a3_404" = "2913010493"
"a3_405" = "2886510428"
"a3_43" = "324843106"
"a3_42" = "284237251"
"a3_41" = "277248416"
"a3_40" = "269796609"
"a3_47" = "353765350"
"a3_46" = "313221959"
"a3_45" = "305778468"
"a3_44" = "332278405"
"a3_49" = "368270520"
"a3_48" = "360822809"
"a4_99" = "709742979"
"a4_98" = "702573858"
"a3_406" = "2893962239"
"a3_407" = "2901015582"
"a3_400" = "2884615609"
"a3_401" = "2857980376"
"a3_402" = "2865023611"
"a3_403" = "2906025626"
"a4_91" = "652390011"
"a4_90" = "645220890"
"a4_93" = "666728253"
"a4_92" = "659559132"
"a4_95" = "681066495"
"a4_94" = "673897374"
"a4_97" = "695404737"
"a4_96" = "688235616"
[HKLM\SOFTWARE\Microsoft\Security Center\Svc]
"FirewallOverride" = "1"
[HKCU\Software\Aas]
"a1_448" = "121684165"
"a1_449" = "2386254880"
"a1_446" = "2311891891"
"a3_408" = "2941554865"
"a1_444" = "2023087180"
"a1_445" = "2496446302"
"a1_442" = "2243176366"
"a1_443" = "4016573108"
"a1_440" = "3209160066"
"a3_409" = "2949002448"
"a3_318" = "2262948439"
"a3_319" = "2303950582"
"a3_310" = "2239031135"
"a3_311" = "2246548478"
"a3_312" = "2219916305"
"a3_313" = "2226966704"
"a3_314" = "2267968723"
"a3_315" = "2275010930"
"a3_316" = "2248445333"
"a3_317" = "2255889972"
"a1_447" = "1008420296"
"a1_441" = "2433385826"
[HKCU\Software\Aas\695404737]
"35845605" = "332"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Aas]
"a4_182" = "1304780022"
[HKLM\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = "1"
[HKCU\Software\Aas]
"a4_180" = "1290441780"
"a4_181" = "1297610901"
"a4_186" = "1333456506"
"a4_187" = "1340625627"
"a4_184" = "1319118264"
"a4_185" = "1326287385"
"a4_188" = "1347794748"
"a4_189" = "1354963869"
"a4_168" = "1204412328"
"a1_194" = "2803013697"
"a1_195" = "2760334992"
"a4_160" = "1147059360"
"a4_161" = "1154228481"
"a4_162" = "1161397602"
"a4_163" = "1168566723"
"a4_164" = "1175735844"
"a4_165" = "1182904965"
"a4_166" = "1190074086"
"a4_167" = "1197243207"
"a4_296" = "2122059816"
"a4_297" = "2129228937"
"a4_294" = "2107721574"
"a4_295" = "2114890695"
"a4_292" = "2093383332"
"a4_293" = "2100552453"
"a4_290" = "2079045090"
"a4_291" = "2086214211"
"a4_142" = "1018015182"
"a4_298" = "2136398058"
"a4_299" = "2143567179"
"a1_192" = "2031713147"
"a1_193" = "341035118"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Aas]
"a4_368" = "2638236528"
"a4_369" = "2645405649"
"a4_362" = "2595221802"
"a4_363" = "2602390923"
"a4_360" = "2580883560"
"a4_361" = "2588052681"
"a4_366" = "2623898286"
"a4_367" = "2631067407"
"a4_364" = "2609560044"
"a4_365" = "2616729165"
"a1_305" = "946610664"
"a1_304" = "1528799275"
"a1_307" = "4225513961"
"a1_306" = "1096400681"
"a1_301" = "2299129275"
"a1_300" = "359243622"
"a1_303" = "1701794689"
"a1_302" = "3418282714"
"a1_309" = "2525372974"
"a1_308" = "899718004"
"a2_438" = "3140068451"
"a2_439" = "3147249575"
"a2_434" = "3111401172"
"a2_435" = "3118543872"
"a2_436" = "3125734244"
"a2_437" = "3132901187"
"a2_430" = "3082716752"
"a2_431" = "3089883768"
"a2_432" = "3097066283"
"a2_433" = "3104232430"
"a1_279" = "2707173315"
"a1_278" = "2015054054"
"a1_271" = "1693404177"
"a1_270" = "699352848"
"a1_273" = "2712815692"
"a1_272" = "1865721538"
"a1_275" = "3432027918"
"a1_274" = "4272664172"
"a1_277" = "603910363"
"a1_276" = "2194473696"
"a2_382" = "2738607854"
"a2_383" = "2745775361"
"a2_380" = "2724256977"
"a2_381" = "2731440861"
"a2_386" = "2767274741"
"a2_387" = "2774443630"
"a2_384" = "2752942032"
"a2_385" = "2760108060"
"a2_388" = "2781624571"
"a2_389" = "2788795940"
"a2_368" = "2638238060"
"a2_369" = "2645407307"
"a2_88" = "630889284"
"a2_89" = "638057686"
"a2_84" = "602206586"
"a2_85" = "609370542"
"a2_86" = "616538697"
"a2_87" = "623722096"
"a2_80" = "573524117"
"a2_81" = "580703574"
"a2_82" = "587872708"
"a2_83" = "595045241"
"a3_273" = "1974165848"
"a3_272" = "1966722361"
"a3_271" = "1926113414"
"a3_270" = "1918678119"
"a3_277" = "2002712284"
"a3_276" = "1962103485"
"a3_275" = "1954659866"
"a3_274" = "1947600379"
"a2_162" = "1161402844"
"a2_163" = "1168568590"
"a3_279" = "1983582110"
"a3_278" = "2009623423"
"a2_166" = "1190071137"
"a2_167" = "1197236018"
"a2_164" = "1175743753"
"a2_165" = "1182901617"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Aas]
"a3_50" = "341766363"
"a3_51" = "348755322"
"a3_52" = "389745053"
"a3_53" = "396796476"
"a3_54" = "370165343"
"a3_55" = "377748222"
"a3_56" = "384737041"
"a3_57" = "425210800"
"a3_58" = "432789459"
"a3_59" = "406145138"
"a3_417" = "3006523432"
"a3_416" = "2965403529"
"a3_415" = "2958480150"
"a3_414" = "2984984311"
"a3_413" = "2977536596"
"a3_412" = "2970543669"
"a3_411" = "2929937810"
"a3_410" = "2922490227"
"a3_419" = "2986877162"
"a3_418" = "3013512267"
"a1_451" = "1648806054"
"a1_450" = "4215988725"
"a1_453" = "228967021"
"a1_452" = "3848304378"
"a1_455" = "3906818650"
"a1_454" = "4079251807"
"a1_457" = "956851829"
"a1_456" = "418798243"
"a1_459" = "2083239254"
"a1_458" = "2713689055"
"a3_309" = "2231976764"
"a3_308" = "2191503005"
"a3_303" = "2155521254"
"a3_302" = "2148466759"
"a3_301" = "2174512164"
"a3_300" = "2167589765"
"a3_307" = "2183924346"
"a3_306" = "2210566619"
"a3_305" = "2203581880"
"a3_304" = "2162448665"
"a4_86" = "616544406"
"a4_87" = "623713527"
"a4_84" = "602206164"
"a4_85" = "609375285"
"a4_82" = "587867922"
"a4_83" = "595037043"
"a4_80" = "573529680"
"a4_81" = "580698801"
"a4_88" = "630882648"
"a4_89" = "638051769"
[HKCU\Software\Aas\695404737]
"14338242" = "0"
[HKCU\Software\Aas]
"a4_387" = "2774449827"
"a2_75" = "537690083"
"a2_74" = "530520495"
"a2_77" = "552019876"
"a2_76" = "544855788"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"GlobalUserOffline" = "0"
[HKCU\Software\Aas]
"a2_71" = "509003960"
"a2_70" = "501829953"
"a2_73" = "523339441"
"a2_72" = "516173254"
"a4_195" = "1397978595"
"a4_194" = "1390809474"
"a4_197" = "1412316837"
"a4_196" = "1405147716"
"a4_191" = "1369302111"
"a4_190" = "1362132990"
"a4_193" = "1383640353"
"a4_192" = "1376471232"
[HKLM\SOFTWARE\Microsoft\Security Center\Svc]
"FirewallDisableNotify" = "1"
[HKCU\Software\Aas]
"a4_198" = "1419485958"
"a4_179" = "1283272659"
"a4_178" = "1276103538"
"a4_173" = "1240257933"
"a4_172" = "1233088812"
"a4_171" = "1225919691"
"a4_170" = "1218750570"
"a4_177" = "1268934417"
"a4_176" = "1261765296"
"a4_175" = "1254596175"
"a4_174" = "1247427054"
"a3_123" = "898388146"
"a3_122" = "891468819"
"a3_121" = "850861040"
"a4_289" = "2071875969"
"a4_288" = "2064706848"
"a3_120" = "843343697"
"a4_281" = "2014523001"
"a4_280" = "2007353880"
"a4_283" = "2028861243"
"a1_108" = "241049125"
"a4_285" = "2043199485"
"a4_284" = "2036030364"
"a4_287" = "2057537727"
"a3_126" = "886312343"
"a3_125" = "879323508"
"a3_124" = "905966805"
"a4_379" = "2717096859"
"a4_378" = "2709927738"
"a4_375" = "2688420375"
"a4_374" = "2681251254"
"a4_377" = "2702758617"
"a4_376" = "2695589496"
"a4_371" = "2659743891"
"a4_370" = "2652574770"
"a4_373" = "2674082133"
"a4_372" = "2666913012"
"a1_437" = "3436636193"
"a2_429" = "3075550092"
"a2_428" = "3068382403"
"a2_427" = "3061215874"
"a2_426" = "3054050304"
"a2_425" = "3046882430"
"a2_424" = "3039714607"
"a2_423" = "3032546342"
"a2_422" = "3025365299"
"a2_421" = "3018196270"
"a2_420" = "3011031160"
"a1_208" = "502112649"
"a1_209" = "1786678668"
"a1_204" = "72132471"
"a1_205" = "2103148274"
"a1_206" = "3693463396"
"a1_207" = "4084002335"
"a1_200" = "2748362649"
"a1_201" = "1475142548"
"a1_202" = "3855385918"
"a1_203" = "2520896345"
"a2_395" = "2831794822"
"a2_394" = "2824625805"
"a2_397" = "2846143793"
"a2_396" = "2838980107"
"a2_391" = "2803124940"
"a2_390" = "2795958556"
"a2_393" = "2817458547"
"a2_392" = "2810293973"
"a2_399" = "2860477854"
"a2_398" = "2853310659"
"a2_379" = "2717090968"
"a2_378" = "2709922413"
"a2_373" = "2674087866"
"a2_372" = "2666921142"
"a2_371" = "2659737865"
"a2_370" = "2652573129"
"a2_377" = "2702753894"
"a2_376" = "2695581013"
"a2_375" = "2688422065"
"a2_374" = "2681256200"
"a3_246" = "1746738975"
"a3_247" = "1753789374"
"a3_244" = "1765852765"
"a3_245" = "1773304572"
"a2_179" = "1283263001"
"a2_178" = "1276105128"
[HKLM\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = "1"
[HKCU\Software\Aas]
"a3_241" = "1744311672"
"a2_175" = "1254591269"
"a2_174" = "1247419075"
"a2_177" = "1268926457"
"a2_176" = "1261771087"
"a2_171" = "1225922260"
"a2_170" = "1218753429"
"a2_173" = "1240254554"
"a3_249" = "1801832560"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKCU\Software\Aas]
"a3_69" = "478110732"
"a3_68" = "470664173"
"a3_65" = "449123976"
"a3_64" = "442135145"
"a3_67" = "497168202"
"a3_66" = "489720619"
"a3_61" = "454263092"
"a3_60" = "413199509"
"a3_63" = "468244982"
"a3_62" = "461186391"
"a1_424" = "767282829"
"a1_425" = "878602679"
"a1_426" = "2168391953"
"a1_427" = "2336067756"
"a1_420" = "3157706324"
"a1_421" = "1896964810"
"a1_422" = "4172388786"
"a1_423" = "2649142777"
"a3_199" = "1409969486"
"a1_428" = "4229322224"
"a1_429" = "891687731"
"a3_338" = "2439897659"
"a3_339" = "2446886490"
"a3_336" = "2391856505"
"a3_337" = "2432846232"
"a3_334" = "2411437223"
"a3_335" = "2384801990"
"a3_332" = "2363312101"
"a3_333" = "2403923972"
"a3_330" = "2348814115"
"a3_331" = "2356388674"
"a3_428" = "3084957701"
"a3_429" = "3058850980"
"a3_422" = "3041926607"
"a3_423" = "3049502318"
"a3_420" = "2994455821"
"a3_421" = "3001383340"
"a3_426" = "3070911299"
"a3_427" = "3077900258"
"a3_424" = "3022858881"
"a3_425" = "3029913376"
"a3_87" = "607024862"
"a3_86" = "633131711"
"a3_85" = "626081308"
"a3_84" = "585598461"
"a3_83" = "578085210"
"a3_82" = "571034939"
"a3_81" = "597665944"
"a4_183" = "1311949143"
"a3_89" = "654610320"
"a3_88" = "614067057"
"a1_439" = "3440898462"
"a1_198" = "1985758136"
"a1_199" = "1992128697"
"a4_148" = "1061029908"
"a4_149" = "1068199029"
"a4_146" = "1046691666"
"a4_147" = "1053860787"
"a1_196" = "223935773"
"a4_145" = "1039522545"
"a1_190" = "568502412"
"a4_143" = "1025184303"
"a4_140" = "1003676940"
"a4_141" = "1010846061"
"a4_380" = "2724265980"
"a4_381" = "2731435101"
"a4_382" = "2738604222"
"a4_383" = "2745773343"
"a4_384" = "2752942464"
"a4_385" = "2760111585"
"a4_386" = "2767280706"
"a4_169" = "1211581449"
"a4_388" = "2781618948"
"a4_389" = "2788788069"
[HKLM\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = "1"
[HKCU\Software\Aas]
"a1_0" = "3512574061"
"a1_1" = "3415466173"
"a1_2" = "3973878148"
"a1_3" = "2486709656"
"a1_4" = "4062365613"
"a1_5" = "2535777852"
"a1_6" = "1344768498"
"a1_7" = "1901979898"
"a1_8" = "1847778927"
"a1_9" = "3156892728"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"EnableLUA" = "0"
[HKCU\Software\Aas]
"a3_8" = "40388897"
"a3_9" = "47967552"
"a3_6" = "59977839"
"a3_7" = "67032206"
"a3_4" = "11991981"
"a3_5" = "52535244"
"a3_2" = "31040235"
"a3_3" = "4933386"
"a3_0" = "17001001"
"a3_1" = "23989832"
"a2_412" = "2953681646"
"a2_413" = "2960843556"
"a2_410" = "2939344157"
"a2_411" = "2946500570"
"a2_416" = "2982349119"
"a2_417" = "2989552386"
"a2_414" = "2968025075"
"a2_415" = "2975180161"
"a2_418" = "2996695520"
"a2_419" = "3003864742"
"a1_219" = "2921261615"
"a1_218" = "3487310416"
"a1_217" = "3196472199"
"a1_216" = "2445698658"
"a1_215" = "963134663"
"a1_214" = "1268962184"
"a1_213" = "971462524"
"a1_212" = "485846686"
"a1_211" = "2050094669"
"a1_210" = "2551788476"
"a4_443" = "3175920603"
"a4_442" = "3168751482"
"a4_441" = "3161582361"
A firewall is disabled:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = "0"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\c:]
"%original file name%.exe" = "c:\%original file name%.exe:*:Enabled:ipsec"
Antivirus notifications are disabled:
[HKLM\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
Firewall notifications are disabled:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
Antivirus notifications are disabled:
[HKLM\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusDisableNotify" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
| MD5 | File path |
|---|---|
| ad3f22e9968916196094a6805389c8c0 | c:\ermq.pif |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.
VersionInfo
Company Name:
Product Name: Application Installer
Product Version: 1.41.8.17
Legal Copyright: Copyright (C) 2014
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.41.8.17
File Description: Application Installer
Comments:
Language: Language Neutral
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| nBe523XI | 4096 | 696320 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| kI2t8P60 | 700416 | 327680 | 327168 | 5.54406 | 5799dcd08002476584c34f4f418f641e |
| .rsrc | 1028096 | 90112 | 90112 | 5.38725 | fe30594486ba11bbb2bc76401737b368 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch | |
| hxxp://softonic-analytics.net/blank.gif?product=st_activity&event=app_loaded&id_session=B35BB114-BA6C-4836-87C3-62F84268133A¶ms={"api_version":"1.41.8","country":"us","flavour":"17","id_file":"35586","machine_id":"a8a67a25000000000000000c298e22d8","os":"[OS:2600,5,1,2,1,256,3,0,Service Pack 3]","ts":"1435517384","url":"hxxp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch","user_agent":"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8"} | |
| hxxp://v1es.sftcdn.net/es/css/generated/2d9b4-b586d.css | |
| hxxp://v1es.sftcdn.net/es/css/generated/90f12-4e468.css | |
| hxxp://v1es.sftcdn.net/es/css/generated/b5ae7-7a102.css | |
| hxxp://v1es.sftcdn.net/es/js/generated/741c2-5ad42.js | |
| hxxp://v1es.sftcdn.net/shared/font/es/OpenSans-CondBold-webfont.eot? | |
| hxxp://v1es.sftcdn.net/shared/font/es/OpenSans-CondLight-webfont.eot? | |
| hxxp://v1es.sftcdn.net/shared/font/softonic/font-icon.eot? | |
| hxxp://v1es.sftcdn.net/es/js/generated/4cd46-f5ea2.js | |
| hxxp://v1es.sftcdn.net/es/js/generated/427b6-dd89a.js | |
| hxxp://v1es.sftcdn.net/es/js/generated/1467b-753f8.js | |
| hxxp://v1es.sftcdn.net/es/js/generated/40c2e-79a51.js | |
| hxxp://mvp-baseball.sd.softonic.com/shared/abp_detection/px.js?ch=1 | |
| hxxp://mvp-baseball.sd.softonic.com/shared/abp_detection/px.js?ch=2 | |
| hxxp://d1ykf07e75w7ss.cloudfront.net/aax2/amzn_ads.js | |
| hxxp://aax-us-east.amazon-adsystem.com/e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=6252925 | |
| hxxp://v1es.sftcdn.net/shared/img/interface/softonic-logo-inline.png | |
| hxxp://v1es.sftcdn.net/shared/img/interface/404.png | |
| hxxp://v1es.sftcdn.net/shared/img/interface/interface_sprite.png | |
| hxxp://v1es.sftcdn.net/shared/img/icons/icons_sprite_ie6.png | |
| hxxp://pagead46.l.doubleclick.net/tag/js/gpt.js | |
| hxxp://www-googletagmanager.l.google.com/gtm.js?id=GTM-WH2GLV&l=oGTM | |
| hxxp://a1294.w20.akamai.net/beacon.js | |
| hxxp://v1es.sftcdn.net/shared/img/icons/icons_sprite.png | |
| hxxp://pix-geo.revsci.net/gateway/gw.js?auto=t&csid=F09828&bpid=softonic | |
| hxxp://a1294.w20.akamai.net/b?c1=2&c2=15548145&ns__t=1435517391437&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= | |
| hxxp://a1294.w20.akamai.net/b2?c1=2&c2=15548145&ns__t=1435517391437&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= | |
| hxxp://v1es.sftcdn.net/es/js/generated/17ad7-e5cc5.js | |
| hxxp://v1es.sftcdn.net/es/js/generated/6d482-41450.js | |
| hxxp://v1es.sftcdn.net/es/js/generated/7c7aa-ad7c7.js | |
| hxxp://softonic-analytics.net/blank.gif?product=st_activity&event=app_loaded&id_session=B35BB114-BA6C-4836-87C3-62F84268133A¶ms={"api_version":"1.41.8","country":"us","flavour":"17","id_file":"35586","machine_id":"a8a67a25000000000000000c298e22d8","os":"[OS:2600,5,1,2,1,256,3,0,Service Pack 3]","ts":"1435517392","url":"hxxp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch","user_agent":"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8"} | |
| hxxp://aax-us-east.amazon-adsystem.com/e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=9268520 | |
| hxxp://pagead46.l.doubleclick.net/tag/js/check_359604.js | |
| hxxp://a1294.w20.akamai.net/b?c1=2&c2=15548145&ns__t=1435517393233&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= | |
| hxxp://partnerad.l.doubleclick.net/gpt/pubads_impl_65.js | |
| hxxp://pagead46.l.doubleclick.net/pagead/show_companion_ad.js | |
| hxxp://asset-pagefair-net.pagefairlimited.netdna-cdn.com/ads.min.js | |
| hxxp://asset-pagefair-com.pagefairlimited.netdna-cdn.com/measure.min.js | |
| hxxp://pagead-googlehosted.l.google.com/safeframe/1-0-2/html/container.html | |
| hxxp://www-google-analytics.l.google.com/analytics.js | |
| hxxp://asset-pagefair-com.pagefairlimited.netdna-cdn.com/adimages/textlink-ads.jpg | |
| hxxp://asset-pagefair-net.pagefairlimited.netdna-cdn.com/adimages/textlink-ads.jpg | |
| hxxp://asset-pagefair-com.pagefairlimited.netdna-cdn.com/adimages/adsense.js | |
| hxxp://www-google-analytics.l.google.com/collect?v=1&_v=j37&a=48384997&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCgAg~&jid=462484683&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=856759801 | |
| hxxp://softonic-analytics.net/blank.gif?product=st_activity&event=app_loaded&id_session=B35BB114-BA6C-4836-87C3-62F84268133A¶ms={"api_version":"1.41.8","country":"us","flavour":"17","id_file":"35586","machine_id":"a8a67a25000000000000000c298e22d8","os":"[OS:2600,5,1,2,1,256,3,0,Service Pack 3]","ts":"1435517394","url":"hxxp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch","user_agent":"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8"} | |
| hxxp://pagefairdotcomstats-1891079619.us-east-1.elb.amazonaws.com/stats/page_view_event/992B8C8C22834BFF/a.js?wl_div_hid_t0=0&div_hid_t0=0&wl_i_blk=0&i_blk=0&s_blk=0&is_ab=0&is_wl=1&new_monthly=1&new_daily=1&cbfnc=r02930926276206978&_=0.4337637090391104 | |
| hxxp://aax-us-east.amazon-adsystem.com/e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=4126714 | |
| hxxp://pagead46.l.doubleclick.net/pagead/osd.js | |
| hxxp://softonic-analytics.net/blank.gif?product=st_activity&event=app_loaded&id_session=B35BB114-BA6C-4836-87C3-62F84268133A¶ms={"api_version":"1.41.8","country":"us","flavour":"17","id_file":"35586","machine_id":"a8a67a25000000000000000c298e22d8","os":"[OS:2600,5,1,2,1,256,3,0,Service Pack 3]","ts":"1435517396","url":"hxxp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch","user_agent":"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8"} | |
| hxxp://partnerad.l.doubleclick.net/gampad/ads?gdfp_req=1&correlator=3153589255958014&output=json_html&callback=callbackProxy&impl=fif&eid=108809048,108809030,108809046,108809076,108809049&sc=0&iu=/5302/Desktop/Desktop-Web-ES/Error&sz=728x90|970x90|970x250&scp=type=leaderboard&pos=top&cust_params=plat=2&devel=&compliant=1&file=&kw=&tab_content=&author=&description_url=http%3A%2F%2Fsony-vegas-64bit.softonic.com%2Fundefined&dc_ref=http%253A%252F%252Fsony-vegas-64bit.softonic.com%252Fundefined&cat=null&contentid=&abp=false&cookie_enabled=1&lmt=1435517395&dt=1435517395937&cc=163&ea=0&frm=20&biw=650&bih=450&oid=3&adx=124&ady=117&adk=350405904&osd=1&gut=v2&oe=utf-8&ifi=1&u_tz=180&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=32&flash=11.6.602.168&url=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&vrg=65&vrp=65&ga_vid=1160059594.1435517394&ga_sid=1435517396&ga_hid=636576500&ga_wpids=UA-43493347-1 | |
| hxxp://www-google-analytics.l.google.com/collect?v=1&_v=j37&a=636576500&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCCAg~&jid=&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=979933613 | |
| hxxp://e5569.g.akamaiedge.net/ad/10496.js | |
| hxxp://aax-us-east.amazon-adsystem.com/e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=3747179 | |
| hxxp://a1843.g.akamai.net/softonicdfp884356052426/moatad.js | |
| hxxp://www-google-analytics.l.google.com/collect?v=1&_v=j37&a=365457603&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCCAg~&jid=&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=1285191312 | |
| hxxp://b.scorecardresearch.com/b?c1=2&c2=15548145&ns__t=1435517393233&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= | |
| hxxp://v2es.sftcdn.net/es/js/generated/7c7aa-ad7c7.js | |
| hxxp://partner.googleadservices.com/gpt/pubads_impl_65.js | |
| hxxp://asset.pagefair.com/adimages/textlink-ads.jpg | |
| hxxp://v2es.sftcdn.net/es/js/generated/6d482-41450.js | |
| hxxp://js.moatads.com/softonicdfp884356052426/moatad.js | |
| hxxp://tpc.googlesyndication.com/safeframe/1-0-2/html/container.html | |
| hxxp://b.scorecardresearch.com/beacon.js | |
| hxxp://b.scorecardresearch.com/b2?c1=2&c2=15548145&ns__t=1435517391437&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= | |
| hxxp://pubads.g.doubleclick.net/gampad/ads?gdfp_req=1&correlator=3153589255958014&output=json_html&callback=callbackProxy&impl=fif&eid=108809048,108809030,108809046,108809076,108809049&sc=0&iu=/5302/Desktop/Desktop-Web-ES/Error&sz=728x90|970x90|970x250&scp=type=leaderboard&pos=top&cust_params=plat=2&devel=&compliant=1&file=&kw=&tab_content=&author=&description_url=http%3A%2F%2Fsony-vegas-64bit.softonic.com%2Fundefined&dc_ref=http%253A%252F%252Fsony-vegas-64bit.softonic.com%252Fundefined&cat=null&contentid=&abp=false&cookie_enabled=1&lmt=1435517395&dt=1435517395937&cc=163&ea=0&frm=20&biw=650&bih=450&oid=3&adx=124&ady=117&adk=350405904&osd=1&gut=v2&oe=utf-8&ifi=1&u_tz=180&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=32&flash=11.6.602.168&url=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&vrg=65&vrp=65&ga_vid=1160059594.1435517394&ga_sid=1435517396&ga_hid=636576500&ga_wpids=UA-43493347-1 | |
| hxxp://aax.amazon-adsystem.com/e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=3747179 | |
| hxxp://aax.amazon-adsystem.com/e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=4126714 | |
| hxxp://stats.pagefair.com/stats/page_view_event/992B8C8C22834BFF/a.js?wl_div_hid_t0=0&div_hid_t0=0&wl_i_blk=0&i_blk=0&s_blk=0&is_ab=0&is_wl=1&new_monthly=1&new_daily=1&cbfnc=r02930926276206978&_=0.4337637090391104 | |
| hxxp://aax.amazon-adsystem.com/e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=9268520 | |
| hxxp://www.google-analytics.com/collect?v=1&_v=j37&a=636576500&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCCAg~&jid=&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=979933613 | |
| hxxp://asset.pagefair.net/adimages/textlink-ads.jpg | |
| hxxp://ads.rubiconproject.com/ad/10496.js | |
| hxxp://www.googletagservices.com/tag/js/gpt.js | |
| hxxp://pagead2.googlesyndication.com/pagead/osd.js | |
| hxxp://pagead2.googlesyndication.com/pagead/show_companion_ad.js | |
| hxxp://v2es.sftcdn.net/shared/img/interface/404.png | |
| hxxp://c.amazon-adsystem.com/aax2/amzn_ads.js | |
| hxxp://www.google-analytics.com/collect?v=1&_v=j37&a=48384997&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCgAg~&jid=462484683&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=856759801 | |
| hxxp://asset.pagefair.com/measure.min.js | |
| hxxp://v2es.sftcdn.net/shared/img/interface/interface_sprite.png | |
| hxxp://b.scorecardresearch.com/b?c1=2&c2=15548145&ns__t=1435517391437&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= | |
| hxxp://www.google-analytics.com/analytics.js | |
| hxxp://www.googletagservices.com/tag/js/check_359604.js | |
| hxxp://asset.pagefair.net/ads.min.js | |
| hxxp://v2es.sftcdn.net/es/js/generated/40c2e-79a51.js | |
| hxxp://aax.amazon-adsystem.com/e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=6252925 | |
| hxxp://js.revsci.net/gateway/gw.js?auto=t&csid=F09828&bpid=softonic | |
| hxxp://v2es.sftcdn.net/es/js/generated/17ad7-e5cc5.js | |
| hxxp://asset.pagefair.com/adimages/adsense.js | |
| hxxp://www.googletagmanager.com/gtm.js?id=GTM-WH2GLV&l=oGTM | |
| hxxp://www.google-analytics.com/collect?v=1&_v=j37&a=365457603&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCCAg~&jid=&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=1285191312 | |
| securepubads.g.doubleclick.net | |
| stats.g.doubleclick.net | |
| web.softonic-analytics.net | |
| pix04.revsci.net |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /blank.gif?product=st_activity&event=app_loaded&id_session=B35BB114-BA6C-4836-87C3-62F84268133A¶ms={"api_version":"1.41.8","country":"us","flavour":"17","id_file":"35586","machine_id":"a8a67a25000000000000000c298e22d8","os":"[OS:2600,5,1,2,1,256,3,0,Service Pack 3]","ts":"1435517394","url":"hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch","user_agent":"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8"}
HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8
Host: softonic-analytics.net
Accept: */*
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:26 GMT
Server: Apache
Set-Cookie: softonic_analytics-admin=deleted; expires=Sat, 28-Jun-2014 18:49:25 GMT; path=/; domain=softonic-analytics.net
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-control: max-age=0, must-revalidate
Pragma: no-cache
Content-Length: 35
Connection: close
Content-Type: image/gifGIF89a.............,...........D..;..
GET /35586/universaldownloader-prefetch HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: mvp-baseball.sd.softonic.com
Connection: Keep-Alive
Cookie: PHPSESSID=36129f33a16f1c00fc01bccaff2431f5; blang=en_US; country=UA; ucountry=EU; entry=Direct; gtm_vl=1; usess=true; SAUID=31198227327810681435517391624; visit_website=2; _ga=GA1.4.1160059594.1435517394; _dc_gtm_UA-366832-1=1
HTTP/1.1 404 Not Found
Date: Sun, 28 Jun 2015 18:49:26 GMT
Server: Apache
Set-Cookie: softonic_es-admin=deleted; expires=Sat, 28-Jun-2014 18:49:25 GMT; path=/; domain=softonic.com
Vary: User-Agent,Accept-Encoding
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-control: max-age=0, must-revalidate
Pragma: no-cache
Content-Encoding: gzip
Content-Length: 10405
Connection: close
Content-Type: text/html; charset=utf-8...........}.n.I........4iu..W.[.(jVs$.=..`....U..E.m*...\.l../>...
.}0.{..|.6`..0p.'..0..?8"3.~."Gc...;....[FFF.........7g.d.......M#...u
.......7.'.E..O.x....sb...B.7X1.....{.z....%.._.S(2......y...@Eh......
........rw....w....Z.....K.........N.[....~.....]z]....IT............u
...a...[.m....5.O`.....#D#gw.[..%.K...N.S...$..#.... .s.LZa...[...8.f.
.....^`.N. ....KxK.%%(.5(.,}...C.F..oC.[.>%.d....X....pm.!....1....
....(T..t......z..{.>..qmZ...as|.$.P_......v..E....k6'...q%6z.....4
.a......N,b.K..Iw....K..w.n.S*..U.x.n.].H.F.;....|\....Hu6w.....d~..00
..:.....W.;J;.a..IC....C.C.t..SkM=...R..o. .x$........!.............X.
:.b{l.4..j.`tnZ.A../........xt..Q.....~.:...md...L..&.\.^.}a..%.z.....
>...a..........r.n...XP...e...M.....a ..Ws._.P..k....S.X~....v. [M(
.bz....'.\...{$.......NZ..P...-4...a..._;c.....i.*[email protected]..
..2.Er.,w...].s..dB.*.A....=.Co..fQ-1.....~o0.$..b3t.%fRY)..X.......9.
.W^u1...i.*.....{......J.....6......vJ....oB....9.].g.>....g.0.r.@.
..5." .-.....ES..Z.e.....n4.........r.X.A.{...P-I....d.di......P....~W
T...(.13.(.G#<4..cm...kT..h... V@^....../.....=:...x9z..9....!O..pu
..q5..9.....Bo.U.....>&.c..W.S.I,e.=...,[email protected]....{
..uo<....5...%oM.z..H. |c...j..FK.e.J..CH.....a.....l.<..`..7..v
F..<...)...B.mE"..p..F\..t.3.......i......?..1..t.....`<....g.=!
.f...U....fk, .[m.R..}[email protected]\[email protected]..
B........(.-.o. ;...P.7O...Z.U..M...J$Q.H..Z. u.5XQ.f..,...U-....<.
..h...8<0b....(..3..`..a... .9..D.........HG.D.0......biui.Y...<<< skipped >>>
GET /analytics.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: VVV.google-analytics.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:01:46 GMT
Expires: Sun, 28 Jun 2015 20:01:46 GMT
Last-Modified: Wed, 27 May 2015 21:02:55 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 11093
Age: 2859
Alternate-Protocol: 80:quic,p=0
Cache-Control: public, max-age=7200...........}iW....w~E\'.U..e...6.^.L$.I.l.,.$......!....~...28.......j
k...,ux2..i.4.......21C5........x44..8I..C=...d_NO[...7*."..33.e.{2>
;..I..W..[......2....ZNe ...\N.i ~.$...i fI.2#.....S....$....t.......T
.g......M..A..>I..HI.&...9......l46.....l4..%*.$.....F.g..H...bJ.h.
.8........x<.f.Tx6.Z...%....Lh..ht..43..ht...4..i..!........`.Q.f.{
..vDW4.3.M...<..~b.B.....Wc*8.\5..z>.5....NeFH.......c..zi..S.zN
....!r...H...~ONGY ^&..Q.....F{.K.....ZX..*........I|....Nw...:..1...2
..M*u_.n....NFY..-.tE..[...x.m..j.....j(;..d0.*i.a.Mn}.klm..~....mK.f$
....Ov.>{......{...o..;z....._..T...N.?......g6.....]..7.76.<|..
...A.Ne.=....M=j...y... ...'.3..t24.......Z.40E.9J....p|.T.f.TS....F..
$'^h...h............-&.d.P...S..#..5jKZ. BN.Q...nn.U]7..5.F.[...}z.[..
xXQ.L...&.j....1r....<(H.......gK.vF.......L^u..!.c_MGG..;;..B.....
..{....W.$ruu...........sP.E.Li-m...{k.\ .....L..di?.-;oU7.}..O...z.z.
...z..j..\L.......h..s.C ./q....N.0sr..Dz4.s1...5.......R...T.P...]f..
..k......N.-L_(..lgW.2.Z?. ....L..d...0. JT*:jR.t*.)....|....*5...8Bh.
k...h>.....1..P,.&*....N.6....i......2..j....41.R"(*&.B....d.......
[email protected]<.....a....Y..:e&.bh..ty...=.N..&m....n.Yw.~-,...AP..s
..`......8.hC=.......Z.ibb\&.L."4..q...q..V.w....a.o...A.V..b6E......$
Q77..o..I......F"......m.K? ...}O.>...K...P.WD.....B.:..{...O......
.$N%......}j.Z.6D..3D...n."u...6M.`E=:#..?......Y:=PI.....$....`b..f3\
BR.-..!.....c.vf.&D([.q.a`Bs.........Yq.K.t..L.m.u..U..i..j..-.n.j7T..
f.5..F.4..<.......st.........KK..`%*ji...H1..........t.}.\.8..d<<< skipped >>>
GET /collect?v=1&_v=j37&a=48384997&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCgAg~&jid=462484683&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=856759801 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: VVV.google-analytics.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Pragma: no-cache
Expires: Mon, 07 Aug 1995 23:30:00 GMT
Access-Control-Allow-Origin: *
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 24 Jun 2015 17:11:24 GMT
Server: Golfe2
Content-Length: 35
Age: 351481
Alternate-Protocol: 80:quic,p=0
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidateGIF89a.............,...........D..;....
GET /collect?v=1&_v=j37&a=636576500&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCCAg~&jid=&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=979933613 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: VVV.google-analytics.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Pragma: no-cache
Expires: Mon, 07 Aug 1995 23:30:00 GMT
Access-Control-Allow-Origin: *
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 24 Jun 2015 17:11:24 GMT
Server: Golfe2
Content-Length: 35
Age: 351484
Alternate-Protocol: 80:quic,p=0
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidateGIF89a.............,...........D..;....
GET /collect?v=1&_v=j37&a=365457603&t=pageview&_s=1&dl=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&ul=en-us&de=utf-8&dt=Softonic.com - Página no encontrada&sd=32-bit&sr=1024x768&vp=650x450&je=0&fl=11.6 r602&_u=QCCAg~&jid=&cid=1160059594.1435517394&tid=UA-366832-1>m=GTM-WH2GLV&cd1=none&cd6=none&cd5=none&cd43=no&cd4=none&z=1285191312 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: VVV.google-analytics.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Pragma: no-cache
Expires: Mon, 07 Aug 1995 23:30:00 GMT
Access-Control-Allow-Origin: *
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Wed, 24 Jun 2015 17:11:24 GMT
Server: Golfe2
Content-Length: 35
Age: 351486
Alternate-Protocol: 80:quic,p=0
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidateGIF89a.............,...........D..;..
GET /gpt/pubads_impl_65.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: partner.googleadservices.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Type: text/javascript
Last-Modified: Mon, 22 Jun 2015 16:10:32 GMT
Date: Sat, 27 Jun 2015 05:39:08 GMT
Expires: Sun, 26 Jun 2016 05:39:08 GMT
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 34747
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=31536000
Age: 133817
Alternate-Protocol: 80:quic,p=1......n.....i[...(.._at..)n.M..H(.aK...Yf......o.l.`....zQK.I.<...L
......k/;...io4...k>.....v{)..:.;..x:.. ..^T...>_0.}....y...,..w
.x.T..Klk.\.......W(.. .a:......L..#..8.X^..'.D.......".6...#l.6..N'.a
...~.....D.*_{.ht.....5..\1.......l...xQC...ag....f.(Nz.8....t.....\..
8.L.....8....e..3lKTf9.s.;{(.^...Y..B....>a]Y...[......:.A..R....l.
\7.|.....{."^.-.t..9$.X\..). |..De....j..lV.pJ{.(.`.e...]..t$.....<
t...DC.)_.9......p....t6./f..........?.i.6.p ..............?..P...F5&g
t;...l^..01>....NS..........v'....d2..t .w.wr...#...q.S...,.O..Z.J.
.......K..i..L..B....L..,.....3&d.n.&..W..h.grcc...*SC5...k|.....O{.q%
.E. .=.^.}Q....=.[...\.....5.......{a.... .|.....8<.'..t>7.l....
X...X\|..PCH;...M..8....L..iF......4#..\......(tU.UB.v.l.. {....BBVp..
TB3.........h.s.....!K.]9...\vq.nn.............iA....Z...kYGZa[.,...C.
.U.T...3..y....S.^.Mx.; .m.....!([email protected]..<..TJ.....*e..)....z.q....
.3........A.[{.t:.P.EC.s.......Z...-.....U........,..I<......s...V.
Y.|}.4g.#.*W.......,mX....Y c...>.{p..K.,......../..O.p...#.Q.p....
F.u?Z.{.....EY...z}...}P..jv.l.............}..).Z.;..G.;._...G........
.......\.....B:....q...?...BWn...{.6.T g..e......YsaR.I.B.\S...I...A?.
7..z............h<...o.-.....B...o..t.....;.t..H(.m..*\G...........
G....v".X-...{P...t.r....0[.x....{.W......Io.N...~T.B./.?...]g..l5..~.
..q....a....U...4..s....a.....Ng..[.DB6,O$..:m...Db'K|.....TX...A>.
O]5.aq.#s...,...3...]6.........np..y...Cn.._q.XtJ\....{.<.....zL.qH
.C|.......8......./.!.....G.qN...`...#z...{.....%R....k.&^........<<< skipped >>>
GET /ads.min.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: asset.pagefair.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:25 GMT
Content-Type: application/x-javascript
Content-Length: 9073
Connection: keep-alive
x-amz-id-2: q5M5fPrqGaxXbVLKEbqAseop/U6e1Ecm 8qC76ne/fuvJZLjbAvA3EK2YQY 7pPXWnWTrH/VMLM=
x-amz-request-id: C56D30B40BEA5EC5
Content-Encoding: gzip
Cache-Control: max-age=7200
Last-Modified: Wed, 17 Jun 2015 10:11:13 GMT
ETag: "c4a457040f9037e09f2e179d7b052fbf"
Server: NetDNA-cache/2.2
X-Cache: HIT
Accept-Ranges: bytes.....G.U..ads.min.js..]y{.6.....fw.r.Q...4....lst...]U....EZ.).....w.g
...%.I.l...I\.f...`....B;..P.]q.#S..H. .L. .U6Y.......i,.....M3.0e. ..
l..lk {0..dk.Vc...P.......A..di..,..X...0.R..CG.D.,`..y.n..d.H.8..l...
f...<......7........Llcn..a...W...][email protected] ...3y...o...Oc..3.V
..&X.w".3........]l"..1.........p.z.h{[. ..h......UW..].D...Rd...V.:..
.V&.R?..i.dG...Z.9gq.'~8..q........T%.A.j4.Y.3......-.f.....f.....mPsS
..W.z}.h..U5&.fg.4..L..p.i'.<.#.R?.Rg..I.\T.>...\_......W.9...2H
..OV.G.u.B..^.,.P........|@zU..G.r4j>8r.s..h............Q..VDcgx.{8
<..R.~.`.Z....h.:-;..X..s]...(.*..F!...V.Q'........f...E.......:...
jH..L..A.. ....B.Z.......^4.D.........E.H...V.b..*\0.....xB.C...C..!Mh
<.C..!E@^7.>z.......q..<w.%>.K.....?.q..2m...Aj..4K..*....
.//h...>.\.N.....{.{..<.........6p...9.....43....AP..,.0......h8
..d....3..0eq.m....(r.u;..WH..\I...QLE..x6....T..IG.d.....X.E'......w.
.D.,..DS]j...m.Cl.:sE....5LS."....QL.....F0?.4..IL....T..w..v.........
*..U...Sl........A..b>.i>..O.r.....|.S[.[..5^.4.O.K ..g@.].CmM.v
:.n?.}Oa...).....D.Y.^N...y.........^..9....fb..VJGj..A...@. a......h.
[email protected]._........YA........hs....!..bR4....s....DW.
..HN.6-$...T..9.l2.A..p...N.3...).... [email protected]......(....Y5t.:wR...t.nU7t
..6.p..T.;..a7[.._\9|...;..'..%..)......"......).F}...>(..N.e..;..F
.../.;qp...R.s....[..*.p........}.H]X._p\Uepp'..r............~g...S...
.....l............7.w...Z.=<\RC.D..D.tj]..B..}ej}.._R.w........2.S(
.....o...s.,[email protected].[Q..).)...Iur...H..:m{.O..H<<< skipped >>>
GET /adimages/textlink-ads.jpg HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: asset.pagefair.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:25 GMT
Content-Type: image/jpeg
Content-Length: 229
Connection: keep-alive
x-amz-id-2: XgTw2t 8X4lILXnwUeM9bmZdHO7uRsZnEAXyB/xOUrOcYbde5l0pu0Zb IDeQuS2OShxGuWVrr0=
x-amz-request-id: 699879650B664685
Content-Encoding: gzip
Cache-Control: max-age=2592000
Last-Modified: Wed, 17 Jun 2015 10:11:13 GMT
ETag: "8ebe86738df782e51648901f67f22021"
Server: NetDNA-cache/2.2
X-Cache: HIT
Accept-Ranges: bytes.....G.U..textlink-ads.jpg...An.0.Dg..L..o..;.m/.E%..T... ....71...V@.
..5z...S..|l.[.....7...*.U.5...2.t:......5.B.6...R.K....W.e\/b....|S..
1...&.[..`[email protected].........%Z..m.%.(.oi.P.p..d.g....#&.z......../.
#.d...%f.|.y.........
GET /blank.gif?product=st_activity&event=app_loaded&id_session=B35BB114-BA6C-4836-87C3-62F84268133A¶ms={"api_version":"1.41.8","country":"us","flavour":"17","id_file":"35586","machine_id":"a8a67a25000000000000000c298e22d8","os":"[OS:2600,5,1,2,1,256,3,0,Service Pack 3]","ts":"1435517392","url":"hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch","user_agent":"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8"}
HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: softonic-analytics.net
Accept: */*
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:24 GMT
Server: Apache
Set-Cookie: softonic_analytics-admin=deleted; expires=Sat, 28-Jun-2014 18:49:23 GMT; path=/; domain=softonic-analytics.net
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-control: max-age=0, must-revalidate
Pragma: no-cache
Content-Length: 35
Connection: close
Content-Type: image/gifGIF89a.............,...........D..;..
GET /softonicdfp884356052426/moatad.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: js.moatads.com
Connection: Keep-Alive
HTTP/1.1 200 OK
x-amz-id-2: qRMimhnbrFpK/f/w9ac0/XAA4HPlK lh33i3jvpmdLgt21NVETqZYb2t999bDz5DzQpPPQpf8cI=
x-amz-request-id: 5B55CBAF9B005827
Last-Modified: Wed, 08 Apr 2015 17:19:58 GMT
ETag: "d41d8cd98f00b204e9800998ecf8427e"
Content-Type: application/x-javascript
Server: AmazonS3
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 20
Cache-Control: max-age=3600
Date: Sun, 28 Jun 2015 18:49:29 GMT
Connection: keep-alive......................
GET /ad/10496.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: ads.rubiconproject.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
X-Powered-By: PHP/5.2.3
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 7107
nnCoection: close
Content-Type: text/javascript
Cache-Control: max-age=1986
Expires: Sun, 28 Jun 2015 19:22:34 GMT
Date: Sun, 28 Jun 2015 18:49:28 GMT
Connection: keep-alive...........<ks.8...a.d...z...aR....w&..3.{.U.(...S$MR..Y...."H..3..
...J$...h4..n....O.hf.v.......oi...p.t....MG..~...O...(W...o.`i..OO...
.4..}u.s....o5.....~[..][email protected]..`[email protected]...
rH.C:m..........;....Xu..H...]J...^...^H...K............s.kP.b(.......
.H.;..n..W.a.\...\H.RH_.'.\J..AEw..xR.,......v.q@{\.!v.K0...zdP{=I....
...b.....y...}.J{.$...........q.//........yG..(HH.x..\.^.%G......r....
.......A...%B......dS.B...9...!t.M..a....#.......{A..I......x...y..Iw.
.0\2S...........h.I.....H..m.B........]..(ZOF#../..5.>...s.6.......
.$.b.t...n&.P.Yj}.b.:.....>..........r).W......q.uy...m\....x....%.
...@."[email protected]....... ....AO..cu^P,.d.I=.._r..aO..v...K.....Z...8.
0I....ai...J...\......<.....e..X.K.d]..&.....H...ud.v....Zr.8. ..Ab
.T;[email protected]{(./.O,..!..}.....6..................
/...tdw..\.Z..5.#;....HVq....PL...].#._7...jP9 b9'^.;.B.............i.
[email protected].. a......Oo........Y.......^...=...|.x,.<(..
.v!..N.r.3.`..2...7~...2....y....7#q...d.p.tZ.....Ok\fesV..8n...9..\.c
...te$)...ij..F............R.!.R......A....^...C.....N.r..\.....>.x
N....s.!.S!...?..k7I..e..*k2.....,Xf%-.Ga.e.jk.X.9....s......y.u..~zza
..X.opO..4..........K2G(....k....S.s...w.fsg....os.9.v...{....N..l.N.m
.....}.6..j'IlS.u..t1.........'..D.o9...y..Z....>...y..q.Z[;.|?|Hc
H".l.....$..[....9.d.../........x....<.....S...hYMA...:...!...A....
.3.......U..~_.D.......VL ..g..3.k........l4.6L...F.....y9..1e.....N.n
E....iF...Z#.........|.z.Xq..8:...v.......O6GP.dw..6#..5]..H......<<< skipped >>>
GET /gateway/gw.js?auto=t&csid=F09828&bpid=softonic HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: js.revsci.net
Connection: Keep-Alive
HTTP/1.1 200 OK
X-TraceID: 147b06620ee70040eaffe3d8a67ffad4
Set-Cookie: pudm_AAAA=MLuxM453B1zDlFHAtWs6Q2mzX02rW sFaUdfZRS0u5aM86kX D eNUcmcIWs3X6a2uZKonD8HcUiBkJsFzjucHZoKsLf4YmpVoNhzHB/L4TZi/GIjhxnpu9fcA==; Domain=.revsci.net; Expires=Mon, 27-Jun-2016 18:49:23 GMT; Path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="hXXp://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
X-Proc-data: pd0-bgas11-0
Server: ASI-Gateway/15.06.15-1777
Content-Type: application/javascript;charset=ISO-8859-1
Transfer-Encoding: chunked
Content-Encoding: gzip
Vary: Accept-Encoding
Date: Sun, 28 Jun 2015 18:49:22 GMTa..............200...Y[W...~._...h2 &....]\.DQ..mu.*. iB.s."....$$....
,_N?4...}I..U.cg.q.'.. .L6j.#. ..Gt..{h.!....-Y....&V..tW@......&.q...
..t..}...p.< .l...%K..r.7UO.Lj.j...xM......'..1..9^60...qju......U.
#N..%[email protected]<..../.!..Aa....0..F.du.r.2.N..{]v.<....W
).5.|.H.7.....[......U..*.gl.v..b.-....c.Wt..k.4..$._,....B.d6......z.
.^...8.C.$.!......DF..z.V.R.!3;f.`.....gHY.I ....z.3<U.......X`5..K
)....Kh...lM.3@....`...F....t.B!]F)..BM...d....h.@H3 .d..f..lv.x.|f..v
.) 1..."!...Re....LuSH.q.c......3.1...v0...f........L...200..xx. ... A
qe*..__.}F.0O./h..b.5....>(..3...<.YY......j.>0-.....:1VP.T..
L.Kp0...}0. A.j.....lA.}%.:*.3.......A...="x..#l....6....z.........Hu.
........'..%g`s....k.1..9.A..q..z;...&..Gjd. >..X...J.p.........5..
C..9.`hu...aJ:.U.xs......|...m..W.t..Oh..z"0t.%.W!}8..d..............q
!E. :......I.h!3...`3.q..z.s..pY.).2....."...:...C...c.d..."........V.
.....a|.s..>8.hL..o.r&3e.....v....`0e.;.........^...c..cut..5:.Vu..
...]7... .t. .7......k7.Z...3$qA|...j.gs... .!.r.cy.j.(d.....r..'d...
.P...;\.).....'...'...........200.....aO.....8xt...F...$... 9F......^.
.z.3e%SQ2.Q-......L..Cj.......!.......9ZS..j.){.tpP.j....0..".........
......2..l_a....N4..n.B.....y.....(s.. .nH..jT..n.h..Z......I.pB..@m.!
NyM.X:..D.@.#...$lIu.5.\......i.C..q.#...e..L. ..5!=hV`..Dvr.e...5h..C
..\..1..M%!.'J&.o..F}..z.Vy.O..H.w..L........OO..... ....4...2..?i.O..
<.OX*. 9......(.X9.%....>.F.8...a.1.Bb.V..t.Ukd[...$.@oq..,..p..
.A}j....T....y.....y.\.. ......7(.P..n.....:e.EJ....Z..ol?.....e..<<< skipped >>>
GET /gateway/gw.js?auto=t&csid=F09828&bpid=softonic HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: js.revsci.net
Connection: Keep-Alive
Cookie: pudm_AAAA=MLuxM453B1zDlFHAtWs6Q2mzX02rW sFaUdfZRS0u5aM86kX D eNUcmcIWs3X6a2uZKonD8HcUiBkJsFzjucHZoKsLf4YmpVoNhzHB/L4TZi/GIjhxnpu9fcA==
HTTP/1.1 200 OK
X-TraceID: a9eb0507196fae786d11f5d800b47cc4
Set-Cookie: pudm_AAAA=MLuxM453B1zDlFHAtWs6Q2mzX02rW sFaUdfZRS0O5aD86kX D eNUcmcIWs3X6a2uZKonD8HcUiBkJsNzjQcHZoKsLf4YmpVnrtAD21RFKQMp59HxdnpMVfaA==; Domain=.revsci.net; Expires=Mon, 27-Jun-2016 18:49:25 GMT; Path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="hXXp://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
X-Proc-data: pd0-bgas16-0
Server: ASI-Gateway/15.06.15-1777
Content-Type: application/javascript;charset=ISO-8859-1
Transfer-Encoding: chunked
Content-Encoding: gzip
Vary: Accept-Encoding
Date: Sun, 28 Jun 2015 18:49:24 GMTa..............200...Y[W...~._...h2 &....]\.DQ..mu.*. iB.s."....$$....
,_N?4...}I..U.cg.q.'.. .L6j.#. ..Gt..{h.!....-Y....&V..tW@......&.q...
..t..}...p.< .l...%K..r.7UO.Lj.j...xM......'..1..9^60...qju......U.
#N..%[email protected]<..../.!..Aa....0..F.du.r.2.N..{]v.<....W
).5.|.H.7.....[......U..*.gl.v..b.-....c.Wt..k.4..$._,....B.d6......z.
.^...8.C.$.!......DF..z.V.R.!3;f.`.....gHY.I ....z.3<U.......X`5..K
)....Kh...lM.3@....`...F....t.B!]F)..BM...d....h.@H3 .d..f..lv.x.|f..v
.) 1..."!...Re....LuSH.q.c......3.1...v0...f........L...200..xx. ... A
qe*..__.}F.0O./h..b.5....>(..3...<.YY......j.>0-.....:1VP.T..
L.Kp0...}0. A.j.....lA.}%.:*.3.......A...="x..#l....6....z.........Hu.
........'..%g`s....k.1..9.A..q..z;...&..Gjd. >..X...J.p.........5..
C..9.`hu...aJ:.U.xs......|...m..W.t..Oh..z"0t.%.W!}8..d..............q
!E. :......I.h!3...`3.q..z.s..pY.).2....."...:...C...c.d..."........V.
.....a|.s..>8.hL..o.r&3e.....v....`0e.;.........^...c..cut..5:.Vu..
...]7... .t. .7......k7.Z...3$qA|...j.gs... .!.r.cy.j.(d.....r..'d...
.P...;\.).....'...'...........200.....aO.....8xt...F...$... 9F......^.
.z.3e%SQ2.Q-......L..Cj.......!.......9ZS..j.){.tpP.j....0..".........
......2..l_a....N4..n.B.....y.....(s.. .nH..jT..n.h..Z......I.pB..@m.!
NyM.X:..D.@.#...$lIu.5.\......i.C..q.#...e..L. ..5!=hV`..Dvr.e...5h..C
..\..1..M%!.'J&.o..F}..z.Vy.O..H.w..L........OO..... ....4...2..?i.O..
<.OX*. 9......(.X9.%....>.F.8...a.1.Bb.V..t.Ukd[...$.@oq..,..p..
.A}j....T....y.....y.\.. ......7(.P..n.....:e.EJ....Z..ol?.....e..<<< skipped >>>
GET /pagead/show_companion_ad.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: pagead2.googlesyndication.com
Connection: Keep-Alive
HTTP/1.1 200 OK
P3P: policyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA IVD OTP OUR OTR IND OTC"
Content-Type: text/javascript; charset=UTF-8
ETag: 6354260028043789566
Date: Sun, 28 Jun 2015 17:56:57 GMT
Expires: Sun, 28 Jun 2015 18:56:57 GMT
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="f.txt"
Content-Encoding: gzip
Server: cafe
Content-Length: 75019
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=3600
Age: 3148
Alternate-Protocol: 80:quic,p=1............y_.....?..|[email protected]
.h$.3....xdZ.n.......1.<W%x..i4.OG...~.ZYs]o.|=..Y`..\..O...i......
.q.xW.V....kA9...f0.Of..z.4.q...-.3......<.F.Yo}....^.33-......3}..
\.-...Q...MQ....h.Z..,L.. w...(.y. .s.n{.Q...l.....U.j... ..;{.D.....;
.1..G..p].. ....}..d.O.....1<..N6.)U"2......<.<..gcl.<.7g.
..[....."..8.._..p|..H.....Y...<.......~4.....qc>..N....Z..S.D.R
..I4.=....8.z.....'.........=../.-l.G....V..$..XD.8Z...9.q(.AU.`...p..
f'EN..........<.\.N.B.4'S..aR.r.AZ6..6)j9.5.e_.n.....`............#
E.....z.7}...{.E....^.&.....}....va.G..@.....\..Yo:.[mL...h.m..rb.8..K
{I..1.h.;e..%.h5....*o9.\...H......O..l%...|..|..,.....p......\_...-KT
.......Oa...Y.6Z..!l..w......C......Az../......w.^.f./O.q.`4.#J'...4u.
.YT.....s#[.....l..L.._...N. ....6.tY.V.<......|.!..."V<-'B.8ZL9
...3...... ...Ho8`.hZ..]>.fv.llY..n9...qz......-W.].Z..%.\.-.IY....
.Q..O.i.....,A|....;1......gD.mP..a.....p.5.j%W./:....6..!..l.gQ....*.
......=.j.b......W.w...u.z.?.m..e^.W..7..U{.....8....^y.....#.w..P..mQ
..sG.iT..-.U,6Sa..y..o..;..^.~...z0h........}......k.... .&..yyR..nU./
*/....{...!....;..|..|....b.=.......;Q..r.N..Z.R..;.w.....n9...j.....G
....}VHT{5c.u..V....Fa?..w...a......S.)....:...N...9......D..x..>.R
B*F Eq..c....K.x....'c.Q....@.....?.&......7..m4u.*.gn~..E[.'....a..{.
x6.R.A.;....x..V\..!...s.p.Ya.<.a..=..N7O..Z..P.i-..D...Gk.........
J....f..8..b4.F.....]4...kZ,.)~&Em....Q.&..k...\..G..........uo8q.K.}.
..L...Q.T.7..1.."....l....P\....!$.K.'... U.%...a..Y.......WR..n.r<<< skipped >>>
GET /pagead/osd.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: pagead2.googlesyndication.com
Connection: Keep-Alive
HTTP/1.1 200 OK
P3P: policyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA IVD OTP OUR OTR IND OTC"
Content-Type: text/javascript; charset=UTF-8
ETag: 15849015797862681494
Date: Sun, 28 Jun 2015 18:01:55 GMT
Expires: Sun, 28 Jun 2015 19:01:55 GMT
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="f.txt"
Content-Encoding: gzip
Server: cafe
Content-Length: 21402
X-XSS-Protection: 1; mode=block
Age: 2853
Cache-Control: public, max-age=3600
Alternate-Protocol: 80:quic,p=1...........}iW....w~..f...86C......$..d q|.Z-.v...L..o.U..Z.H.=..l....
....t......z...h.*..;c..M8.~...t._..t...J..9..J.".Y..2.v;[email protected]
.9..V.Jr...1..'...s....ab/H.#..I *.....WW.$..q..N\....,..F^=n$.0......
)..|."......T..WL...YK.uR.?.vW..!.^D. ...e5...(w4g"_.,ur7L..2..4g..L..
.....4.....'./0..h..<Y......4.T.........p4.....dp1.u.......E.h..,..
...M.Z"tm.m.....C.f3.?.E..<.Of..i?N.N?...,.GY$..BK..hrw4........v.&
lt;.uda..88...j.u{K......$,*k..zgn-....#..6.$.%.kE.oaqR.E..-2.q.s#....
d..j{h...W.....1.. ..MJ..b.sv]...<5x..?....P..~..3{$....FL..%......
.. .,|.G-...d.Mh/...Z...=..,..F. h.l..|j.d...v.....T...Y.........*...S
M...T...M.\.ao...Z..-Y#2g..#r...e..C...^[y(.. ...7.=......u.,.1l.z..m=
....=8..9...5.j.k..{.......*...m.....P.... ...k>I*...l.0.k..f......
.G.....Aw.'..]........j;.../y..sYB..W.uj.*..=..V....k....L....v....s..
.....&.i..Ie...DL9@*.....R.4.N.)..qb.0.N.^.&p.q.._.9J.]....?.......\..
..'-.80...C.{...Vr.s.F.....Zu<.......p....0.H]L.....Sw'e._.$.......
8....c._.Ai..,.....g.EY.....B.=.P..zt...fx.....;....K.......|....|.Xp^
........?.'li...4.$.*.xS..m..c..........O....uc.LY..*k.......jk'.Zkkr.
...k5..;..&.9.......u........~.9.iA=7........G...m.y.(..o.ax#...p<.
.q}@U....a...Q.....!S.t..g..G.....V..e.M2TI.~]..N'...L...C..M..8....O.
1g..S...NT_...eT...9;..F`....S..E.......~..`.....!.i... >.H;.......
.J...[HQV..Xw...............1..vV...........j.m.........;...B(m....57.
;0.k...\s|.Dk..z.VT.hL.~.%.=%.y...!o8.N.....U`h...|..<.....5.. .`D
..@p:...$..O.........p.J5.u..BJ.v.\.Cpmn.K...NA...-....nm.}.%m...J<<< skipped >>>
GET /blank.gif?product=st_activity&event=app_loaded&id_session=B35BB114-BA6C-4836-87C3-62F84268133A¶ms={"api_version":"1.41.8","country":"us","flavour":"17","id_file":"35586","machine_id":"a8a67a25000000000000000c298e22d8","os":"[OS:2600,5,1,2,1,256,3,0,Service Pack 3]","ts":"1435517384","url":"hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch","user_agent":"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8"}
HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: softonic-analytics.net
Accept: */*
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:18 GMT
Server: Apache
Set-Cookie: softonic_analytics-admin=deleted; expires=Sat, 28-Jun-2014 18:49:17 GMT; path=/; domain=softonic-analytics.net
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-control: max-age=0, must-revalidate
Pragma: no-cache
Content-Length: 35
Connection: close
Content-Type: image/gifGIF89a.............,...........D..;..
GET /safeframe/1-0-2/html/container.html HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: tpc.googlesyndication.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Type: text/html
Last-Modified: Fri, 16 Jan 2015 15:36:52 GMT
Date: Sat, 27 Jun 2015 05:39:07 GMT
Expires: Sun, 26 Jun 2016 05:39:07 GMT
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 1877
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=31536000
Age: 133818
Alternate-Protocol: 80:quic,p=1......n....W{s....?..0.........X.....i...h.v;.dC....Wc..=..Wr.wwv.u.&l
t;..yR.=.l.|.jj..D.;......F}..."..;l..;.t..F........%..B..&.<..{J!.
.o.$.G..p.R...e.K....7-.._...<bD...0....'1s.i......3G.X..D.....L3G2
.x8.......8.D...?M(.<".pd.dI...%b>dIO.N.Cz..`...q1......x$h.I.#.
..s&.<..|..m.Ke$..\G.a$.ZC..D..D..<...G..|)....v..~2...Vx..m.)8J
j.....e.^.#Y..."0.}....!.....n:......!.b~:j.a.........g.t..n.`O../...V
^...I.Z.*"..,.1-..c.qv.Ib]JA.l. ....R.;U...<.k......}..U.....L...&l
t;..o...3..ni.|ze.M]..._.k.]....~.J..z.Z............$.S.p..AV.1.X...G}
..I..S@b...>h<M.....!......\e.K..K....b.M......-~.C....p.:m....x
[email protected].... .)s.B!.v..t..q........1...O<.?..".u...'>.N.
....9}.... .{h..%...-DZV.k...t..<.!a...*uD.%6.t......n...^8..>JN
.E..<..Op..u.......=s.B..Q.U.6v...%.o....y(...].V!...>*....{8.|.
N......Y5 .0.......?.....`c..]..\Rvz.GY......c....-....C79_.9..5.3..Vh
^....`......8.T.@|%.....t.OrU<RJ.Y.9.".u:..\X.x.....G._q.?Q......}.
.k.Q..kF....n0.m...v..l.......I.%.L.R0.....i,.$..26..."Q...sK..X..|...
>.|SRq:.Bh...q....k.M.....V..G.O.x.C.,.Ho.Z.F2.R9r.Z.z.uR_b.J`.?p^9
...e.rDv...#.".NR..G....m.x.9".......H.Xo....Q...'..S"...b...JFm...y..
.r....$......-.}..)K~O......j..q....xF*nS.n.g......aJ'L;..(.lhBy.....|
..;..0....c.......ws.8-..Jq........K......D[.C..P..........8...0N,..a.
_).X.g..q....s..=..T;..M..l.B....Z[.o.\...c..z....a.-..{ ...S1f.t....y
.nv...T.........>8I.|.Sb.......:...{C..._.Nq..H....Z8-...MT.F...X.&
lt;.jM.........Tuj.$.4..2..HPM$...Na...^.1....e9....*Z.8=...}.Y..?<<< skipped >>>
GET /shared/img/interface/interface_sprite.png HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v2es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:49 GMT
Cache-Control: max-age=172800
Content-Type: image/png
Content-Length: 64655
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:22 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 14625338
Expires: Tue, 30 Jun 2015 18:49:22 GMT.PNG........IHDR.......l......A......tEXtSoftware.Adobe ImageReadyq.e&
lt;...viTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.5-c021 79.155772, 2014/01/13-19:44:00 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap
/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#"
xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xm
p.did:2e34ddbb-1331-b845-be76-1698875a12c6" xmpMM:DocumentID="xmp.did:
DE39FB122F7711E48374DED760286C04" xmpMM:InstanceID="xmp.iid:DE39FB112F
7711E48374DED760286C04" xmp:CreatorTool="Adobe Photoshop CC 2014 (Wind
ows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:2e34ddbb-133
1-b845-be76-1698875a12c6" stRef:documentID="xmp.did:2e34ddbb-1331-b845
-be76-1698875a12c6"/> </rdf:Description> </rdf:RDF> <
;/x:xmpmeta> <?xpacket end="r"?>........IDATx....|T.....Lv...
!.BX....[T..0jE.b.Z........._.....^... m....V.kq.Zj..*n."K ..I........
.s...3sf2YH&...|&.....y.....}...|[email protected]}y.c .M.C%..T.>..v...&......@
;.4..9.#.#.#.#....HB2....`...c.([email protected]............
.............k...... [email protected]_..v\...P. ..
...8..u_...s~...-J....[....G.[..a........([email protected].
.{..n........Z,[email protected]
..D.......n.q...4u.;..T..Ym.....9G;.?.b:!.W....>.......=*.:1..-<<< skipped >>>
GET /es/js/generated/6d482-41450.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v2es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 03 Jun 2015 10:23:34 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 1158
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:24 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 1114109
Expires: Tue, 28 Jul 2015 18:49:24 GMT...........VQo.6.~..P.".3GI..m.iX....$...{0...O6...H*.....(...8....4y.
....N<:..).....6=..........;......t.q)...'150....3A..*[email protected].|>.zv
..w.n.}.Bi.5L.....O..S...2.\......k.4...g... ...P.t...:q../O.)..:\r.m0
..N.. ..\s..H..A.? .....r.1 ...._1L..R.%........H...|...E.*[email protected]
.OT{[email protected].......{.Z%y...3.,\...Y&0. &.fs0.g.9..Y.4
t. ...SZL.d.n..)O....'E..[..J.o.%S..j...........\.....^,.L.u.wk.V.P`P.
.c_9.E....fG`..u. ...}I...}..E.'..R....2pU.*............?.N.x....=...^
[email protected],....v6.........y...k......'....;%[R8..J..s@..|..uYe..g..
.3..K.[.`..'..S..Xt........u..........<_.Y..Ja...b....,z........"L.
l.cU/.NL..#.........jlw.F.WM([email protected]@..
.....\G..d8...r.-.....ti..G....V.yVy..k..Rm...9......X!....<.T..l..
...:.3.No.).......4.@..)..A{lc#%.....nTC{..O.J[.G.Y3 /p..f......;t....
Q..vg....*..H. .x3...s.<V.S...#....\.i.... ..1s..;AR...E0.Z....1..^
Me.*.......xx2......~L...Q.U.}l?4=.u.=......U.E...T..\VR...k)...9)*M..
...]Pk.'B...a.[......q.`..Z...:.W..>.&...eo..D.`.Y.l..l.....*..254.
?.$H1............X....Z.().u_.c...*..z5FaK.....n..ZU..M.BU/..?.R......
.....E...Z-.MOCcUv..0.hq...H..../I.x0c,q|.Z0[...l.........<<< skipped >>>
GET /beacon.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: b.scorecardresearch.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Expires: Sun, 12 Jul 2015 18:49:22 GMT
Date: Sun, 28 Jun 2015 18:49:22 GMT
Content-Length: 1140
Connection: keep-alive
Cache-Control: private, no-transform, max-age=1209600..........mU...6.}......CF.l/.4..k4.<.h. i.\..(.bK.....".{.e..M..".
3...sF..(_[3;...J..._..)A.m?).. <..U.V....ce.......R........J......
.$........{q.|...x#...;.[,.7....r'.p....p.6......7....K.A.Jv:....eJ..V
...vb...q.5..$!.........M.(b...=.q...sZ.6:...t<.Rj".0.X"#.Dd...f.5.
n....E0.*.E..tRy.>i`..\.......`!.Ed.^.....}..".~.l.?.9..6....s.1...
z?....e.K >..0....W,nd...k.....N.g.G?^:..(.cS0c<..V...P#Bjo....M
.....0..o...,....A.p.....\...Z'2T5.........^[email protected].....
........l`y..1.,.h.N......d.......< z<....c.g..G.f..M....._..M.3
=.|... .r.{-.. [email protected]..]G.<"..R/j........U.F.\..Q.c.A..u)....6_.=?..
....~q1I0.l....K^...$......f..R..j..A %J4Ip.....L;..m..i...~(......_..
A..z..Be .b'.....r..8".i.t&.......a.~..8..C....P&d.....*.M......'[email protected].
.b...Yp..v/l,.3G9.......2I..[....]`.X8.q..>%n..t..nW....!.. ...M...
...,.%.....>#k.g.A.jf..sC`S ..v.{[....$~F...|..zr!..hK}U.....N..S&d
"...v?$..|.V.4QWy.....T)K2.T.'........Ee.j<Ml:f@...{....i..7...d..Y
.7 .;.y..zmz\9.a.....Y..E.,.I....-e/V.%......Z.........../Y....)..O.6.
....h...G.8../.9.VzU.....C....P...s....Q..e.;.....>*.k._kd...9.qJ..
8.L........o......J-.P&.RY#.l}. ............g...g...".Al.......
GET /b?c1=2&c2=15548145&ns__t=1435517391437&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: b.scorecardresearch.com
Connection: Keep-Alive
HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: hXXp://b.scorecardresearch.com/b2?c1=2&c2=15548145&ns__t=1435517391437&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9=
Date: Sun, 28 Jun 2015 18:49:23 GMT
Connection: keep-alive
Set-Cookie: UID=15823a15a4aa14a551365cg1435517363; expires=Sat, 17-Jun-2017 18:49:23 GMT; path=/; domain=.scorecardresearch.com
Set-Cookie: UIDR=1435517363; expires=Sat, 17-Jun-2017 18:49:23 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate....
GET /b2?c1=2&c2=15548145&ns__t=1435517391437&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: b.scorecardresearch.com
Connection: Keep-Alive
Cookie: UID=15823a15a4aa14a551365cg1435517363; UIDR=1435517363
HTTP/1.1 204 No Content
Content-Length: 0
Date: Sun, 28 Jun 2015 18:49:23 GMT
Connection: keep-alive
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate....
GET /b?c1=2&c2=15548145&ns__t=1435517393233&ns_c=windows-1252&c8=Softonic.com - Página no encontrada&c7=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&c9= HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: b.scorecardresearch.com
Connection: Keep-Alive
Cookie: UID=15823a15a4aa14a551365cg1435517363; UIDR=1435517363
HTTP/1.1 204 No Content
Content-Length: 0
Date: Sun, 28 Jun 2015 18:49:24 GMT
Connection: keep-alive
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
GET /gampad/ads?gdfp_req=1&correlator=3153589255958014&output=json_html&callback=callbackProxy&impl=fif&eid=108809048,108809030,108809046,108809076,108809049&sc=0&iu=/5302/Desktop/Desktop-Web-ES/Error&sz=728x90|970x90|970x250&scp=type=leaderboard&pos=top&cust_params=plat=2&devel=&compliant=1&file=&kw=&tab_content=&author=&description_url=http%3A%2F%2Fsony-vegas-64bit.softonic.com%2Fundefined&dc_ref=http%253A%252F%252Fsony-vegas-64bit.softonic.com%252Fundefined&cat=null&contentid=&abp=false&cookie_enabled=1&lmt=1435517395&dt=1435517395937&cc=163&ea=0&frm=20&biw=650&bih=450&oid=3&adx=124&ady=117&adk=350405904&osd=1&gut=v2&oe=utf-8&ifi=1&u_tz=180&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=32&flash=11.6.602.168&url=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&vrg=65&vrp=65&ga_vid=1160059594.1435517394&ga_sid=1435517396&ga_hid=636576500&ga_wpids=UA-43493347-1 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: pubads.g.doubleclick.net
Connection: Keep-Alive
Cookie: test_cookie=CheckForPermission
HTTP/1.1 200 OK
P3P: policyref="hXXp://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Google-LineItem-Id: 59295179
Google-Creative-Id: 55073904419
Date: Sun, 28 Jun 2015 18:49:28 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/javascript; charset=UTF-8
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="f.txt"
Content-Encoding: gzip
Server: cafe
Content-Length: 870
X-XSS-Protection: 1; mode=block
Set-Cookie: id=22f24c85170400d7||t=1435517368|et=730|cs=002213fd48f20d546418284d1a; expires=Tue, 27-Jun-2017 18:49:28 GMT; path=/; domain=.doubleclick.net
Set-Cookie: test_cookie=; domain=.doubleclick.net; path=/; Max-Age=0; expires=Mon, 21 Jul 2008 23:59:00 GMT
Alternate-Protocol: 80:quic,p=1...........U.o.8..*..?{R..NHPu..E...U.........C...Ph....I .r.*...7...q
.AQ....*..|z.M......9'..5.E.q?2...Tz..'|CQ..../..JO...2.i!..Z"....<
.](....5.Y.f...Kk.*..w..{..d..d.{.2..).6Z.r>....2.i.8.......^(.....
g...... .n..C{\...R34..8.;^.u.".#'..P.A..V.F....4.._.O....,..5.|. 0.O)
...6.Gkn...vx....U4...e.......%.-/.....1.....~%%b...( S...3v......@-..
...q....{....s..........U..H....\...jSs.D...9.i"z...Kt[[email protected]..
...E.w.A.v...#......?.............`h...<.....2v]mG.Vd. ..d!....k...
..]......0.d..};6..9)1.r..x..X..9............*l.$.I..n$.....#.Ss.W....
.....x...z..Q.!.TQ..ZV..%..D....gz....H}.T......g'f#.I.O.4c....-..3..[
.h..K:_.......E]/jz......)<.\....S.x.%R.uaG...._..../.....rP0..,.9l
9 !s...|.....K....nP.y0....v..i<..E...n..G7../.d.....o.n...=...?...
.v6^.&... .......D.pS...M.....R..l.A...e}....P.3Ud.M...."K........R...
.R....:J.....m..J.4^o...([email protected].....<<< skipped >>>
GET /gtm.js?id=GTM-WH2GLV&l=oGTM HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: VVV.googletagmanager.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: text/javascript; charset=UTF-8
Content-Encoding: gzip
Vary: Accept-Encoding
Date: Sun, 28 Jun 2015 18:49:22 GMT
Expires: Sun, 28 Jun 2015 18:49:22 GMT
Cache-Control: private, max-age=966
Server: HTTP server (unknown)
Content-Length: 21272
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=0............i{...0.=...3$.Dq,K^.....@ ...8>y..&^..,...o-.R..0......
.....z.....o.G.vg. ..R..p..E..AP...z9...F.8..Eaac...&^w..r....;.4ruk#.
O...|.{..?.7.-..f.....B.&I...(.LG.\t................&,.'^.....v4......
i....>..Nwl.y)\O.....<.F.8.9.8...oQ0.\....i.7...'. .d.....3F....
YL....D9..rB.C....d.e.&....;h........&c......LBY..-....T..6...h..Y.B/.
.'..-m:....".6...m..D.b...h4y<....h..=H..:".10M_.M..KA{...b...G(!..
!...<......L!..AA.k..X ...Eq.Qdc..{.....,t.....#.D.....`26L].R8..4.
.y.....q..........N.z".x...s..s.......o....1wg...3..t......ZD..B.=,...
..;......b1.G...{...=w.J6q.p8.E.`..xq..>.-?#*...I4...O.n.....#./...
[..d.b0.G...^!z.../..GC6=....7...{;..FG..(...87...Od[*.........-..D7n.
*......6.....f^a0..K..n.r.%.....LF.$....D.h.L.#`...nhJ...P5a...u....&g
t;N...9..I..'...x8....X.y.....0Wt]w../!.BE.V3.?....p....V.i........U#H
...#.k.-G.......-..PY....n.....K..7..F..L(.........b8'.;..3o.).<h.~
^7N.../.....(.k.....x.i.E......qU.%...<>[email protected].
.....1zx..f.d.0..X..[..6vS.....<....vvH.".Q......d4...H............
..xg....k...}.z..U...Q..Y(!.f.....$W.....$2' ,.7....&4..U.D..*.#..t".~
.V?......".aK.PP}..D. ......g .m....~}.*/|.s....L.j...]u.....?..... _.
..4..`.P........CA`.M.1.....SU[4Y.PI.T..x-._...dN....B..M..* ,.6]...$.
..i..Y..`{B. 9...l..1..k.{[email protected]$.q..:...AYCZ/A.[...1 [email protected]
W..&ymK....*z.H...S........N:..j.S|......L.3......9.h. ..a......a..c.d
..E._......w..u...|.J>.......!S .....7y.iq..C.3z..#.fk.[..@',.....e
&...T....|....km.o.j..r.^..~Z).P#.W.2..e...s..rE........>.|.H..<<< skipped >>>
GET /stats/page_view_event/992B8C8C22834BFF/a.js?wl_div_hid_t0=0&div_hid_t0=0&wl_i_blk=0&i_blk=0&s_blk=0&is_ab=0&is_wl=1&new_monthly=1&new_daily=1&cbfnc=r02930926276206978&_=0.4337637090391104 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: stats.pagefair.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Authorization,Content-Type,Accept,Origin,User-Agent,Cache-Control,Keep-Alive,X-Requested-With,If-Modified-Since,X-CSRF-TOKEN
Access-Control-Allow-Methods: GET, POST, OPTIONS
Content-Type: application/javascript
Date: Sun, 28 Jun 2015 18:49:27 GMT
P3P: CP="NID DSP ALL COR"
Server: nginx/1.1.19
Set-Cookie: m_uniq=True; Domain=.pagefair.com; expires=Tue, 30-Jun-2015 23:59:58 GMT; Max-Age=191431; Path=/
Set-Cookie: d_uniq=True; Domain=.pagefair.com; expires=Sun, 28-Jun-2015 23:59:58 GMT; Max-Age=18631; Path=/
Content-Length: 46
Connection: keep-aliver02930926276206978('{"sample_frequency": 1}');..
GET /aax2/amzn_ads.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: c.amazon-adsystem.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: application/x-javascript
Content-Length: 4379
Connection: keep-alive
Content-Encoding: gzip
ETag: 295a622c70bd6d15cd989e7fc112f26a
Accept-Ranges: bytes
Cache-Control: public, max-age=3601, s-maxage=14400
Date: Sun, 28 Jun 2015 18:15:33 GMT
Server: Server
Age: 2027
X-Cache: Hit from cloudfront
Via: 1.1 f5d15668460b65c58e6a13f494ba5b26.cloudfront.net (CloudFront)
X-Amz-Cf-Id: j4k4eBoQYaVWv4MKlcl4RSqgwuwaJA9P3duU1PZKOGW5NvCFPV1KMw==...........[ms.8..~...].dDS.^..........&v./3u... ...P.. e ..._7.. E...
.....`..4....2..8g<s..[.H.....[H..\.8w..X..G.......LQ.c..S../H..L..
.).xn...q..$$..z..W....'.r.....u..A..)......f....W..^....#.......9....
o..bF...N.Y...D84.C....}.C..G..h....2.o.....A........w..?....?....Z.n.
.....E.xG..ot.d..y.?..~.-..2..K"w./......|...[S.&.....R....,......?...
...i. .....b9..$....3#b.2..j...c4.y..../.?...\S..)..VS.@.=.y.gu.......
..,Sz..r.....)....W.'4..X...C.Op..i..:.....K...'......ey.F=.P* g......
...,QZ.u..Z.?.....TN.e/H.G/.....m..^.....Oj..a.S7.7....VX....H...PY...
@.,.A..A.F6e2.Z.Q..&....(...5..O.Y...2'...........X....x...u.f4:......
1...6..(D.wd..pV *;A!..Apg..][email protected]^u.p.8.Y.i..4>
..Y'.*...V_..|..'.kPf...d....?.. ...EF.OhX...4...O..*......a1........Y
..0.v.....{C.......i.m}.C8(Is..Y...D;.............Q....F...PD.'..3.(..
.i....$`}...hvP..5.a0.&2... ..y=:.O....`......=z.G.G.7.`.M.$...Z....i.
\[.d.....`a....9..K.r...4q..l;Q..o.....*.z....6 :\7..8*....b.lY..b....
....ze.....Ozy:..l...us-$..~.A....|u..xu......k......~..Iiv.E[$.l...).
..^k.^..$.G.H...:B.....PE....<...W..l..#........!....).y...Ff.G ...
J9L&.G.LSo.....ß,e..=...*-q...._.n.C.=.x.u...@bG}.*...s.......k.&nd.
y...R.:..u`......J...6!A.q.sd..ES)..k...z.}r.fd.6..)..(...=..r...h..}.
......C..5..CD.o e.q.!*uZ.<a."xN.......[..*[email protected].
..{..P......r..vs...(lPr..E.Y,o..F.$.?B(.!8.*LaT_..m..m.^W.....2......
...z.X=.S.8.i.t.....8.v....V.Lt....R..9........e..?.D9....K.d.. .....h
.(.S1}@&ma.z. [.z=....~..~pB.G...5..E......Ty...1^....UE..I...[.-&<<< skipped >>>
GET /es/css/generated/90f12-4e468.css HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Tue, 16 Jun 2015 10:01:03 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/css
Vary: Accept-Encoding
Content-Length: 29567
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:19 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 7675233
Expires: Tue, 28 Jul 2015 18:49:19 GMT............i..F.0.}..W..[3...gwx..%....xl.=......MH .!.>......YUY.
.f..N.:.M.YYYWVVV.....]..{O...7}r.._...C.%Yu.[...|.'.....[..f../...7.&
gt;...y..../h.E\e..~5.....,.l'...O?...........G.}t.>]g..j.. ./..j.[
d..r..............6?...E.I.M.._.B.]T.... >..EE..._.B_d......(,.lA_.
.r...'.....l..<yF.Gh...$[/.4.R.$.........x....`._.E..C...!.4b...3..
#..<.w....#F.{Z...1.O.?....PG..#.cy.....e..|M..N...G.W.r_n..}.r..8
T8........DJw.R.....s.6i.. !..y....'...$E..H....].(...].W.....o...<
^..]]@~....;..d..BCt.....`........*_.E..=_.d\6.....v^|....".l...L....E
v..w....1..\>).%.p?........d.../.n.<.......m...v.y.,.[....O..<
;K.&....`....[....]y..^R....l...a.....o.h.\...x.....tj..D..$.Go...o.G.
...n....)D'.) Bv..S?.....T34HY8.v.....y$...!..4 ......?.........!..:..
...uk..EZ.F.......;[email protected].~....{.g.2HS.Z[U...``p
./.t.....y...l..3.cI.....?.......:..;T. ....*.-.....W..7.}.:.W....=r..
vd...^.....GFfMX}.:..zLv...d....7..6.'.H._.2......'s.......o_.l.].....
....?.5......_..m?...i.O..4...~Y............a.5............."%'.~.....
}v.'{w........}......C.....y.8M..%...!..`...g......t. .".V...p!^..&...
Vb.moz.}M..R`!@..]VU.$....'9.,)....7...xw...49..t... ....d...~uG{.....
......?QO.1;.|.)V.........7C.....x....dWnn.u.....>j|.Q.y....W....i?
./..P.y...'..v.....7....lr.Ai..xU....]..._.].o.~E.e2....h`..._...[.c&g
t;.......3.f..lL.c|!.EQD{w@Q{.@#..z.}.......w...I_....>:S..........
[email protected]..;2;;[email protected]..&..d..t..I...JB.-..c[WJ.N..=?.W.
.q.Z.d..jc%...h..`.'........z...E......UIy...7.U.,.2.........?..V.<<< skipped >>>
GET /es/js/generated/741c2-5ad42.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 03 Jun 2015 10:23:32 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 46119
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:19 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 15160302
Expires: Tue, 28 Jul 2015 18:49:19 GMT.............z.h.(......5*..(&%.0.,.U.vjK..b.A"E....`.s.g.7.........LY
....r.{.._..,.o9.yo..im=....g[..i.f..q8J.i...._....e....I......|9..e..
U:O..d.....<.g..83>-...`>H..d2..'..A....<..3.KU......n.@_.
.L..&.p.;....e..M...x2K...Ng.a.....r.Z.0.$...<..w.4..W...%w)...r9..
W..!,..d..o...'....~~..\/.~..g[....q.R.e.....I........m..f....m]..?o.=
.....`:.z7.f!.......,s5.O.{{.R9....-~x;...$...._....uf....ufV8.L.f...|
.V....o.&..f.....V..py .YN.W.v.... Z....>...&.lA...e...=...b8....'.
....._......w..........8......o.G..;?... ...I........G<W4.h..<..
g......W~x.t.~.8.......X.1....>L....6.g.#....{........aX.O.`.... &g
t;].......d....~.. ........R?.z..t.......V....C..9}.....}..:..n.m7/.g
...w.........x\z{.l.....`......O..?;......7o..O*..2......P..s.w...~..^
x.?_t.-......3..a....s....]d..../........%~......|\]d.g..&..B...K...C.
......./p.....^.......s......7.....r...=..'..].....|.H..p....b8\....6.
.t..F.;.va...{..u..........Ua?.......va.Bc...A....$y}.G.. ......ay..&.
...u^}|..w....N.8co}....-..a..}...[.7gs8.A.8p3.C...v...0...\g2......0.
.....j..S.....d>.?L.r..kf>....A~3z...k.kR....18.Q....N.:.....^a.
....7.k..".eDM's........z.....?........_....cT.:..~...........>....
........v.....Q...M....5 $.........t.Q..e.......qy...|...W....D..x...0
?.Y...... f......g..pa....\t.u.....a8.......4..d.%`P[.Hc.bo...`:.....O
.Gox..m9...._~Y.....j..r?....8...o..Y.KC..0..N..}...P..A...\N].Z......
:.=..-.`..D.... ...C.R........9:u.a.p..|.ew...y.O*n4P6.,..*.[N...*....
.-{&k.../...z...>.;9UX;DI....-k0..%7.Odx...f!4.ca.<.r.q|.p..<<< skipped >>>
GET /shared/font/softonic/font-icon.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:46 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 4355
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:20 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 211...........Yi...u.....k......rwg.3..c.sK<L..%-E].R&i....$...2i.....
.@.............. .0.`[email protected] v...U....K.g..z..].^..L3.[S.
qf...g_...}....<'......,{.]d.....>...2c!;.....g.y..>...{.-.a.
1..L.&.c.w..,..k.d.....r*...h...O...t...[.......[.|.y.u.......?.q.{._e
.t..sK...N..c.....<...5,..;..x...............xv....K...............
.M.f..K..}..o..IP......W.'.....L...1....Y.<....1.........1vk.......
.F....C....H..-......B...........Y..........q3.7.h..h..k.......iS4...:
xQf.D{^....w;.^.W,.544l../.!...*.E..eMgvC$...nc..f........Q.{..>g..
...k...H...mTW.-LS...(.[...4....;B.0.s.O.......]...#.._w,{...0, ..P.Kr
*`.....pnI..6A5....eQEZ....f.....8*....{9.w.."S...B...|....k.S.|.;....
.........z)9...S..tF.....u.. ..h. I ..A^U)...wU.*...6.._w..E...q^..GW.
......F.}..j.9..r..W.....#....C.:....j.r.~q^..."^..;.C.....h.j"..''RA.
T.,...~m*....=m.W.j..mw.q.'...L....[...\xQ...A ......l&J.B.T...Q. ..i.
.|H......z#.}i{..B.,Gz..:R...G3.L&....w....8..H< \....Ri.T.3.;.....
..I..0.z-A.$....L>.\..LK:.0..L>...~.?...a.82..x..*...L... .9....
%/.3{.u.[t.t....0%.im.....,.OL....r......r......h.........g..-.....$..
$d`#V #.. ..2.k..L..K.T..T[]......J..C..H^v..Yi&..K.<.g. 5.U.9/1.jW
{h.u.....W.N\...%[.Q...)..J.G...v..<.Q-$b."[email protected].^j..!n..,H..
Z..6.U..m..)R.-[m.S.:@[email protected] ....T..X..H....vm*.moh.M.i......kw.....
.|.....V2...xs.t.^.G.~eD.z]Z.)TU.....9q.A<....R%.#Nv..{.K.....D;...
n5[.^.v..b..x...I.q......jc.A.H.C.....h..5.x.@y..%r.....XR.R]J`Ex.....
..a&.Id..fbG.b...<..I.Z....I.U.S.....h..ONno...o.&.o.l..?..3...<<< skipped >>>
GET /es/js/generated/427b6-dd89a.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 03 Jun 2015 10:23:36 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 8244
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:20 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 880505
Expires: Tue, 28 Jul 2015 18:49:20 GMT...........<kw.....W.l.EZ0-9MkSAt...6q..I....>$1.H..............
..svsN,.....`f0..^...$...1...GF..w._.{..a...S.n'".FA.?.&...8..Q..{i.Hu
uE..1.....Xx.(..A...........g./......"/......7"....%..}h?6. ..O.xP...q
......9.2...8.yg............k.y<Q....,v..l?.f.....yq.Br.^.n.N.....0
....,..!....9{."&.....!....ol..1..7.._{W..;[email protected]....^/...^o..3
.L7....._....5......N...E...`".F..^...^.....z.......=.{eZ.F.g.pc......
e.../.e.-slY...... ....z}h.b#....l.T. .....8..^.......M...M.....Z..i..
.C..y..{..!....i.A....~.aFCd.#...a ...M....0.NG]XF..w..q.W.W..mo..\...
.T...2....!....g.0.Qvlk.c.z.....x.. 1K.~.7...../......h....0..6...9..f
......'O..........(....U<F.'...0.>^/.!..w....'f.{...x...>...w
S.-3...M..q%.............Dqf...B.Nj...U...-.9.....G.H...&.....3..:...&
lt;.B.*....&..U.S~.%.g ..D.8.2.c.0qs.$....H."q..s[L.A....1....I....,4.
. .%Q........1w... ........../.ww.y..;[email protected]..|B.ba......sf.
D..lY.M....,H./.d{Y..d~.....v...|lhA..TnI.._......~...t,.T../;.d..;...
.z...../kRw.'.0...d.~..rc.D.ld...~..vv^....a.<.....R..........G...`
q........(..<\...E^.a6>....$...Y....k.~.l <[email protected]....,..N.s..
.2..&..(....C.N...E >n....Q7....zoxdY6u.G$.(...Y0...p.....0I3.I.MB:
....R..I0.o...p..q$#.\.....V.2...._.....{.......4;;.y....X/..%...'...A
.........A...~0..x#i..t*" .NKZk...5....!\[email protected].(.......h...J...
8..L...Pl.`v.aI....o.h.Mg...*#7b<.....J....1.g..i.?.......]<....
.d...dW\.....-J..U......O.....k.V.X.<[[email protected]\.......?..A".B;.... ...M
O.#...........Xd&5.7A....S.j11..M.....f.......|....0w..{....A.u7..<<< skipped >>>
GET /shared/img/interface/softonic-logo-inline.png HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:45 GMT
Cache-Control: max-age=172800
Content-Type: image/png
Content-Length: 3167
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:22 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 15163856
Expires: Tue, 30 Jun 2015 18:49:22 GMT.PNG........IHDR.......$.....B.......PLTE............_.....q..[.. ....
................d..........................&..-.....f.....d...........
T........=......................................2........V...........i
..L........&..4........T........y.................E..............R....
....X.....V..'..........."..]..a....................g.....u..F........
..................).....?..s.....>..<.....w....................J
.....j.....T...........v...~................o.........................
............. ..............`.....&..G..r.......................Q..]..
z.....W...........Z..,........e..>..............p..(........~..%..D
..$..5.....J..b.....*...........[..m..<..:............|.B.....f..@.
...................2..8......}....L........|.....".....0..k..N........
...... ............................................A.1.....IDATx...uX[
Y.....;.....;V.i;..Swww/....m..b.)..Z<@ ......g..yI.2.-0...}.'.r...
.....##.!.H..f&.}!..@.../[..{...<p...#....=p..x.....w.xB.I.3...,.&g
t;......mS...&......k.4..j...YI./.Zp0.c.\.&...*&..A.DVS.41.9..E.B.GDFF
.).....I......&4n....U_JT...S"?.p..jR..eQ.62..vL.....#...R.Q...F....#O
..{....|[email protected]....?:b..h/..\5X.z.J.........#.e../O]n..'.....z.
....#jL..... ........ pa..Od(1..@o..........`.:.....J......scw9vw{D.8.
......i.D.[0.....*..K.q..wfAE.a..1{f;......J...=...Z..Rr..0.[O...}.UEl
k7*..G........'BO....6g....h..Ra.E3q...o......5.j...Z....v...u....4..7
k..M......V.:.^...ywMKJ...........m=$s.[. .w.7*g..J.]..j#!.m..}...rm.V
]..W....b.U.D"...hp.p......A.......K.:.r.......:(<b.%..].q...S.<<< skipped >>>
GET /shared/img/icons/icons_sprite.png HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:45 GMT
Cache-Control: max-age=172800
Content-Type: image/png
Content-Length: 8611
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:22 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 14303345
Expires: Tue, 30 Jun 2015 18:49:22 GMT.PNG........IHDR...n...K.............tEXtSoftware.Adobe ImageReadyq.e&
lt;...!iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.5-c021 79.154911, 2013/10/29-11:47:16 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CC (Windows)" xmpMM:InstanceID="xmp.iid:4D3A6133B67B11E39726BBB80
6C3259F" xmpMM:DocumentID="xmp.did:4D3A6134B67B11E39726BBB806C3259F"&g
t; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:4D3A6131B67B11E3972
6BBB806C3259F" stRef:documentID="xmp.did:4D3A6132B67B11E39726BBB806C32
59F"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
<?xpacket end="r"?>..I.....PLTE....b..Q.>g{..9.............=
....(H.....^...?{.n..\..n.d..Ve..)..'.....T....l,..7....FH.......pi...
........i.....}..%........~..s....N=..........f..O7...........}.f\.ZI.
...CI...^v..........d.S...;Xw...P.<../.........i...k'..........&4o.
..yiR{.c..W.....*....L[..H....................(e......E...:c....Ok.024
.E.......~.....-..kkk...!w....0m.U..;Z.....j........H0............SSS.
......................................................................
......................................................................
..................................................................<<< skipped >>>
GET /shared/font/es/OpenSans-CondLight-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:45 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 13715
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:24 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 261............UT.L..g`...VVV...,.kpw.......-...........`....{.{.....<
UoW.u.....(.. .7@..<&2........8....:....eB.............*.|..?..x...
.... ..X.........E6....[m.c..G.=..............\..x.GH.........GK...p.7
y.........:....2..>?2.......[.PC..........L<UC.....8.9....Q.#~..
....>g..A..9u-...`.. .a ..l.inq ~.m..u.36.........1..%.7F..._.GE...
....IB..b.Y...[j..\.8...RN....*.RP..87..p...W.)`.......A..p.......P...
/V.ce.]W..*.......J $.t......Q...%.`a3..R..]e....r_t...^.z...0NW....3.
... *.]........3.........C.sm.....5pa$.'>.....c..1.6W.i).Zc...nZV..
`.uV4..O:......L.. .}.....^...I..t.....z1$y.@`.cz..iP}.........Dl.....
.^../.w...?.J..60.......e./CN.....u..b...@.#..*#....L..b.....6 3....q.
v@!"M....o.A .......s..Fd.5./...1.].Q.K]?....#) *..epx.........k,.$..7
ZO.p....L].....".....pQNE..q....j.,&.....:.. A.6.c.M.....^O.......[Yr.
..!.L.bB.fV6]...;;.........G-............V..t.xoQcA....]. ....<"$q.
......'.f../`......}....%...yq.....2.W..E=8..].%<X.|..'.:?.!...G...
.T.C...`..............,.y..qL...pnS..!.JY..G.e_.;.K0.....r..~<.C...
w....u.b%.^...Xa^.J.4.d...`...F..|....2d.~C...[...e~Tt..!........C,jy"
.FG....6...i.....I.....D{...l.#EI;.....Y8...b'[email protected]. .*.......p..c..
GH....\P.1..9Y...|x.m..F<`Py..ih.M...J...c|P[.E%6.j.....#.^..=.".,.
....%W.`.W/..|2..TG,K7.{U..| i...I..-.n...3mg....\.I(.c..d...).....G.=
......;..T.1Z..dW...Di.....L."...'$=.p$.p...QQ.Pn.w..%#/K..4.1Y..x..}Z
...*Q.....lTx.R".CD..%."H3.........P.G...T'..Dp.....E......Uc..-}&.3m.
f..K.k.,i-..06..$..GI..}h-y.....D...` Y..|....L.#.g..b.U.'....G...<<< skipped >>>
GET /shared/font/es/OpenSans-CondBold-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:43 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 14130
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:26 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 607............UP.N.%<30...0..Kpww.4..VVV...KH.. ..ww.....I.........]}
..sO...............o!..C.4.$02........i...@.=3(@....G.....p........@..
.....g..X....cr..........v.9........I....................x..;B..~.....
..y6$..).... .....>K..05.p4.R.......x........."G|Jz.{.A..N.~`.A1T..
9.<F.C......Z...H....0>}./i>'8.Jg.e.k.P.vX.Z.._E...23F./M.) p
Jr.....7..Bi..r.h.hV.... ...e.i....AJ.'.0.r.....L.\L.oD.,..0...e......
......e...]<........S\.MJ.8....R..(w.?....o.....e.u.fs.....m....0..
........f?..WsBmRR../.`.~...v.......(..6S......n_#.d6)..MVYEz-.2`:....
.t.e.l[Xyq*M.n..ZTw..~y...N..6nC..x.3D.....OD[.K...UV.......#.d.;F.^ .
...UH9I..Z~P...}H..I:.k.....AR...?7.kf.K..O 8...d..Mq....B.........M..
....|X...4....{....K0...~....`.w.;w...Ha.....E.J..rD?..nXr.9^:3.\T.9.s
..Y..T.\I.lA?^........HagT...~mb....[..m...'B.I.......~m.....`.l.2:..5
</i..m.b...`.......G.q9..yB(.X.......D.r.K"..E..-.r...s...ucK$.Q. .
.B.V.b{....=c ..D...........~g...!...)...!.....K.....NA....:.yLWlg..2S
........'....I..<......,z...1R..=.nz...Rv. .....S.b4..|...8{...1.).
...?B.....`.M.....1.....~.EWV......a.. h....y......*'.I.D.....I..S....
..)...P..5gk.I.8.~.].M,....F.i..)..s...b..M.......y...T.1..F.f..}...;.
........Z.b..b....k.klb..F.......E...H....L`.......a.)R.W...W...H.|$.2
.....=<.........T..i....-..}...}[email protected].$e......~?. ..EU.\e.."..%
..&d.)!.v.I02k...e.........8..e..MD.7/..`."!.=.V.........G>........
..b...4..c.8f.._..B~..Un.5ZRP.H..........-T...4J.'j.}m.t..)..!.XU.Z2..
.NG..;...>....v*[email protected]..[...<..`.....P.$"0..$r..^"<<<< skipped >>>
GET /shared/font/softonic/font-icon.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:46 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 4355
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:27 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 221...........Yi...u.....k......rwg.3..c.sK<L..%-E].R&i....$...2i.....
.@.............. .0.`[email protected] v...U....K.g..z..].^..L3.[S.
qf...g_...}....<'......,{.]d.....>...2c!;.....g.y..>...{.-.a.
1..L.&.c.w..,..k.d.....r*...h...O...t...[.......[.|.y.u.......?.q.{._e
.t..sK...N..c.....<...5,..;..x...............xv....K...............
.M.f..K..}..o..IP......W.'.....L...1....Y.<....1.........1vk.......
.F....C....H..-......B...........Y..........q3.7.h..h..k.......iS4...:
xQf.D{^....w;.^.W,.544l../.!...*.E..eMgvC$...nc..f........Q.{..>g..
...k...H...mTW.-LS...(.[...4....;B.0.s.O.......]...#.._w,{...0, ..P.Kr
*`.....pnI..6A5....eQEZ....f.....8*....{9.w.."S...B...|....k.S.|.;....
.........z)9...S..tF.....u.. ..h. I ..A^U)...wU.*...6.._w..E...q^..GW.
......F.}..j.9..r..W.....#....C.:....j.r.~q^..."^..;.C.....h.j"..''RA.
T.,...~m*....=m.W.j..mw.q.'...L....[...\xQ...A ......l&J.B.T...Q. ..i.
.|H......z#.}i{..B.,Gz..:R...G3.L&....w....8..H< \....Ri.T.3.;.....
..I..0.z-A.$....L>.\..LK:.0..L>...~.?...a.82..x..*...L... .9....
%/.3{.u.[t.t....0%.im.....,.OL....r......r......h.........g..-.....$..
$d`#V #.. ..2.k..L..K.T..T[]......J..C..H^v..Yi&..K.<.g. 5.U.9/1.jW
{h.u.....W.N\...%[.Q...)..J.G...v..<.Q-$b."[email protected].^j..!n..,H..
Z..6.U..m..)R.-[m.S.:@[email protected] ....T..X..H....vm*.moh.M.i......kw.....
.|.....V2...xs.t.^.G.~eD.z]Z.)TU.....9q.A<....R%.#Nv..{.K.....D;...
n5[.^.v..b..x...I.q......jc.A.H.C.....h..5.x.@y..%r.....XR.R]J`Ex.....
..a&.Id..fbG.b...<..I.Z....I.U.S.....h..ONno...o.&.o.l..?..3...<<< skipped >>>
GET /shared/font/es/OpenSans-CondLight-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:45 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 13715
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:28 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 270............UT.L..g`...VVV...,.kpw.......-...........`....{.{.....<
UoW.u.....(.. .7@..<&2........8....:....eB.............*.|..?..x...
.... ..X.........E6....[m.c..G.=..............\..x.GH.........GK...p.7
y.........:....2..>?2.......[.PC..........L<UC.....8.9....Q.#~..
....>g..A..9u-...`.. .a ..l.inq ~.m..u.36.........1..%.7F..._.GE...
....IB..b.Y...[j..\.8...RN....*.RP..87..p...W.)`.......A..p.......P...
/V.ce.]W..*.......J $.t......Q...%.`a3..R..]e....r_t...^.z...0NW....3.
... *.]........3.........C.sm.....5pa$.'>.....c..1.6W.i).Zc...nZV..
`.uV4..O:......L.. .}.....^...I..t.....z1$y.@`.cz..iP}.........Dl.....
.^../.w...?.J..60.......e./CN.....u..b...@.#..*#....L..b.....6 3....q.
v@!"M....o.A .......s..Fd.5./...1.].Q.K]?....#) *..epx.........k,.$..7
ZO.p....L].....".....pQNE..q....j.,&.....:.. A.6.c.M.....^O.......[Yr.
..!.L.bB.fV6]...;;.........G-............V..t.xoQcA....]. ....<"$q.
......'.f../`......}....%...yq.....2.W..E=8..].%<X.|..'.:?.!...G...
.T.C...`..............,.y..qL...pnS..!.JY..G.e_.;.K0.....r..~<.C...
w....u.b%.^...Xa^.J.4.d...`...F..|....2d.~C...[...e~Tt..!........C,jy"
.FG....6...i.....I.....D{...l.#EI;.....Y8...b'[email protected]. .*.......p..c..
GH....\P.1..9Y...|x.m..F<`Py..ih.M...J...c|P[.E%6.j.....#.^..=.".,.
....%W.`.W/..|2..TG,K7.{U..| i...I..-.n...3mg....\.I(.c..d...).....G.=
......;..T.1Z..dW...Di.....L."...'$=.p$.p...QQ.Pn.w..%#/K..4.1Y..x..}Z
...*Q.....lTx.R".CD..%."H3.........P.G...T'..Dp.....E......Uc..-}&.3m.
f..K.k.,i-..06..$..GI..}h-y.....D...` Y..|....L.#.g..b.U.'....G...<<< skipped >>>
GET /es/js/generated/40c2e-79a51.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v2es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 25 Jun 2015 10:00:19 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 38516
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:20 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 2208401
Expires: Tue, 28 Jul 2015 18:49:20 GMT.............v.H.(.~..Bw...HK...n.(o.l..-.%WM/...$@...@.(..x....y..y..
..[..ZS?v.....@IU.{.............|...h.eyP..E1.........z....0..y.5]....
..d.zE8...Xv.Q... J<?.:.7.....'.x..|..y.3<....y.e.. ...~..2..I..
.qp3.....-..~r.c?.&..KL...|.w...... ....e.O:.$.D..K.N.L......3..A./.E.
[email protected]/..a.t...$..$.`(..3.Z..jp..E>.{1..u.0......-...-..Q.
....c...._....0.\..M'...7.;.gp........q......c.a.>o.. ..0.....?.S..
.{0O...._)\.. ....3...".....n.1?...X...|.~T$Yg.\C...g.]..iA@C/.i..h.v.
L..........wO...}>c....."&....k/k.:.3w...S8w......u.8...'q.......D.
#w...u..A...,.... ...$...3.)M.m......:;[;.......a.:.......j;n.q.....p.
>......`....\...v. ...U...|..............}.......j..]~X..b....%..e.
.`.u-..e...\.-hY.....z...T$..{$..x..... ...N."w...Z.67.'..._......E.Qe
.{?u....8.....K.)8..n1......2...c.0...........t_Z.].._...pop.b..."9-2
....".R..P .u..s...F......#.w..[..=,....o.....\..;....n............L#.
.....On..Y..Y.l....m.8@..'.#...s.?v.....T?nn.t..#..i.eE..?...t."I.A..c
....?r.....q7....A.....R:..... ....V...IT.Za..d."....v. >c.......J.
......G.G5....4p..8.r..n.B.#.B..|v..^6Y..e;.v..............|.W#..M.'..
..H.@.'...K.h..q..n.....D...z..UI.3...dO...............p.Hx/....77...?
...(W.*..{. (..A..J..Q.....].D;.IP.O.8..C.X..%dX...G.`lf)$......BB*...
...6A.. .t.oD.,).....Y.@.;....Xq....&K.e.....B...tk..26L/....6......W.
..[[..' ....>..d0..H. `aY..;......G..I`>....E>mk3.;v....G....
z...-....e....... ..:].9...L..q?.2x4....#.......l..)d....Fj. 1..9r....
....h>...y.....?.I....Os..=....9IG<I..4..9.h:J...$.}v..~B...<<< skipped >>>
GET /shared/img/interface/404.png HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v2es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:45 GMT
Cache-Control: max-age=172800
Content-Type: image/png
Content-Length: 16763
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:22 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 57325
Expires: Tue, 30 Jun 2015 18:49:22 GMT.PNG........IHDR................s....tEXtSoftware.Adobe ImageReadyq.e&
lt;....PLTE..8.....P..h...........t...../........A.....O...........Y..
......(.....h........3............{.1..j..u..,.....q..5.........s. ..i
........:...........O..8..9..7.m....z./~.1..6..0..... ..2...........1.
....2.....2f....3..5..2..............6........1..... ..L|.......Lv.-..
S.....\..4..E........0...u.1..[..5..O........7........9........;.....H
..|.....0...........~..5.....J.....0......Y.,..W..3...........5..A....
....C..7..O........F..1...u./../..............>..:m.-..].....1.....
.../........B...s.&}.&.....t..4..o..2..1.....W..2..5..6..0../[email protected]
..0.}!..[..5.....>...n."........`v.%..=..0..5}.-.....6..,.....3}.8.
.....{.)o.3{.7s.......0../...........5..=.............................
........................v.....8..............F..4.....1........2.....'
..................&..>.IDATx......U....*i...2X.a..T...Gw.........6.
..(..D.W[..q.u.Z.Y.w].7..(*......q\.e..J..g.&.jd...zo..s....*[email protected].
.<.;..{[email protected]&..k/..q].._..th..S...Z..."...I.&u.. ..u....]Sw...t.
*.....O"Pn.s..Iz|..M........v...:..#!...Y!%.D1..|.t>K...TU........p
..'.t.t.1........i...G.-m.0..l..kJJ.)1-..C\Y....jv{e=.H.../X.f......lO
|.F.U.W..i..>vkg.E:.f1.....l|.W.. ..a.9/&.p..1...|j.5#..#.....Q..g.
T#......>...4.....r|E.Z....!..E>...BX`.T....9~c..F.QlG>..I..g
]...M.|w.~........lG....ub..jb.S.(..3..U.{L..u...#G.&.F............&.?
[[email protected][email protected]."..%Z...o..V.._vt.~..^&...V.
].....b.Q.......-..=_^0...K......}./...t.....Ot.Z.-Y.W......U/....<<< skipped >>>
GET /es/js/generated/17ad7-e5cc5.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v2es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 03 Jun 2015 10:23:33 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 271
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:24 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 803102
Expires: Tue, 28 Jul 2015 18:49:24 GMT...........P.J.0......f...M...xR.../"%.Nl$&%I......'Q...{.f. 6.:n.z..^
l/..l..bC......F.B*UK.... .p.u.}W...vF.hW...z....n.O..K..V..1.....=..|
/h..`b....)?..>.%...t.B...2...x..c......&4..M.R8...]|9..*.._.......
fJ..5.....M.YF.,.o..k..4X.....i....T..Q.......j..1:..G..'.......>....
GET /es/js/generated/7c7aa-ad7c7.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v2es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 03 Jun 2015 10:23:32 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 467
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:24 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 13121270
Expires: Tue, 28 Jul 2015 18:49:24 GMT..........}RM..0...W....h..S.W...li...^.....VcKA.o......4.&..@..{of.r.
.F........$M..7.yro@CX%.\.^....!U...Va.o[..qm.....y.k.#.~w...5s......O
....E.).....j4.R..'..B.....Z....a.z...Ae..2.|X=<r.{VG06`c..3..(K..?
B....=e;......F.D.6..^=..-..;.(.W>3Q.[R".........w.?N[....|.ky....E
....W..D.FoHZ9OS..),.l.d.....h%P..T......|..F.......!b.......VL....O.u
\.j."..F.;~....'..K$.d..-....9.1@'dS.p....f..8l..D..5h .=...7...-.O...
.d...p...Y \.w<F..e .k....`..?..%.C..EK#..g....I.'...HTTP/1.1 200 O
K..Server: Apache..Last-Modified: Wed, 03 Jun 2015 10:23:32 GMT..Cache
-Control: max-age=2592000..Content-Encoding: gzip..Content-Type: text/
javascript..Vary: Accept-Encoding..Content-Length: 467..Accept-Ranges:
bytes..Date: Sun, 28 Jun 2015 18:49:24 GMT..Connection: keep-alive..A
ge: 0..X-Served-By: generated..X-Cache: HIT..X-Cache-Hits: 13121270..E
xpires: Tue, 28 Jul 2015 18:49:24 GMT............}RM..0...W....h..S.W.
..li...^.....VcKA.o......4.&..@..{of.r..F........$M..7.yro@CX%.\.^....
!U...Va.o[..qm.....y.k.#.~w...5s......O....E.).....j4.R..'..B.....Z...
.a.z...Ae..2.|X=<r.{VG06`c..3..(K..?B....=e;......F.D.6..^=..-..;.(
.W>3Q.[R".........w.?N[....|.ky....E....W..D.FoHZ9OS..),.l.d.....h%
P..T......|..F.......!b.......VL....O.u\.j."..F.;~....'..K$.d..-....9.
1@'dS.p....f..8l..D..5h .=...7...-.O....d...p...Y \.w<F..e .k....`.
.?..%.C..EK#..g....I.'.....<<< skipped >>>
GET /softonicdfp884356052426/moatad.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: js.moatads.com
Connection: Keep-Alive
HTTP/1.1 200 OK
x-amz-id-2: qRMimhnbrFpK/f/w9ac0/XAA4HPlK lh33i3jvpmdLgt21NVETqZYb2t999bDz5DzQpPPQpf8cI=
x-amz-request-id: 5B55CBAF9B005827
Last-Modified: Wed, 08 Apr 2015 17:19:58 GMT
ETag: "d41d8cd98f00b204e9800998ecf8427e"
Content-Type: application/x-javascript
Server: AmazonS3
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 20
Cache-Control: max-age=3600
Date: Sun, 28 Jun 2015 18:49:29 GMT
Connection: keep-alive......................
GET /blank.gif?product=st_activity&event=app_loaded&id_session=B35BB114-BA6C-4836-87C3-62F84268133A¶ms={"api_version":"1.41.8","country":"us","flavour":"17","id_file":"35586","machine_id":"a8a67a25000000000000000c298e22d8","os":"[OS:2600,5,1,2,1,256,3,0,Service Pack 3]","ts":"1435517396","url":"hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch","user_agent":"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8"}
HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8 SoftonicDownloader/1.41.8
Host: softonic-analytics.net
Accept: */*
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:28 GMT
Server: Apache
Set-Cookie: softonic_analytics-admin=deleted; expires=Sat, 28-Jun-2014 18:49:27 GMT; path=/; domain=softonic-analytics.net
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-control: max-age=0, must-revalidate
Pragma: no-cache
Content-Length: 35
Connection: close
Content-Type: image/gifGIF89a.............,...........D..;..
GET /e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=6252925 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: aax.amazon-adsystem.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: text/javascript;charset=UTF-8
Content-Length: 8
Date: Sun, 28 Jun 2015 18:49:21 GMT
Server: Servervoid(0);....
GET /e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=9268520 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: aax.amazon-adsystem.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: text/javascript;charset=UTF-8
Content-Length: 8
Date: Sun, 28 Jun 2015 18:49:23 GMT
Server: Servervoid(0);....
GET /e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=4126714 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: aax.amazon-adsystem.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: text/javascript;charset=UTF-8
Content-Length: 8
Date: Sun, 28 Jun 2015 18:49:26 GMT
Server: Servervoid(0);....
GET /e/dtb/bid?src=3177&u=http://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch&cb=3747179 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: aax.amazon-adsystem.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: text/javascript;charset=UTF-8
Content-Length: 8
Date: Sun, 28 Jun 2015 18:49:28 GMT
Server: Servervoid(0);..
GET /shared/abp_detection/px.js?ch=1 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: mvp-baseball.sd.softonic.com
Connection: Keep-Alive
Cookie: PHPSESSID=36129f33a16f1c00fc01bccaff2431f5; blang=en_US; country=UA; ucountry=EU; entry=Direct
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:20 GMT
Server: Apache
Last-Modified: Tue, 12 May 2015 12:57:02 GMT
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Expires: Tue, 28 Jul 2015 18:49:20 GMT
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 236
Connection: close
Content-Type: text/javascript..........eP.j.!....aQ.1.^.,[email protected].
.&(ho\...........,.cx.}..]M.Q.!....SQ;.p..i.If.\@r_..3.[...5.....wGq&l
t;..=....!B..&b.T#...../l.x."...y......-6...N.....V.......L.\..u...I.;
......RF...gRSl....~..5..Z.....
GET /35586/universaldownloader-prefetch HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: mvp-baseball.sd.softonic.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Sun, 28 Jun 2015 18:49:18 GMT
Server: Apache
Set-Cookie: PHPSESSID=36129f33a16f1c00fc01bccaff2431f5; path=/; domain=softonic.com; HttpOnly
Set-Cookie: softonic_es-admin=deleted; expires=Sat, 28-Jun-2014 18:49:18 GMT; path=/; domain=softonic.com
Set-Cookie: blang=en_US; expires=Mon, 27-Jun-2016 18:49:18 GMT; path=/; domain=softonic.com
Set-Cookie: country=UA; expires=Mon, 27-Jun-2016 18:49:18 GMT; path=/; domain=softonic.com
Set-Cookie: ucountry=EU; expires=Mon, 27-Jun-2016 18:49:18 GMT; path=/; domain=softonic.com
Set-Cookie: entry=Direct; expires=Mon, 27-Jun-2016 18:49:18 GMT; path=/; domain=softonic.com
Vary: User-Agent,Accept-Encoding
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-control: max-age=0, must-revalidate
Pragma: no-cache
Content-Encoding: gzip
Content-Length: 10408
Connection: close
Content-Type: text/html; charset=utf-8...........}.n.I........4iu..W.[.(jVs$.=..`....U..E.m*...\.l../>...
.}0.{..|.6`..0p.'..0..?8"3.~."Gc...;....[FFF.........7g.d.......M#...u
.......7.'.E..O.x....sb...B.7X1.....{.z....%.._.S(2......y...@Eh......
........rw....w....Z.....K.........N.[....~.....]z]....IT............u
...a...[.m....5.O`.....#D#gw.[..%.K...N.S...$..#.... .s.LZa...[...8.f.
.....^`.N. ....KxK.%%(.5(.,}...C.F..oC.[.>%.d....X....pm.!....1....
....(T..t......z..{.>..qmZ...as|.$.P_......v..E....k6'...q%6z.....4
.a......N,b.K..Iw....K..w.n.S*..U.x.n.].H.F.;....|\....Hu6w.....d~..00
..:.....W.;J;.a..IC....C.C.t..SkM=...R..o. .x$........!.............X.
:.b{l.4..j.`tnZ.A../........xt..Q.....~.:...md...L..&.\.^.}a..%.z.....
>...a..........r.n...XP...e...M.....a ..Ws._.P..k....S.X~....v. [M(
.bz....'.\...{$.......NZ..P...-4...a..._;c.....i.*[email protected]..
..2.Er.,w...].s..dB.*.A....=.Co..fQ-1.....~o0.$..b3t.%fRY)..X.......9.
.W^u1...i.*.....{......J.....6......vJ....oB....9.].g.>....g.0.r.@.
..5." .-.....ES..Z.e.....n4.........r.X.A.{...P-I....d.di......P....~W
T...(.13.(.G#<4..cm...kT..h... V@^....../.....=:...x9z..9....!O..pu
..q5..9.....Bo.U.....>&.c..W.S.I,e.=...,[email protected]....{
..uo<....5...%oM.z..H. |c...j..FK.e.J..CH.....a.....l.<..`..7..v
F..<...)...B.mE"..p..F\..t.3.......i......?..1..t.....`<....g.=!
.f...U....fk, .[m.R..}[email protected]\[email protected]..
B........(.-.o. ;...P.7O...Z.U..M...J$Q.H..Z. u.5XQ.f..,...U-....<.
..h...8<0b....(..3..`..a... .9..D.........HG.D.0......biui.Y...<<< skipped >>>
GET /es/css/generated/2d9b4-b586d.css HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 03 Jun 2015 10:23:32 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/css
Vary: Accept-Encoding
Content-Length: 8749
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:19 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 2721073
Expires: Tue, 28 Jul 2015 18:49:19 GMT...........=k..6...W.fj.v".|.5..:v.u..zm..{kOE..D.EjIj.V.~..I.Iif.....
[email protected]......{.J......j......
<..}....>[email protected]..)(.7e.5YYL ..Mv...q...{^6M..z.
....,.{....fz...(..E.., ...?BZN.'O.,.....*.N..bX]<.aA..U....a.....j
z... .Zy.$.q5...9...f5..g..8M.b.).\.;f.].l.j.sH.9...../`.{.,..x.X..Y..
...GN.....Q..5......r...<\........u.GR...dr..6....{9........8.XV..H
m..S/.........Wg...u.J..1,&...Z..P.n...L....!G .... ..5....\.TIk......
.L........T~.[([/.V..........;..y].[(q..]*.....S...../v.{.z..=..i2.'..
......w_J4...Y..j...e.N...r.....J......YR.u.h.e........w7.....P.4.P-uS
=yp.c.N./|.`..T.\.fg...*.....e1..Z.P..P)`'..Z.......e.*:....w..u.qc.].
,.o..c...}.>?.o. [email protected]...=4N.~.vH ..2.....)8|.#....PMyg
S...>.b.......\.Y..^.E.OP. >. ~.e).%I...,H.7.........UU...8.3.H.
...Bh........7...g.s. s.}....A..... .yP...hOT<[r..3...cv...k3{]~.QA
j.@{.b.K..9....Ysh....iFF...0.d..yg...I.\$...>..S...1gL..Lq.@......
.....w/.........a..l../...J..lJ.e`xnC......:...Q4A3...7!m......PAg..Y.
*.V..Q._.....8.....H..H.V.O.4ij8.5n..Z.\.(.........5.B[..Vd....f2....g
&....z)r....M).A..%..G..v.r...PVq.^\.......F...l.._2....-..{P.qa2.B...
...;..3<g,w%...w.Qs....j..|......=b,.=..?..:..=.7$..p^jjZ......?..&
lt;.j..)...>....9C.1.P..&^..aa....j..4.k.....R....w]"Cq.-....../...
_.D.......'..1....3Q.3....W N.j........p...}.xf...."3..\..w8q..L.....N
VY.>,.........p.........pj....l.....>L..c....8..fVn.2......R.S..
..u....^#M..k....qV.rub...... ...s,..i.`M........-.f...S*?.....u:(<<< skipped >>>
GET /es/css/generated/b5ae7-7a102.css HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Tue, 16 Jun 2015 10:00:46 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/css
Vary: Accept-Encoding
Content-Length: 3165
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:19 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 325002
Expires: Tue, 28 Jul 2015 18:49:19 GMT............ko...{... ..]..g.8X..p@?\...(P...%.6/..#.89#..3....rr:...n
$...y.3.[p R........z...O......:.z..<*O...O_..O.............,....o.
.....xS...U..$,.......oBD[..H........Tfq.".c...O......W....D.gqL.?....
|...gz;.=|..5. ..#;7d...../....{NG..4.#..IyeI..O...6.C......f$..F4.[..
Hd....>....a........1.i.D.H@M|D......4..8....$.%.....9.....I~d...._
3.R..rT...i2>...k........1>..}I#.D.U.|..?.i h...$..QMs.n3..8.V..
......e ...#..i../...H.(..a<.V.$R...Qr.7..k.V.d.N....]$.c.H8n..!..s
H#.\.(U........=u.. ......&R.%.<?KS....5....y..OR$S.D..>........
.......p..bX/p.I...]._..a\_..Q.h..N.....d|.Z.$.I...W.d....r.S...YL.(..
...i.......(...|6.ym.l.......V.'H%Dn.T_5.h........v....O..0X)..tdaz..V
.....80......?......Ze.........qzH-g.\.0.2........<..{.\...jj..q{`a
H.s.d{@.SJ......,.m,b.:......H............1.....;&U....p....'..4..p...
,m..!d.w{.s.<..OK.f.9y76D.T$..=l.E.z]....O..j.9....z.(l..........(.
..vB.}.w..s\.[A..3..l...I'...._A........TL"Zb...a~..0.2..3..N~.v.Yu..Q
...{).8.f.......w..... ....T"a)....$._}...J.....8..!...r...!D^,y.#.5..
D(..n..............fC....,....a...=.]...@d. .Vy'....<U.J.5..|U...k.
.(I..'..#F...............$.{!.U..i.s....K....~...i..:('$...@.....}....
.D.;....j....M70...V.}.........Ky...;....:......^S......][email protected].........
.;.[x.h9..f...<Q.3>..lR..]...:i5*)...R.:...........z.[']...;.O^e
z.W.g).....m.....N Z..A.R....OUJ...O.d.............].AP.....3./..'.|0l
,..........(Y.........|.....j.L..KR. h....!....hx..r4....3w.g..Y..cDo.
P.b..o...S{......R.P~.R..]..B...2e.,....3.k2~a....X.....S)..v.q...<<< skipped >>>
GET /shared/font/es/OpenSans-CondBold-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:43 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 14130
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:19 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 279............UP.N.%<30...0..Kpww.4..VVV...KH.. ..ww.....I.........]}
..sO...............o!..C.4.$02........i...@.=3(@....G.....p........@..
.....g..X....cr..........v.9........I....................x..;B..~.....
..y6$..).... .....>K..05.p4.R.......x........."G|Jz.{.A..N.~`.A1T..
9.<F.C......Z...H....0>}./i>'8.Jg.e.k.P.vX.Z.._E...23F./M.) p
Jr.....7..Bi..r.h.hV.... ...e.i....AJ.'.0.r.....L.\L.oD.,..0...e......
......e...]<........S\.MJ.8....R..(w.?....o.....e.u.fs.....m....0..
........f?..WsBmRR../.`.~...v.......(..6S......n_#.d6)..MVYEz-.2`:....
.t.e.l[Xyq*M.n..ZTw..~y...N..6nC..x.3D.....OD[.K...UV.......#.d.;F.^ .
...UH9I..Z~P...}H..I:.k.....AR...?7.kf.K..O 8...d..Mq....B.........M..
....|X...4....{....K0...~....`.w.;w...Ha.....E.J..rD?..nXr.9^:3.\T.9.s
..Y..T.\I.lA?^........HagT...~mb....[..m...'B.I.......~m.....`.l.2:..5
</i..m.b...`.......G.q9..yB(.X.......D.r.K"..E..-.r...s...ucK$.Q. .
.B.V.b{....=c ..D...........~g...!...)...!.....K.....NA....:.yLWlg..2S
........'....I..<......,z...1R..=.nz...Rv. .....S.b4..|...8{...1.).
...?B.....`.M.....1.....~.EWV......a.. h....y......*'.I.D.....I..S....
..)...P..5gk.I.8.~.].M,....F.i..)..s...b..M.......y...T.1..F.f..}...;.
........Z.b..b....k.klb..F.......E...H....L`.......a.)R.W...W...H.|$.2
.....=<.........T..i....-..}...}[email protected].$e......~?. ..EU.\e.."..%
..&d.)!.v.I02k...e.........8..e..MD.7/..`."!.=.V.........G>........
..b...4..c.8f.._..B~..Un.5ZRP.H..........-T...4J.'j.}m.t..)..!.XU.Z2..
.NG..;...>....v*[email protected]..[...<..`.....P.$"0..$r..^"<<<< skipped >>>
GET /shared/font/es/OpenSans-CondLight-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:43 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 13715
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:19 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 293............UT.L..g`...VVV...,.kpw.......-...........`....{.{.....<
UoW.u.....(.. .7@..<&2........8....:....eB.............*.|..?..x...
.... ..X.........E6....[m.c..G.=..............\..x.GH.........GK...p.7
y.........:....2..>?2.......[.PC..........L<UC.....8.9....Q.#~..
....>g..A..9u-...`.. .a ..l.inq ~.m..u.36.........1..%.7F..._.GE...
....IB..b.Y...[j..\.8...RN....*.RP..87..p...W.)`.......A..p.......P...
/V.ce.]W..*.......J $.t......Q...%.`a3..R..]e....r_t...^.z...0NW....3.
... *.]........3.........C.sm.....5pa$.'>.....c..1.6W.i).Zc...nZV..
`.uV4..O:......L.. .}.....^...I..t.....z1$y.@`.cz..iP}.........Dl.....
.^../.w...?.J..60.......e./CN.....u..b...@.#..*#....L..b.....6 3....q.
v@!"M....o.A .......s..Fd.5./...1.].Q.K]?....#) *..epx.........k,.$..7
ZO.p....L].....".....pQNE..q....j.,&.....:.. A.6.c.M.....^O.......[Yr.
..!.L.bB.fV6]...;;.........G-............V..t.xoQcA....]. ....<"$q.
......'.f../`......}....%...yq.....2.W..E=8..].%<X.|..'.:?.!...G...
.T.C...`..............,.y..qL...pnS..!.JY..G.e_.;.K0.....r..~<.C...
w....u.b%.^...Xa^.J.4.d...`...F..|....2d.~C...[...e~Tt..!........C,jy"
.FG....6...i.....I.....D{...l.#EI;.....Y8...b'[email protected]. .*.......p..c..
GH....\P.1..9Y...|x.m..F<`Py..ih.M...J...c|P[.E%6.j.....#.^..=.".,.
....%W.`.W/..|2..TG,K7.{U..| i...I..-.n...3mg....\.I(.c..d...).....G.=
......;..T.1Z..dW...Di.....L."...'$=.p$.p...QQ.Pn.w..%#/K..4.1Y..x..}Z
...*Q.....lTx.R".CD..%."H3.........P.G...T'..Dp.....E......Uc..-}&.3m.
f..K.k.,i-..06..$..GI..}h-y.....D...` Y..|....L.#.g..b.U.'....G...<<< skipped >>>
GET /es/js/generated/4cd46-f5ea2.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 25 Jun 2015 10:00:18 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 6542
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:20 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 2016351
Expires: Tue, 28 Jul 2015 18:49:20 GMT...........\kw.H..>.B..rC.0...L&.#q"?.v'[email protected]......
n.t[.bs.<.9...._{x...T=aZ..'.{.n.c...IB0).{)...J.%..A........vN.N.{
!*..~.....U..<...^....=.I..e..QUM...n.R.e\.(S3Rm.r.K.uE2R..D[..,Gq,
.v./././W.,..J....&..f...$....~.V..7T\.....Y(.... .6..e.M.8M..!F.jZ...
.].k...^XcU......."d.....e..Q~..9.....p.G..C"b..R|'6.......de.g?.l..e
.....1.$...?.a8...1....IV.-\}.&%............yQ....V.*/.Rr.A.]C.....U
.d8)....9.|W#.b".m..z.. ..I..F.....;.q..R.....LO#....k.^... T.rx.d..&l
t;.`Y....q.F.5,...E<qcE.m*.o......i....Uy.a=.. ....]u...<.p.....
[email protected].^...3#G..7......Q._}DE.<.a;..|%...
k.2.O..Q.!..-. ..I#MX$W..._..$.y...m].......&Gp(..bS..7...-..M....h..=
..|...8'."....*........D~..a^U.xX.T.... '.5. .A5.(..a...........nb....
.wg.f.FdR..c....RA..xZq...3.@%.9'.r.B.C....Oj....b..k.iI..em.(.#C..i.9
..`[email protected].|...&1..)....-Lb.8...LY.R.5d.1*.b
.vL..........k.a...H7tP=.mNi........S.\..}....mH.. .FX.C.'.m.%.M>,S
.....C[w.....R......)(..M.W..nS%..B.t.....L.v.*<"....&.K....7t.(.|.
.nz....')...<.R..i.S" .V...c.C.....u..S. hP..oy.!..&P....:.".'%O>
;w..%..]l.`})y.q....8.fVpF..A.....C".y.amN3.t..(E.......Qb;...\).&.C..
8Rg.;.....5......A$B)..TEx..32|C..f.F_..%x...;.8T.......q.@4apXO......
.V.......,....:.. .......%...S.$..t..3Pu..bH.=..C...3.......F....#....
.Q.5.9..5........P...Ws........Y.I.-....A.t....je 9.^'.f.......&!.....
.P.z.aF].i5..Z@(U9...P...B.....M.a....T...VL.kq......!..9....i..@.$Rd.
.X."[email protected]#.t.|...yXqc.s:...GE...'. =.D.l.t.(#.e..p:%.<<< skipped >>>
GET /es/js/generated/1467b-753f8.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 03 Jun 2015 10:23:33 GMT
Cache-Control: max-age=2592000
Content-Encoding: gzip
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Length: 3794
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:20 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 14446719
Expires: Tue, 28 Jul 2015 18:49:20 GMT.............s.8.....v...`....3..$mg{..v....q]..a.10B.I.....$@`.fwz...
......$.ON..c..'....O.9y2...........,....{.5..U.....&.M..g#....:.=....
.i.%.ej._.......oo._..B.#,S..Yj......|.....~.w6.;Q.....K ....C....`.?6
WD.ovvu...u........Q.7!.`.X..[...[M...B.;.[...[R>.{...1.{....AG..(
....E....c..,=.....6qa..6Ly5.0.0c....#k...dz3snNO.......Uk.{...y.:Yd..
a!4w....^_.../m!.....E..x.2>....Kj..z.......AB...H..`..{.9J..u..".2
...5-..H.Q._"$...~.{...PB#..m.9e?{i.P.).Z.T............K..RN..k.......
..0.;....[.....]......g.[\.....~....,.7.....Y.f.K..\..0....3r..\...b:.
m.7C.-t...B.S...Gr.-#......w..sf..).E.....jS4.0.....g.X4..q......x....
.ot..67......w3r.<%.1...OL..bF HzK}..j3z..e...X.......t<3.j.....
...z,r0).tDt..:.J..F.N...v.6K.......Fqa....;.yM.2^.....F`...i.........
..7.v.2....../@.%...=~J.^,t... 6.x.A....A..k.K..W.......[.....J...L.;.
..Gg..N.....%GT...^...N?}...|[email protected].&D.^......).....<0..
....[.^.D...k,` ...<B`P!fi:Gb..gCD.i1...Hh.C.j..b...L.F. ..>U.0.
.\)L..8.{A..-......G.L..p.m<[email protected]..
5..~.d..cw.%.J../...!e...ay. .........2A.,m..2../......J1w.@.((.."..`.
...|.y..BY.. ..<(...R.....V.k8..;.l.[.[.k<^T.xM?g..}...~ .A.....
..K.....r.....dT..O.... [email protected]..
&q..C6e.w...WB]....8.YJ...6.J...<....v....kw..n. .b...".~..W..".)cs
[email protected]..%D..H.tT."0Q..&....Y^..#.e....][email protected] ..
......B....C....8.Z.....k..&../c..J.....C..#...L]...YpgC.......T......
.......j.......C&D.....bJ....m.F8../.J\..:xq...h.TXo...LFz..X.....<<< skipped >>>
GET /shared/img/icons/icons_sprite_ie6.png HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:45 GMT
Cache-Control: max-age=172800
Content-Type: image/png
Content-Length: 3842
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:22 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 178800
Expires: Tue, 30 Jun 2015 18:49:22 GMT.PNG........IHDR....... .............tEXtSoftware.Adobe ImageReadyq.e&
lt;...diTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap
/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#"
xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xm
p.did:9E962B544069E211B7EB8D9DB40552B0" xmpMM:DocumentID="xmp.did:43F6
853AE30911E2B1CF8CF7F1C405D4" xmpMM:InstanceID="xmp.iid:43F68539E30911
E2B1CF8CF7F1C405D4" xmp:CreatorTool="Adobe Photoshop CS5 Windows">
<xmpMM:DerivedFrom stRef:instanceID="xmp.iid:EE241FC406E3E211B5E5CC
7696148C04" stRef:documentID="xmp.did:9E962B544069E211B7EB8D9DB40552B0
"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> &l
t;?xpacket end="r"?>........PLTE...e..........5...r...4.....YC...l.
..=$.L4........4..-..5.}l.......tc.....{........,.<".Q9..5...z.....
........s..........8....................bM.............H0.............
: .F........D,...k...n\.......B)....?&................................
......1...|.3k...]H.......iU....M6.........................D*.......H/
.......zi....2.......b..j.,.B(.... .....A(.......WA.J2..5.K3n..k..m..l
..Qt.j..Xz.c..]}.Tv.Uw.^~.Ru.Sv.\|.Zz.[{.Vx.Wy.i..h..f..g.....`.._~.b.
.a.............5.......K4....E-.......J3.K2.........r./..,........<<< skipped >>>
GET /shared/font/es/OpenSans-CondBold-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:43 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 14130
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:24 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 282............UP.N.%<30...0..Kpww.4..VVV...KH.. ..ww.....I.........]}
..sO...............o!..C.4.$02........i...@.=3(@....G.....p........@..
.....g..X....cr..........v.9........I....................x..;B..~.....
..y6$..).... .....>K..05.p4.R.......x........."G|Jz.{.A..N.~`.A1T..
9.<F.C......Z...H....0>}./i>'8.Jg.e.k.P.vX.Z.._E...23F./M.) p
Jr.....7..Bi..r.h.hV.... ...e.i....AJ.'.0.r.....L.\L.oD.,..0...e......
......e...]<........S\.MJ.8....R..(w.?....o.....e.u.fs.....m....0..
........f?..WsBmRR../.`.~...v.......(..6S......n_#.d6)..MVYEz-.2`:....
.t.e.l[Xyq*M.n..ZTw..~y...N..6nC..x.3D.....OD[.K...UV.......#.d.;F.^ .
...UH9I..Z~P...}H..I:.k.....AR...?7.kf.K..O 8...d..Mq....B.........M..
....|X...4....{....K0...~....`.w.;w...Ha.....E.J..rD?..nXr.9^:3.\T.9.s
..Y..T.\I.lA?^........HagT...~mb....[..m...'B.I.......~m.....`.l.2:..5
</i..m.b...`.......G.q9..yB(.X.......D.r.K"..E..-.r...s...ucK$.Q. .
.B.V.b{....=c ..D...........~g...!...)...!.....K.....NA....:.yLWlg..2S
........'....I..<......,z...1R..=.nz...Rv. .....S.b4..|...8{...1.).
...?B.....`.M.....1.....~.EWV......a.. h....y......*'.I.D.....I..S....
..)...P..5gk.I.8.~.].M,....F.i..)..s...b..M.......y...T.1..F.f..}...;.
........Z.b..b....k.klb..F.......E...H....L`.......a.)R.W...W...H.|$.2
.....=<.........T..i....-..}...}[email protected].$e......~?. ..EU.\e.."..%
..&d.)!.v.I02k...e.........8..e..MD.7/..`."!.=.V.........G>........
..b...4..c.8f.._..B~..Un.5ZRP.H..........-T...4J.'j.}m.t..)..!.XU.Z2..
.NG..;...>....v*[email protected]..[...<..`.....P.$"0..$r..^"<<<< skipped >>>
GET /shared/font/softonic/font-icon.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:46 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 4355
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:24 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 339...........Yi...u.....k......rwg.3..c.sK<L..%-E].R&i....$...2i.....
.@.............. .0.`[email protected] v...U....K.g..z..].^..L3.[S.
qf...g_...}....<'......,{.]d.....>...2c!;.....g.y..>...{.-.a.
1..L.&.c.w..,..k.d.....r*...h...O...t...[.......[.|.y.u.......?.q.{._e
.t..sK...N..c.....<...5,..;..x...............xv....K...............
.M.f..K..}..o..IP......W.'.....L...1....Y.<....1.........1vk.......
.F....C....H..-......B...........Y..........q3.7.h..h..k.......iS4...:
xQf.D{^....w;.^.W,.544l../.!...*.E..eMgvC$...nc..f........Q.{..>g..
...k...H...mTW.-LS...(.[...4....;B.0.s.O.......]...#.._w,{...0, ..P.Kr
*`.....pnI..6A5....eQEZ....f.....8*....{9.w.."S...B...|....k.S.|.;....
.........z)9...S..tF.....u.. ..h. I ..A^U)...wU.*...6.._w..E...q^..GW.
......F.}..j.9..r..W.....#....C.:....j.r.~q^..."^..;.C.....h.j"..''RA.
T.,...~m*....=m.W.j..mw.q.'...L....[...\xQ...A ......l&J.B.T...Q. ..i.
.|H......z#.}i{..B.,Gz..:R...G3.L&....w....8..H< \....Ri.T.3.;.....
..I..0.z-A.$....L>.\..LK:.0..L>...~.?...a.82..x..*...L... .9....
%/.3{.u.[t.t....0%.im.....,.OL....r......r......h.........g..-.....$..
$d`#V #.. ..2.k..L..K.T..T[]......J..C..H^v..Yi&..K.<.g. 5.U.9/1.jW
{h.u.....W.N\...%[.Q...)..J.G...v..<.Q-$b."[email protected].^j..!n..,H..
Z..6.U..m..)R.-[m.S.:@[email protected] ....T..X..H....vm*.moh.M.i......kw.....
.|.....V2...xs.t.^.G.~eD.z]Z.)TU.....9q.A<....R%.#Nv..{.K.....D;...
n5[.^.v..b..x...I.q......jc.A.H.C.....h..5.x.@y..%r.....XR.R]J`Ex.....
..a&.Id..fbG.b...<..I.Z....I.U.S.....h..ONno...o.&.o.l..?..3...<<< skipped >>>
GET /shared/font/es/OpenSans-CondLight-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:43 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 13715
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:26 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 300............UT.L..g`...VVV...,.kpw.......-...........`....{.{.....<
UoW.u.....(.. .7@..<&2........8....:....eB.............*.|..?..x...
.... ..X.........E6....[m.c..G.=..............\..x.GH.........GK...p.7
y.........:....2..>?2.......[.PC..........L<UC.....8.9....Q.#~..
....>g..A..9u-...`.. .a ..l.inq ~.m..u.36.........1..%.7F..._.GE...
....IB..b.Y...[j..\.8...RN....*.RP..87..p...W.)`.......A..p.......P...
/V.ce.]W..*.......J $.t......Q...%.`a3..R..]e....r_t...^.z...0NW....3.
... *.]........3.........C.sm.....5pa$.'>.....c..1.6W.i).Zc...nZV..
`.uV4..O:......L.. .}.....^...I..t.....z1$y.@`.cz..iP}.........Dl.....
.^../.w...?.J..60.......e./CN.....u..b...@.#..*#....L..b.....6 3....q.
v@!"M....o.A .......s..Fd.5./...1.].Q.K]?....#) *..epx.........k,.$..7
ZO.p....L].....".....pQNE..q....j.,&.....:.. A.6.c.M.....^O.......[Yr.
..!.L.bB.fV6]...;;.........G-............V..t.xoQcA....]. ....<"$q.
......'.f../`......}....%...yq.....2.W..E=8..].%<X.|..'.:?.!...G...
.T.C...`..............,.y..qL...pnS..!.JY..G.e_.;.K0.....r..~<.C...
w....u.b%.^...Xa^.J.4.d...`...F..|....2d.~C...[...e~Tt..!........C,jy"
.FG....6...i.....I.....D{...l.#EI;.....Y8...b'[email protected]. .*.......p..c..
GH....\P.1..9Y...|x.m..F<`Py..ih.M...J...c|P[.E%6.j.....#.^..=.".,.
....%W.`.W/..|2..TG,K7.{U..| i...I..-.n...3mg....\.I(.c..d...).....G.=
......;..T.1Z..dW...Di.....L."...'$=.p$.p...QQ.Pn.w..%#/K..4.1Y..x..}Z
...*Q.....lTx.R".CD..%."H3.........P.G...T'..Dp.....E......Uc..-}&.3m.
f..K.k.,i-..06..$..GI..}h-y.....D...` Y..|....L.#.g..b.U.'....G...<<< skipped >>>
GET /shared/font/es/OpenSans-CondBold-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:43 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 14130
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:28 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 293............UP.N.%<30...0..Kpww.4..VVV...KH.. ..ww.....I.........]}
..sO...............o!..C.4.$02........i...@.=3(@....G.....p........@..
.....g..X....cr..........v.9........I....................x..;B..~.....
..y6$..).... .....>K..05.p4.R.......x........."G|Jz.{.A..N.~`.A1T..
9.<F.C......Z...H....0>}./i>'8.Jg.e.k.P.vX.Z.._E...23F./M.) p
Jr.....7..Bi..r.h.hV.... ...e.i....AJ.'.0.r.....L.\L.oD.,..0...e......
......e...]<........S\.MJ.8....R..(w.?....o.....e.u.fs.....m....0..
........f?..WsBmRR../.`.~...v.......(..6S......n_#.d6)..MVYEz-.2`:....
.t.e.l[Xyq*M.n..ZTw..~y...N..6nC..x.3D.....OD[.K...UV.......#.d.;F.^ .
...UH9I..Z~P...}H..I:.k.....AR...?7.kf.K..O 8...d..Mq....B.........M..
....|X...4....{....K0...~....`.w.;w...Ha.....E.J..rD?..nXr.9^:3.\T.9.s
..Y..T.\I.lA?^........HagT...~mb....[..m...'B.I.......~m.....`.l.2:..5
</i..m.b...`.......G.q9..yB(.X.......D.r.K"..E..-.r...s...ucK$.Q. .
.B.V.b{....=c ..D...........~g...!...)...!.....K.....NA....:.yLWlg..2S
........'....I..<......,z...1R..=.nz...Rv. .....S.b4..|...8{...1.).
...?B.....`.M.....1.....~.EWV......a.. h....y......*'.I.D.....I..S....
..)...P..5gk.I.8.~.].M,....F.i..)..s...b..M.......y...T.1..F.f..}...;.
........Z.b..b....k.klb..F.......E...H....L`.......a.)R.W...W...H.|$.2
.....=<.........T..i....-..}...}[email protected].$e......~?. ..EU.\e.."..%
..&d.)!.v.I02k...e.........8..e..MD.7/..`."!.=.V.........G>........
..b...4..c.8f.._..B~..Un.5ZRP.H..........-T...4J.'j.}m.t..)..!.XU.Z2..
.NG..;...>....v*[email protected]..[...<..`.....P.$"0..$r..^"<<<< skipped >>>
GET /shared/font/softonic/font-icon.eot? HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: v1es.sftcdn.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 09 Apr 2015 09:12:46 GMT
Content-Encoding: gzip
Access-Control-Allow-Origin: *
Content-Type: application/vnd.ms-fontobject
Vary: Accept-Encoding
Content-Length: 4355
Accept-Ranges: bytes
Date: Sun, 28 Jun 2015 18:49:28 GMT
Connection: keep-alive
Age: 0
X-Served-By: generated
X-Cache: HIT
X-Cache-Hits: 344...........Yi...u.....k......rwg.3..c.sK<L..%-E].R&i....$...2i.....
.@.............. .0.`[email protected] v...U....K.g..z..].^..L3.[S.
qf...g_...}....<'......,{.]d.....>...2c!;.....g.y..>...{.-.a.
1..L.&.c.w..,..k.d.....r*...h...O...t...[.......[.|.y.u.......?.q.{._e
.t..sK...N..c.....<...5,..;..x...............xv....K...............
.M.f..K..}..o..IP......W.'.....L...1....Y.<....1.........1vk.......
.F....C....H..-......B...........Y..........q3.7.h..h..k.......iS4...:
xQf.D{^....w;.^.W,.544l../.!...*.E..eMgvC$...nc..f........Q.{..>g..
...k...H...mTW.-LS...(.[...4....;B.0.s.O.......]...#.._w,{...0, ..P.Kr
*`.....pnI..6A5....eQEZ....f.....8*....{9.w.."S...B...|....k.S.|.;....
.........z)9...S..tF.....u.. ..h. I ..A^U)...wU.*...6.._w..E...q^..GW.
......F.}..j.9..r..W.....#....C.:....j.r.~q^..."^..;.C.....h.j"..''RA.
T.,...~m*....=m.W.j..mw.q.'...L....[...\xQ...A ......l&J.B.T...Q. ..i.
.|H......z#.}i{..B.,Gz..:R...G3.L&....w....8..H< \....Ri.T.3.;.....
..I..0.z-A.$....L>.\..LK:.0..L>...~.?...a.82..x..*...L... .9....
%/.3{.u.[t.t....0%.im.....,.OL....r......r......h.........g..-.....$..
$d`#V #.. ..2.k..L..K.T..T[]......J..C..H^v..Yi&..K.<.g. 5.U.9/1.jW
{h.u.....W.N\...%[.Q...)..J.G...v..<.Q-$b."[email protected].^j..!n..,H..
Z..6.U..m..)R.-[m.S.:@[email protected] ....T..X..H....vm*.moh.M.i......kw.....
.|.....V2...xs.t.^.G.~eD.z]Z.)TU.....9q.A<....R%.#Nv..{.K.....D;...
n5[.^.v..b..x...I.q......jc.A.H.C.....h..5.x.@y..%r.....XR.R]J`Ex.....
..a&.Id..fbG.b...<..I.Z....I.U.S.....h..ONno...o.&.o.l..?..3...<<< skipped >>>
GET /measure.min.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: asset.pagefair.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:25 GMT
Content-Type: application/x-javascript
Content-Length: 4442
Connection: keep-alive
x-amz-id-2: HiMl4eSPUKfbIMwac8jmAXzPBinOQSJg8Fcn1mcIVKdfTdV0iU981UIMdCzIFDYN7LsVQRxj7BM=
x-amz-request-id: CB75C73A35D75C28
Content-Encoding: gzip
Cache-Control: max-age=7200
Last-Modified: Wed, 17 Jun 2015 10:11:13 GMT
ETag: "99169f88f6b9a69e0506ac632c4e8729"
Server: NetDNA-cache/2.2
X-Cache: HIT
Accept-Ranges: bytes.....G.U..measure.min.js..Zkw.6..._Acw...))I.7....I..I.&N...:: .^..I..
W.....".b..l....`.....Uw.8e.&...RA.m..d.M=m..........O.,W.E.RbY.}&RW..
.".E.W?........r.'....C...f,.......\%.,I.Rq.. q...P....'O.f.~....;)...
t....w..W...W.?.%...n....3V...[......H.:...U..D....15.=e*.sCh..)....x6
.<~@g....,.........'z$...M...25.xS...FSW#c.n....Dg.ji.[.u..= ..]m..
.>!nEX.Jt}.(.. .M.w.9......9..D2...gyZ.N... .Q.......$....1.D..~7."
...‰mOo...'.{.F./.0.......L....R.P...w.6..2.....\..3..W........Q}h#E
....E..P...!...N........z...w......O..."..=..~.;.......a....Z...{`...n
M.x.....L.D.n.....B.m%...f.....b..[<u..HJ8m..B/.((....M...-.,..P...
?.....aW....'..$.8.........aL...X.E.....hT....$..&..\.k.......t.F.h...
~, .s....T `L...5Dn@.."..#..l6.x..D..Ie..=..*y.....`...x}zB.f.....x..B
\&%.. o..>.j1..2_.x...F..i..c`.R.....%@..".2....)M..t.|.........?..
..S.X.[..Z..*...j.c.X....m..f.~\.3QT....5j.B...y..U...T.<..yz.n....
....XM.*....!wi.g.V.w.d{P..z....U..p.9^%..c....e...`Fk.....%..p3^....N
-...3..F.......^..(.$..=.Q{..j..!.4w..\E.|..J.g........#....r...l...x.
......@a....:.... ..H..J.^..l... }}f1...............8......./../...4..
.h8.vG#....v#v..u.e"..~.q..LH..A,@(....................2........?Y..*9
...=.a...f.!.....6..fgg....\..T....E..f..H...hQH.."No..4O.f2u......!6`
#.w....3.....JF....<[email protected];.....
..A.....z.g.......>[email protected].:...(...\'.B`!|..I...
3......?@..&......w........G~.._.4.2.....I.9s'.?(.b..p.e..;.}......Y.2
.N..a0.8..............([email protected]$LD.......E..c_.^ .9....n..3...<<< skipped >>>
GET /adimages/textlink-ads.jpg HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: asset.pagefair.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:25 GMT
Content-Type: image/jpeg
Content-Length: 229
Connection: keep-alive
x-amz-id-2: ELVGgR0NwcSA7daQhO2cHPvLx5/mauNhRKR/raov55iP5PMfFmFjxGYPqU8e6V9hHbAcYakGoAM=
x-amz-request-id: 4EB1F47782F5ACC3
Content-Encoding: gzip
Cache-Control: max-age=2592000
Last-Modified: Wed, 17 Jun 2015 10:11:13 GMT
ETag: "8ebe86738df782e51648901f67f22021"
Server: NetDNA-cache/2.2
X-Cache: HIT
Accept-Ranges: bytes.....G.U..textlink-ads.jpg...An.0.Dg..L..o..;.m/.E%..T... ....71...V@.
..5z...S..|l.[.....7...*.U.5...2.t:......5.B.6...R.K....W.e\/b....|S..
1...&.[..`[email protected].........%Z..m.%.(.oi.P.p..d.g....#&.z......../.
#.d...%f.|.y...........
GET /adimages/textlink-ads.jpg HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: asset.pagefair.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:25 GMT
Content-Type: image/jpeg
Content-Length: 229
Connection: keep-alive
x-amz-id-2: ELVGgR0NwcSA7daQhO2cHPvLx5/mauNhRKR/raov55iP5PMfFmFjxGYPqU8e6V9hHbAcYakGoAM=
x-amz-request-id: 4EB1F47782F5ACC3
Content-Encoding: gzip
Cache-Control: max-age=2592000
Last-Modified: Wed, 17 Jun 2015 10:11:13 GMT
ETag: "8ebe86738df782e51648901f67f22021"
Server: NetDNA-cache/2.2
X-Cache: HIT
Accept-Ranges: bytes.....G.U..textlink-ads.jpg...An.0.Dg..L..o..;.m/.E%..T... ....71...V@.
..5z...S..|l.[.....7...*.U.5...2.t:......5.B.6...R.K....W.e\/b....|S..
1...&.[..`[email protected].........%Z..m.%.(.oi.P.p..d.g....#&.z......../.
#.d...%f.|.y.........
GET /shared/abp_detection/px.js?ch=2 HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: mvp-baseball.sd.softonic.com
Connection: Keep-Alive
Cookie: PHPSESSID=36129f33a16f1c00fc01bccaff2431f5; blang=en_US; country=UA; ucountry=EU; entry=Direct
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:21 GMT
Server: Apache
Last-Modified: Tue, 12 May 2015 12:57:02 GMT
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Expires: Tue, 28 Jul 2015 18:49:21 GMT
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 236
Connection: close
Content-Type: text/javascript..........eP.j.!....aQ.1.^.,[email protected].
.&(ho\...........,.cx.}..]M.Q.!....SQ;.p..i.If.\@r_..3.[...5.....wGq&l
t;..=....!B..&b.T#...../l.x."...y......-6...N.....V.......L.\..u...I.;
......RF...gRSl....~..5..Z.....
GET /tag/js/gpt.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: VVV.googletagservices.com
Connection: Keep-Alive
HTTP/1.1 200 OK
P3P: policyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA IVD OTP OUR OTR IND OTC"
Content-Type: text/javascript; charset=UTF-8
ETag: 5996376913532208559
Date: Sun, 28 Jun 2015 18:49:22 GMT
Expires: Sun, 28 Jun 2015 18:49:22 GMT
Cache-Control: private, max-age=3600
Timing-Allow-Origin: *
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="f.txt"
Content-Encoding: gzip
Server: cafe
Content-Length: 16512
X-XSS-Protection: 1; mode=block
Alternate-Protocol: 80:quic,p=1...........}kw.:.......o..c...`'.......;.O.l ..MB.....~fF.K...~....4.5
..F..Ir..q..&c..u.f5...l8J}....DZ.dWS>..Xg.w.Ix.......W.....8..8B..
..]y3..gc....)..!$...v..(._...$.`..l......F.......D.j.F.xry.5.Ti.n..U.
......<.3xQMj$|<.....|...h.cg=OM..(..R..S>....}@.g,L.v.:.u.2.
...........bg./U.Q..R#.,x....:..Lg.>a]5...U...bqP.`/.3............
...:..!.SN.P.e......N.....?...'.....8..,........(j.v.z..ifw/...N.L....
.G..Sw[.....e.....8w....4=......r...T%..5.t.\....d..l..1.R....s.....3/
..&....l2siFn...eO.....=c>.8..dVY.-5...S.~ ..)B...p..d."?..0..[.X.K
-..=......Oj.........Z_.....5...x..j.....E..xD....E.......5L.*...Q.j..
j....a..a.=V.....e-.......8.l.e.Y.....!.?.~..(....;.H...<..lu.%....
u/..oo..:.7?.|#.H/:V..'02.|...Q.4e..?I&,.9Gm..f.....n....|.u.v..O.r..c
....%$"...6....].>..kx..._[..s..{........M?).!&Ua%d.s.EC.,.t..z..v(
Z{....4..-...>V..F.....K.S.N..uZ..g,8e...mB:...T....^[..?......9>
;...K..........._a7...[......z..f{........?._....E..y.......U.3...z{..
5../...fo..to.R^.>.x.)...`EU.'..*...~{....=E..Wd..}....$..9.a4.Zw.l
ly.K.....j.M....Q..,....V..1.......;......*..x'...~2.y...VZ.XsW.X.? qN
.(b..k. .~C.....J.E.|`....x.|...}X.....b.......x.....Q..1.u..\...).p.g
.z.k.H..hHPX...B.8......q.T...{...b....g0...../..a.B.M...*.M..o...3..i
.v../.....;|./.Q.s..B....B..<."(/u..`2.$<c..k.x.~-.a..q..u....}.
..u`.n.c...,.wE.f../.r.`...E`.3..Y..%.'.......s....s.$.|.)....d{..q<
;.}.M.....L.y...1h..9H....g.1.$.........2.Xu.e.FY...g. ..FU. ..s...ow.
.9.Mk..T.PC...j.D.P=g.......e............Bp!_......../...|.._...6.<<< skipped >>>
GET /tag/js/check_359604.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: VVV.googletagservices.com
Connection: Keep-Alive
HTTP/1.1 200 OK
P3P: policyref="hXXp://VVV.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA IVD OTP OUR OTR IND OTC"
Content-Type: text/javascript; charset=UTF-8
ETag: 10802316996441022840
Date: Sun, 28 Jun 2015 18:43:51 GMT
Expires: Sun, 28 Jun 2015 18:58:51 GMT
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="f.txt"
Content-Encoding: gzip
Server: cafe
Content-Length: 1878
X-XSS-Protection: 1; mode=block
Age: 333
Cache-Control: public, max-age=900
Alternate-Protocol: 80:quic,p=1..........M.9.e..D}.B*.*$.......g.$8.....rd....@..'.i...k......;......
..\......O..../.S...c{.E..t....]/9: 8..sg.g..7).n.....).R..[.0W#.]....
.e..`Y........&....c.=...A...b",........%B.Z.........O......sZ0J..wT..
:Z}.q..Z...3.jJ....dA.~..T...d|...-g.....Cm.Z..b.RV....m..#.S.....{l.t
.4..Tj..t....M.r.].V..XR...u]... /[..3......lp?5.......i...?..4..g....
..............sP_......y..a3sP.E.)...........9t!........fi..5.....s%..
]&...........ul.b.......xO.7..d1........1.#P.Jw.r.j......l..7..H.g.V..
..t.K...........U..(..4jm..tx....Y8,..7.PA.9W.Q.m....@w.`.hZ....l|?d..
|..H.no%.7.%k.V.. ..%..'......<...Sw.8.tz..u..Hh..../.;.7...^e.....
./[email protected].%S.a.N...H..F(....kC!^...S&..k.Av..i...%']......
..37LZ...)._.vrr(.y4..........6.m...*....*.._...jhCJ...9..8..3.>Y._
...q...i2..._..UY..v....mj:.,...k....5eDa.s.....i.rz...........d...D.n
..j....E.UU..t..x..y.`...nl......K...f6...8..d......uSj...9$).I.]`.e..
.d.%Th..z.G.....u.c.8..<a....}...Uz..M:a Q..zd./.|L......f[........
.........PPvf];..,........K../Lq.6.1.($~s.....h...../(`...t)E .....q..
A.r..W.hJ~...hf..'.|Y...b.).5....^.yfM.g..h<.....2O.....Z"....N.E..
X.r..ty...1:[email protected]..........\..md....5...V.G.3.....s<m..
....t...d."_1F.9..%Xb}.Qml*R...;...(.ZnT...U..f.]~M<...v..........2
..Sr.....F...3.pNu..?a9r.6...{`..Y.s..}..y._....w$..: .CojG.8Ae.x..v.
....27....z....zEOy..| .......`.e}...< Y.....T...Qo.BG.%..%<g..]
'N.......B...Y..q......e......H..@.....3..Y.......F...3..e.........hD5
.........;(Yeb.t[%."!.hj..k8.....(. ./..S.e.R...([email protected].@.<<< skipped >>>
GET /adimages/adsense.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: asset.pagefair.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:25 GMT
Content-Type: application/x-javascript
Content-Length: 31
Connection: keep-alive
x-amz-id-2: wpkyuA7 ORlkvKU1j/o00BEf6CZQYY8 bTN3YZDBsMkvXlyYYZBSF5kXIn/emdhnugJnDiTLB9I=
x-amz-request-id: 03EE602FEA903CFE
Content-Encoding: gzip
Cache-Control: max-age=2592000
Last-Modified: Wed, 17 Jun 2015 10:11:13 GMT
ETag: "3c622a837e8ba87543b9ae9554cc24de"
Server: NetDNA-cache/2.2
X-Cache: HIT
Accept-Ranges: bytes.....G.U..adsense.js...............
GET /adimages/adsense.js HTTP/1.1
Accept: */*
Referer: hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: asset.pagefair.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Jun 2015 18:49:25 GMT
Content-Type: application/x-javascript
Content-Length: 31
Connection: keep-alive
x-amz-id-2: wpkyuA7 ORlkvKU1j/o00BEf6CZQYY8 bTN3YZDBsMkvXlyYYZBSF5kXIn/emdhnugJnDiTLB9I=
x-amz-request-id: 03EE602FEA903CFE
Content-Encoding: gzip
Cache-Control: max-age=2592000
Last-Modified: Wed, 17 Jun 2015 10:11:13 GMT
ETag: "3c622a837e8ba87543b9ae9554cc24de"
Server: NetDNA-cache/2.2
X-Cache: HIT
Accept-Ranges: bytes.....G.U..adsense.js.............
GET /35586/universaldownloader-prefetch HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: mvp-baseball.sd.softonic.com
Connection: Keep-Alive
Cookie: PHPSESSID=36129f33a16f1c00fc01bccaff2431f5; blang=en_US; country=UA; ucountry=EU; entry=Direct; gtm_vl=1; usess=true; SAUID=31198227327810681435517391624; visit_website=2; _ga=GA1.4.1160059594.1435517394; _dc_gtm_UA-366832-1=1; ads_bm_last_load_status=NOT_BLOCKING; bm_last_load_status=NOT_BLOCKING; bm_monthly_unique=true; bm_daily_unique=true
HTTP/1.1 404 Not Found
Date: Sun, 28 Jun 2015 18:49:28 GMT
Server: Apache
Set-Cookie: softonic_es-admin=deleted; expires=Sat, 28-Jun-2014 18:49:27 GMT; path=/; domain=softonic.com
Vary: User-Agent,Accept-Encoding
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-control: max-age=0, must-revalidate
Pragma: no-cache
Content-Encoding: gzip
Content-Length: 10407
Connection: close
Content-Type: text/html; charset=utf-8...........}.n.I........4iu..W.[.(jVs$.=..`....U..E.m*...\.l../>...
.}0.{..|.6`..0p.'..0..?8"3.~."Gc...;....[FFF.........7g.d.......M#...u
.......7.'.E..O.x....sb...B.7X1.....{.z....%.._.S(2......y...@Eh......
........rw....w....Z.....K.........N.[....~.....]z]....IT............u
...a...[.m....5.O`.....#D#gw.[..%.K...N.S...$..#.... .s.LZa...[...8.f.
.....^`.N. ....KxK.%%(.5(.,}...C.F..oC.[.>%.d....X....pm.!....1....
....(T..t......z..{.>..qmZ...as|.$.P_......v..E....k6'...q%6z.....4
.a......N,b.K..Iw....K..w.n.S*..U.x.n.].H.F.;....|\....Hu6w.....d~..00
..:.....W.;J;.a..IC....C.C.t..SkM=...R..o. .x$........!.............X.
:.b{l.4..j.`tnZ.A../........xt..Q.....~.:...md...L..&.\.^.}a..%.z.....
>...a..........r.n...XP...e...M.....a ..Ws._.P..k....S.X~....v. [M(
.bz....'.\...{$.......NZ..P...-4...a..._;c.....i.*[email protected]..
..2.Er.,w...].s..dB.*.A....=.Co..fQ-1.....~o0.$..b3t.%fRY)..X.......9.
.W^u1...i.*.....{......J.....6......vJ....oB....9.].g.>....g.0.r.@.
..5." .-.....ES..Z.e.....n4.........r.X.A.{...P-I....d.di......P....~W
T...(.13.(.G#<4..cm...kT..h... V@^....../.....=:...x9z..9....!O..pu
..q5..9.....Bo.U.....>&.c..W.S.I,e.=...,[email protected]....{
..uo<....5...%oM.z..H. |c...j..FK.e.J..CH.....a.....l.<..`..7..v
F..<...)...B.mE"..p..F\..t.3.......i......?..1..t.....`<....g.=!
.f...U....fk, .[m.R..}[email protected]\[email protected]..
B........(.-.o. ;...P.7O...Z.U..M...J$Q.H..Z. u.5XQ.f..,...U-....<.
..h...8<0b....(..3..`..a... .9..D.........HG.D.0......biui.Y...<<< skipped >>>
GET /35586/universaldownloader-prefetch HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C) SoftonicDownloader/1.41.8
Host: mvp-baseball.sd.softonic.com
Connection: Keep-Alive
Cookie: PHPSESSID=36129f33a16f1c00fc01bccaff2431f5; blang=en_US; country=UA; ucountry=EU; entry=Direct; gtm_vl=1; usess=true; SAUID=31198227327810681435517391624; visit_website=1
HTTP/1.1 404 Not Found
Date: Sun, 28 Jun 2015 18:49:24 GMT
Server: Apache
Set-Cookie: softonic_es-admin=deleted; expires=Sat, 28-Jun-2014 18:49:23 GMT; path=/; domain=softonic.com
Vary: User-Agent,Accept-Encoding
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-control: max-age=0, must-revalidate
Pragma: no-cache
Content-Encoding: gzip
Content-Length: 10407
Connection: close
Content-Type: text/html; charset=utf-8...........}.n.I........4iu..W.[.(jVs$.=..`....U..E.m*...\.l../>...
.}0.{..|.6`..0p.'..0..?8"3.~."Gc...;....[FFF.........7g.d.......M#...u
.......7.'.E..O.x....sb...B.7X1.....{.z....%.._.S(2......y...@Eh......
........rw....w....Z.....K.........N.[....~.....]z]....IT............u
...a...[.m....5.O`.....#D#gw.[..%.K...N.S...$..#.... .s.LZa...[...8.f.
.....^`.N. ....KxK.%%(.5(.,}...C.F..oC.[.>%.d....X....pm.!....1....
....(T..t......z..{.>..qmZ...as|.$.P_......v..E....k6'...q%6z.....4
.a......N,b.K..Iw....K..w.n.S*..U.x.n.].H.F.;....|\....Hu6w.....d~..00
..:.....W.;J;.a..IC....C.C.t..SkM=...R..o. .x$........!.............X.
:.b{l.4..j.`tnZ.A../........xt..Q.....~.:...md...L..&.\.^.}a..%.z.....
>...a..........r.n...XP...e...M.....a ..Ws._.P..k....S.X~....v. [M(
.bz....'.\...{$.......NZ..P...-4...a..._;c.....i.*[email protected]..
..2.Er.,w...].s..dB.*.A....=.Co..fQ-1.....~o0.$..b3t.%fRY)..X.......9.
.W^u1...i.*.....{......J.....6......vJ....oB....9.].g.>....g.0.r.@.
..5." .-.....ES..Z.e.....n4.........r.X.A.{...P-I....d.di......P....~W
T...(.13.(.G#<4..cm...kT..h... V@^....../.....=:...x9z..9....!O..pu
..q5..9.....Bo.U.....>&.c..W.S.I,e.=...,[email protected]....{
..uo<....5...%oM.z..H. |c...j..FK.e.J..CH.....a.....l.<..`..7..v
F..<...)...B.mE"..p..F\..t.3.......i......?..1..t.....`<....g.=!
.f...U....fk, .[m.R..}[email protected]\[email protected]..
B........(.-.o. ;...P.7O...Z.U..M...J$Q.H..Z. u.5XQ.f..,...U-....<.
..h...8<0b....(..3..`..a... .9..D.........HG.D.0......biui.Y...<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
`.rsrc
8Y%u*
PSSSSSSh
PSSSSh
u.hl`L
F><.tN<[tJ<\tF<*tB<|t><^t:<$t6
II I!"II#$IIII%&'III(I)*I III,-.II/0123IIII4I5IIIIIII6IIIIII789:;<IIIIIIII=>II?@ABCDEFIIIIGIIIIH
88888888888888888
%u$Vj%
t.Gj:W
xSSSh
FTPjKS
FtPj;S
C.PjRV
[%s %s %s]
Send failure: %s
Failed writing body (%d != %d)
%s:%d
WARNING: failed to save cookies in %s
About to connect() to %s%s port %d (#%d)
Connected to %s (%s) port %d (#%d)
<url> malformed
:]://%[^
[^:]:%[^
Protocol %s not supported or disabled in libcurl
http_proxy
%5[^:@]:%5[^@]
%5[^:]:%5[^
:%5[^@]
Port number too large: %lu
%s://%s%s%s:%d%s%s
ftps
[%*39[0123456789abcdefABCDEF:.%]%c
Couldn't find host %s in the _netrc file; using defaults
[email protected]
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
Connection #%d seems to be dead!
Connection (#%d) was killed to make room (holds %d)
Re-using existing connection! (#%ld) with host %s
%s://%s
Connection #%ld to host %s left intact
operation aborted by callback
HTTP/
ioctl callback returned error %d
the ioctl callback returned %d
seek callback returned error %d
The requested URL returned error: %d
HTTP/1.0 connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.0 proxy connection set to keep alive!
HTTP 1.0, assume close after body
HTTP =
HTTP/%d.%d =
No URL set!
[^?&/:]://%c
Violate RFC 2616/10.3.2 and switch from POST to GET
Disables POST, goes with %s
Issue another request to this URL: '%s'
Maximum (%d) redirects followed
Received problem %d in the chunky parser
HTTP server doesn't seem to support byte ranges. Cannot resume.
Rewinding stream by : %d bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %d)
Leftovers after chunking. Rewinding %d bytes
Operation timed out after %ld milliseconds with %lld bytes received
Operation timed out after %ld milliseconds with %lld out of %lld bytes received
unspecified error %d
%s cookie %s="%s" for domain %s, path %s, expire %d
#HttpOnly_
httponly
I99[^;
skipped cookie with bad tailmatch domain: %s
skipped cookie with illegal dotcount domain: %s
23[^;=]=I99[^;
%s%s%s
# Fatal libcurl error
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/rfc/cookie_spec.html
# This file was generated by libcurl! Edit at your own risk.
bind failure: %s
Local port: %d
Bind to local port %d failed, trying next
couldn't find my own IP address (%s)
Bind local address to %s
Couldn't bind to '%s'
TCP_NODELAY set
Could not set TCP_NODELAY: %s
Failed to connect to %s: %s
Trying %s...
Internal error removing splay node = %d
Internal error clearing splay node = %d
Error in the SSH layer
Caller must register CURLOPT_CONV_ callback options
TFTP: No such user
TFTP: Unknown transfer ID
TFTP: Illegal operation
TFTP: Access Violation
TFTP: File Not Found
Login denied
Issuer check against peer certificate failed
Invalid LDAP URL
Unrecognized HTTP Content-Encoding
Problem with the SSL CA cert (path? access rights?)
Peer certificate cannot be authenticated with known CA certificates
Problem with the local SSL certificate
SSL peer certificate or SSH md5 fingerprint was not OK
A libcurl function was given a bad argument
Operation was aborted by an application callback
FTP: command REST failed
FTP: command PORT failed
HTTP response code said error
FTP: couldn't retrieve (RETR failed) the specified file
FTP: couldn't set file type
FTP: can't figure out the host in the PASV response
FTP: unknown 227 response format
FTP: unknown PASV reply
FTP: unknown PASS reply
FTP: weird server reply
URL using bad/illegal format or missing URL
Unsupported protocol
Winsock version not supported
Protocol family not supported
Address family not supported
Operation not supported
Socket is unsupported
Protocol is unsupported
Protocol option is unsupported
Unknown error %d (%#x)
Resolving host timed out: %s
Could not resolve host: %s; %s
Could not resolve proxy: %s; %s
Could not resolve host: %s
gethostbyname(2) failed for %s:%d; %s
init_resolve_thread() failed for %s; %s
TFTP
set timeouts for state %d; Total %d, retry %d maxtry %d
tftp_rx: giving up waiting for block %d
Received unexpected DATA packet block %d
Timeout waiting for block %d ACK. Retries = %d
tftp_rx: internal error
tftp_tx: giving up waiting for block %d ack
Received ACK for block %d, expecting %d
tftp_tx: internal error
bind() failed; %s
tftp_send_first: internal error
%s%c%s%c
TFTP finished
Can't get the size of %s
Can't open %s for writing
Last-Modified: %s, d %s M d:d:d GMT
Couldn't open file %s
There are more than %d entries
LDAP remote: %s
LDAP local: ldap_simple_bind_s %s
LDAP local: Cannot connect to %s:%d
LDAP local: trying to establish %s connection
LDAP local: %s
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
CLIENT libcurl 7.19.0
MATCH %s %s %s
DEFINE %s %s
insufficient winsock version to support telnet
WSAStartup failed (%d)
%s %d %d
%s %s %d
%s %s %s
%s IAC %d
%s IAC %s
Sending data failed (%d)
%d (unknown)
%s (unsupported)
%s IAC SB
Syntax error in telnet option: %s
Unknown telnet option %s
7[^= ]%*[ =]%5s
USER,%s
%c%c%c%c%s%c%c
%c%s%c%s
7[^,],7s
%c%c%c%c
FreeLibrary(wsock2) failed (%d)
WSACloseEvent failed (%d)
WSACreateEvent failed (%d)
failed to find WSAEnumNetworkEvents function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSACreateEvent function (%d)
failed to load WS2_32.DLL (%d)
WS2_32.DLL
Excessive FTP response line length received, %zd bytes. Stripping
FTP response reading failed
FTP response aborted due to select/poll error: %d
FTP response timeout
Failed FTP upload:
RETR response: d
Connecting to %s (%s) port %d
Uploading to a URL without a file name!
FTPS not supported!
USER %s
socket(2) failed (%s)
PORT %d,%d,%d,%d,%d,%d
Telling server to connect to %d.%d.%d.%d:%d
Failed to resolve host name %s
getsockname() failed: %s
Connect data stream passively
REST %d
SIZE %s
STOR %s
APPE %s
Bad PASV/EPSV response: d
Can't resolve new host %s:%d
%d.%d.%d.%d
Skips %d.%d.%d.%d for data connection, uses %s instead
%d,%d,%d,%d,%d,%d
%c%c%c%u%c
Failed to do PORT
Got a d response code instead of the assumed 200
RETR %s
ftp server doesn't support SIZE
PBSZ %d
Access denied: d
ACCT %s
PASS %s
ACCT rejected by server: d
QUOT string not accepted: %s
TYPE %c
MDTM %s
ddd d:d:d GMT
dddddd
unsupported MDTM reply format
server did not report OK, got %d
Remembering we are in dir "%s"
CWD %s
Failed to MKD dir: d
MKD %s
QUOT command failed with d
Entry path is '%s'
PROT %c
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
AUTH %s
Got a d ftp-server response when 220 was expected
%sAuthorization: Basic %s
%s:%s
Server auth using %s with user '%s'
Proxy auth using %s with user '%s'
Failed sending HTTP POST request
Content-Type: application/x-www-form-urlencoded
Internal HTTP POST error!
Failed sending HTTP request
If-Unmodified-Since: %s
Last-Modified: %s
If-Modified-Since: %s
%s, d %s M d:d:d GMT
%s%s=%s
%s %s%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
Content-Range: bytes %s/%lld
Content-Range: bytes %s%lld/%lld
Range: bytes=%s
;type=%c
ftps://
PTF://
Host: %s%s%s:%d
Host: %s%s%s
Accept-Encoding: %s
Referer: %s
Received HTTP code %d from proxy after CONNECT
%d bytes of chunk left
HTTP/1.%d %d
Read %d bytes of chunk, continue
CONNECT %s:%d HTTP/1.0
%s%s%s%s
Host: %s
Establish HTTP proxy tunnel to %s:%d
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Failed to resolve "%s" for SOCKS4 connect.
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
SOCKS5 GSSAPI per-message authentication is not supported.
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Failed to resolve "%s" for SOCKS5 connect.
User was rejected by the SOCKS5 server (%d %d).
SOCKS5: server resolving disabled for hostnames of length > 255 [actual len=%d]
--:--:--
= %s = %s = %s %s %s %s %s %s %s
password
login
Operation too slow. Less than %d bytes/sec transfered the last %d seconds
%s, algorithm="%s"
%s, opaque="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop="%s", response="%s"
%s:%s:x:%s:%s:%s
%s:%s:%s
%5[^=]=23[^
%5[^=]="23[^"]"
d:d:d
%c%c==
%c%c%c=
.html
.jpeg
--%s--
Content-Type: %s
; filename="%s"
Content-Disposition: attachment; filename="%s"
Content-Type: multipart/mixed, boundary=%s
%s; boundary=%s
()$^.* ?[]|\-{},:=!:/-_.!~*'()
Kernel32.DLL
xxxxx
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
GetProcessWindowStation
portuguese-brazilian
operator
invalid map<K, T> key
User-Agent: %s
http/
NOINT_MSG
urls_to_restore_on_startup
startup_urls
search_url
keyword
zcÁ
.?AVHTTPClientImplementation@@
.?AVHTTPClientInterface@@
.?AV?$EventTSpecificFunctor@VWindowsAPI@@@@
.?AV?$TSpecificFunctor@VWindowsAPI@@@@
.?AVFirefoxBrowserHandler@Browser@Lib@Softonic@@
.?AVChromeBrowserHandler@Browser@Lib@Softonic@@
.?AVWindowsAPI@@
.?AUDWebBrowserEvents2@@
.?AUIHttpNegotiate@@
.?AVCustomIHttpNegotiate@@
.?AV?$EventTSpecificFunctor@VCurlMultiDownloadJob@@@@
.?AVCurlMultiDownloadJob@@
c:\%original file name%.exe
GetCPInfo
GetProcessHeap
PeekNamedPipe
RegEnumKeyExW
RegQueryInfoKeyW
RegCloseKey
RegDeleteKeyW
RegOpenKeyExW
RegCreateKeyExW
ShellExecuteExW
ShellExecuteW
URLDownloadToFileW
UrlMkGetSessionOption
UrlMkSetSessionOption
GetAsyncKeyState
GetKeyState
EnumChildWindows
EnumDesktopWindows
InternetOpenUrlA
.text
`.rdata
@.data
.rsrc
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.1.1.0" processorArchitecture="X86" name="Softonic.UniversalDownloader" type="win32"></assemblyIdentity><description>Universal Downloader Download Helper.</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
GDI32.dll
gdiplus.dll
IPHLPAPI.DLL
ole32.dll
OLEAUT32.dll
PSAPI.DLL
RPCRT4.dll
SHELL32.dll
SHLWAPI.dll
urlmon.dll
USER32.dll
VERSION.dll
WININET.dll
WLDAP32.dll
WSOCK32.dll
[BEGIN DATA SEGMENT][KEY]WIDTH[VALUE]650[ENDVALUE][KEY]HEIGHT[VALUE]450[ENDVALUE][KEY]URL[VALUE]hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch[ENDVALUE][KEY]NOINT_TITLE[VALUE]No se ha detectado conexi
n a Internet[ENDVALUE][KEY]NOINT_MSG[VALUE]Se necesita conexi
ntalo de nuevo. [ENDVALUE][KEY]PROGRESS_BAR_X[VALUE]20[ENDVALUE][KEY]PROGRESS_BAR_Y[VALUE]99[ENDVALUE][KEY]PROGRESS_BAR_HEIGHT[VALUE]30[ENDVALUE][KEY]START_HIDDEN[VALUE]true[ENDVALUE][KEY]LOADING_DIALOG_TEXT[VALUE]Por favor, espere...[ENDVALUE][KEY]LOADING_DIALOG_TITLE[VALUE]Descarga e instalaci
n de MVP Baseball[ENDVALUE][KEY]MIN_BUTTON_SIZE_X[VALUE]18[ENDVALUE][KEY]MIN_BUTTON_SIZE_Y[VALUE]17[ENDVALUE][KEY]MIN_PROGRAM_SIZE_X[VALUE]210[ENDVALUE][KEY]MIN_PROGRAM_SIZE_Y[VALUE]20[ENDVALUE][KEY]MIN_PROGRESS_TEXT_SIZE_X[VALUE]210[ENDVALUE][KEY]MIN_PROGRESS_TEXT_SIZE_Y[VALUE]20[ENDVALUE][KEY]MIN_PROGRESS_BAR_SIZE_X[VALUE]222[ENDVALUE][KEY]MIN_PROGRESS_BAR_SIZE_Y
SHELL32.DLL
ShellExecuteA
%original file name%.exe
-a}"]q
hXXp://adinathbio.com/images/logo.gif
hXXp://active.cput.ac.za/images/image.gif
hXXp://fcgagra.ge/images/logo.gif
hXXp://ilmesters.edu.pk/images/bottom.gif
hXXp://diaxisperu.com/bottom.gif
hXXp://furkanbedir.com/img/icons/bottom.gif
hXXp://atlascobranca.com.br/atlascobranca01/bottom.gif
hXXp://riviera-palace.com/images/logo.gif
@annuncieprofili.com/logos.gif
iphuketschool.com/logos.gif
//antalyadovme.com/xs.jpg
.info/J
home.gifI888
KERNEL32.dll
h.rata
Bkrnl.exe?
= =$=(=,=
322%2`.50728)
.klkjw:9fqwi
FamXf39.sys
.pBTa8
%s:*:
Bg.laXV
&?%x=
GUrlA'
Web%w|nc
HTTP)
2GUARDCMD.
.ENHCDM
PL/KPCKwWEB
MM.PFW.
.bssf
J:CRT
MSVCRT.dll
WS2_32.dll
SHFileOperationA
H[%s] %s
[%d][%s|%s][%s][%s]
[%d][%s|%s][%s][%s][%s]
Glog.txt
.temp
Ld-d-d
HKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
mscoree.dll
WUSER32.DLL
[%d] [%lld|%lld]
CrashReport tool status:
1.41.8
Got Elevation URL. [%s]
New URL was not valid.
@kernel32.dll
@Received message %s
xxxxxxxxxxx
explorer.exe "
[%d %d]
Hchrome
firefox
0.0.0.0
Web View
Web Host
%d|%d|%d
errorUrl
%s(%s)
%s --> (%s)
.swf?
.jpg?
.gif?
.png?
Value: %d
%s\*.*
%s\%s
Proxy by URL are not supported.
Automatic proxy discovery are not supported.
http=
https=
CPTF://
- URL:
[%d] Starting thread...
[%d] Thread Creation OK!
[%d] Error creating thread! trying again...
[%d] Thread started...
Ahttp/
%d - [%d][%lld/%lld][%lld]
json_writer.cpp
Hjson_value.cpp
Software\Classes\http\shell\open\command\
http\shell\open\command\
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice\
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice\
chrome.exe
iexplore.exe
firefox.exe
opera.exe
opera
safari.ex
browser.startup.homepage
browser.search.order.1
browser.search.order.2
browser.search.order.3
prefs.js
\"(.)*.;
browser.search.selectedEngine
browser.search.defaultenginename
browser.search.useDBForOrder
user_pref("browser.search.useDBForOrder", "false");browser.search.useDBForOrder", "false");
browser.search.useDBForOrder.*
%s*.*
Software\Mozilla\Mozilla Firefox\
\Google\Chrome
SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox\
PathToExe
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\
\search-metadata.json
ljson_reader.cpp
log.txt
Assertion failed: %s, file %s, line %d
"FG1?OO23&]\OU3!%U;
.0;1#49 0(.7<;4',*>0,(.7<;4',*#49 0(.7<;4',*0;1#49 0(
&:3!"4'0)'
EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEFEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEGEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEDEEEEEEEEXEEEEXEEEEXEEEEXEEEEEEEEEEEGEEEEEEEEXEEEEXEEEEXEEEEXEEEEEEEEEEED&
&:3!"4'0)!
U.RU^U
EEEEEEEEXEEEEXEEEEXEEEEXEEEEEEEEEEEF
<0-%9:'0
&:3!"4'0)&
?&*<;?06!<:;&
[&:3!"4'0)!
)Z].EXL(_\)Zu
?&*<;?06!<:;8
H 4XAMGABAB@XF)Z].EXL(_\)Zu
1.41.8.17
%original file name%.exe_176_rwx_00401000_000FA000:
8Y%u*
PSSSSSSh
PSSSSh
u.hl`L
F><.tN<[tJ<\tF<*tB<|t><^t:<$t6
II I!"II#$IIII%&'III(I)*I III,-.II/0123IIII4I5IIIIIII6IIIIII789:;<IIIIIIII=>II?@ABCDEFIIIIGIIIIH
88888888888888888
%u$Vj%
t.Gj:W
xSSSh
FTPjKS
FtPj;S
C.PjRV
[%s %s %s]
Send failure: %s
Failed writing body (%d != %d)
%s:%d
WARNING: failed to save cookies in %s
About to connect() to %s%s port %d (#%d)
Connected to %s (%s) port %d (#%d)
<url> malformed
:]://%[^
[^:]:%[^
Protocol %s not supported or disabled in libcurl
http_proxy
%5[^:@]:%5[^@]
%5[^:]:%5[^
:%5[^@]
Port number too large: %lu
%s://%s%s%s:%d%s%s
ftps
[%*39[0123456789abcdefABCDEF:.%]%c
Couldn't find host %s in the _netrc file; using defaults
[email protected]
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
Connection #%d seems to be dead!
Connection (#%d) was killed to make room (holds %d)
Re-using existing connection! (#%ld) with host %s
%s://%s
Connection #%ld to host %s left intact
operation aborted by callback
HTTP/
ioctl callback returned error %d
the ioctl callback returned %d
seek callback returned error %d
The requested URL returned error: %d
HTTP/1.0 connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.0 proxy connection set to keep alive!
HTTP 1.0, assume close after body
HTTP =
HTTP/%d.%d =
No URL set!
[^?&/:]://%c
Violate RFC 2616/10.3.2 and switch from POST to GET
Disables POST, goes with %s
Issue another request to this URL: '%s'
Maximum (%d) redirects followed
Received problem %d in the chunky parser
HTTP server doesn't seem to support byte ranges. Cannot resume.
Rewinding stream by : %d bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %d)
Leftovers after chunking. Rewinding %d bytes
Operation timed out after %ld milliseconds with %lld bytes received
Operation timed out after %ld milliseconds with %lld out of %lld bytes received
unspecified error %d
%s cookie %s="%s" for domain %s, path %s, expire %d
#HttpOnly_
httponly
I99[^;
skipped cookie with bad tailmatch domain: %s
skipped cookie with illegal dotcount domain: %s
23[^;=]=I99[^;
%s%s%s
# Fatal libcurl error
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/rfc/cookie_spec.html
# This file was generated by libcurl! Edit at your own risk.
bind failure: %s
Local port: %d
Bind to local port %d failed, trying next
couldn't find my own IP address (%s)
Bind local address to %s
Couldn't bind to '%s'
TCP_NODELAY set
Could not set TCP_NODELAY: %s
Failed to connect to %s: %s
Trying %s...
Internal error removing splay node = %d
Internal error clearing splay node = %d
Error in the SSH layer
Caller must register CURLOPT_CONV_ callback options
TFTP: No such user
TFTP: Unknown transfer ID
TFTP: Illegal operation
TFTP: Access Violation
TFTP: File Not Found
Login denied
Issuer check against peer certificate failed
Invalid LDAP URL
Unrecognized HTTP Content-Encoding
Problem with the SSL CA cert (path? access rights?)
Peer certificate cannot be authenticated with known CA certificates
Problem with the local SSL certificate
SSL peer certificate or SSH md5 fingerprint was not OK
A libcurl function was given a bad argument
Operation was aborted by an application callback
FTP: command REST failed
FTP: command PORT failed
HTTP response code said error
FTP: couldn't retrieve (RETR failed) the specified file
FTP: couldn't set file type
FTP: can't figure out the host in the PASV response
FTP: unknown 227 response format
FTP: unknown PASV reply
FTP: unknown PASS reply
FTP: weird server reply
URL using bad/illegal format or missing URL
Unsupported protocol
Winsock version not supported
Protocol family not supported
Address family not supported
Operation not supported
Socket is unsupported
Protocol is unsupported
Protocol option is unsupported
Unknown error %d (%#x)
Resolving host timed out: %s
Could not resolve host: %s; %s
Could not resolve proxy: %s; %s
Could not resolve host: %s
gethostbyname(2) failed for %s:%d; %s
init_resolve_thread() failed for %s; %s
TFTP
set timeouts for state %d; Total %d, retry %d maxtry %d
tftp_rx: giving up waiting for block %d
Received unexpected DATA packet block %d
Timeout waiting for block %d ACK. Retries = %d
tftp_rx: internal error
tftp_tx: giving up waiting for block %d ack
Received ACK for block %d, expecting %d
tftp_tx: internal error
bind() failed; %s
tftp_send_first: internal error
%s%c%s%c
TFTP finished
Can't get the size of %s
Can't open %s for writing
Last-Modified: %s, d %s M d:d:d GMT
Couldn't open file %s
There are more than %d entries
LDAP remote: %s
LDAP local: ldap_simple_bind_s %s
LDAP local: Cannot connect to %s:%d
LDAP local: trying to establish %s connection
LDAP local: %s
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
CLIENT libcurl 7.19.0
MATCH %s %s %s
DEFINE %s %s
insufficient winsock version to support telnet
WSAStartup failed (%d)
%s %d %d
%s %s %d
%s %s %s
%s IAC %d
%s IAC %s
Sending data failed (%d)
%d (unknown)
%s (unsupported)
%s IAC SB
Syntax error in telnet option: %s
Unknown telnet option %s
7[^= ]%*[ =]%5s
USER,%s
%c%c%c%c%s%c%c
%c%s%c%s
7[^,],7s
%c%c%c%c
FreeLibrary(wsock2) failed (%d)
WSACloseEvent failed (%d)
WSACreateEvent failed (%d)
failed to find WSAEnumNetworkEvents function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSACreateEvent function (%d)
failed to load WS2_32.DLL (%d)
WS2_32.DLL
Excessive FTP response line length received, %zd bytes. Stripping
FTP response reading failed
FTP response aborted due to select/poll error: %d
FTP response timeout
Failed FTP upload:
RETR response: d
Connecting to %s (%s) port %d
Uploading to a URL without a file name!
FTPS not supported!
USER %s
socket(2) failed (%s)
PORT %d,%d,%d,%d,%d,%d
Telling server to connect to %d.%d.%d.%d:%d
Failed to resolve host name %s
getsockname() failed: %s
Connect data stream passively
REST %d
SIZE %s
STOR %s
APPE %s
Bad PASV/EPSV response: d
Can't resolve new host %s:%d
%d.%d.%d.%d
Skips %d.%d.%d.%d for data connection, uses %s instead
%d,%d,%d,%d,%d,%d
%c%c%c%u%c
Failed to do PORT
Got a d response code instead of the assumed 200
RETR %s
ftp server doesn't support SIZE
PBSZ %d
Access denied: d
ACCT %s
PASS %s
ACCT rejected by server: d
QUOT string not accepted: %s
TYPE %c
MDTM %s
ddd d:d:d GMT
dddddd
unsupported MDTM reply format
server did not report OK, got %d
Remembering we are in dir "%s"
CWD %s
Failed to MKD dir: d
MKD %s
QUOT command failed with d
Entry path is '%s'
PROT %c
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
AUTH %s
Got a d ftp-server response when 220 was expected
%sAuthorization: Basic %s
%s:%s
Server auth using %s with user '%s'
Proxy auth using %s with user '%s'
Failed sending HTTP POST request
Content-Type: application/x-www-form-urlencoded
Internal HTTP POST error!
Failed sending HTTP request
If-Unmodified-Since: %s
Last-Modified: %s
If-Modified-Since: %s
%s, d %s M d:d:d GMT
%s%s=%s
%s %s%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
Content-Range: bytes %s/%lld
Content-Range: bytes %s%lld/%lld
Range: bytes=%s
;type=%c
ftps://
PTF://
Host: %s%s%s:%d
Host: %s%s%s
Accept-Encoding: %s
Referer: %s
Received HTTP code %d from proxy after CONNECT
%d bytes of chunk left
HTTP/1.%d %d
Read %d bytes of chunk, continue
CONNECT %s:%d HTTP/1.0
%s%s%s%s
Host: %s
Establish HTTP proxy tunnel to %s:%d
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Failed to resolve "%s" for SOCKS4 connect.
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
SOCKS5 GSSAPI per-message authentication is not supported.
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Failed to resolve "%s" for SOCKS5 connect.
User was rejected by the SOCKS5 server (%d %d).
SOCKS5: server resolving disabled for hostnames of length > 255 [actual len=%d]
--:--:--
= %s = %s = %s %s %s %s %s %s %s
password
login
Operation too slow. Less than %d bytes/sec transfered the last %d seconds
%s, algorithm="%s"
%s, opaque="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop="%s", response="%s"
%s:%s:x:%s:%s:%s
%s:%s:%s
%5[^=]=23[^
%5[^=]="23[^"]"
d:d:d
%c%c==
%c%c%c=
.html
.jpeg
--%s--
Content-Type: %s
; filename="%s"
Content-Disposition: attachment; filename="%s"
Content-Type: multipart/mixed, boundary=%s
%s; boundary=%s
()$^.* ?[]|\-{},:=!:/-_.!~*'()
Kernel32.DLL
xxxxx
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
GetProcessWindowStation
portuguese-brazilian
operator
invalid map<K, T> key
User-Agent: %s
http/
NOINT_MSG
urls_to_restore_on_startup
startup_urls
search_url
keyword
zcÁ
.?AVHTTPClientImplementation@@
.?AVHTTPClientInterface@@
.?AV?$EventTSpecificFunctor@VWindowsAPI@@@@
.?AV?$TSpecificFunctor@VWindowsAPI@@@@
.?AVFirefoxBrowserHandler@Browser@Lib@Softonic@@
.?AVChromeBrowserHandler@Browser@Lib@Softonic@@
.?AVWindowsAPI@@
.?AUDWebBrowserEvents2@@
.?AUIHttpNegotiate@@
.?AVCustomIHttpNegotiate@@
.?AV?$EventTSpecificFunctor@VCurlMultiDownloadJob@@@@
.?AVCurlMultiDownloadJob@@
c:\%original file name%.exe
GetCPInfo
GetProcessHeap
PeekNamedPipe
RegEnumKeyExW
RegQueryInfoKeyW
RegCloseKey
RegDeleteKeyW
RegOpenKeyExW
RegCreateKeyExW
ShellExecuteExW
ShellExecuteW
URLDownloadToFileW
UrlMkGetSessionOption
UrlMkSetSessionOption
GetAsyncKeyState
GetKeyState
EnumChildWindows
EnumDesktopWindows
InternetOpenUrlA
.text
`.rdata
@.data
.rsrc
H[%s] %s
[%d][%s|%s][%s][%s]
[%d][%s|%s][%s][%s][%s]
Glog.txt
.temp
Ld-d-d
HKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
mscoree.dll
WUSER32.DLL
[%d] [%lld|%lld]
CrashReport tool status:
1.41.8
Got Elevation URL. [%s]
New URL was not valid.
@kernel32.dll
@Received message %s
xxxxxxxxxxx
explorer.exe "
[%d %d]
Hchrome
firefox
0.0.0.0
Web View
Web Host
%d|%d|%d
errorUrl
%s(%s)
%s --> (%s)
.swf?
.jpg?
.gif?
.png?
Value: %d
%s\*.*
%s\%s
Proxy by URL are not supported.
Automatic proxy discovery are not supported.
http=
https=
CPTF://
- URL:
[%d] Starting thread...
[%d] Thread Creation OK!
[%d] Error creating thread! trying again...
[%d] Thread started...
Ahttp/
%d - [%d][%lld/%lld][%lld]
json_writer.cpp
Hjson_value.cpp
Software\Classes\http\shell\open\command\
http\shell\open\command\
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice\
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice\
chrome.exe
iexplore.exe
firefox.exe
opera.exe
opera
safari.ex
browser.startup.homepage
browser.search.order.1
browser.search.order.2
browser.search.order.3
prefs.js
\"(.)*.;
browser.search.selectedEngine
browser.search.defaultenginename
browser.search.useDBForOrder
user_pref("browser.search.useDBForOrder", "false");browser.search.useDBForOrder", "false");
browser.search.useDBForOrder.*
%s*.*
Software\Mozilla\Mozilla Firefox\
\Google\Chrome
SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox\
PathToExe
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\
\search-metadata.json
ljson_reader.cpp
log.txt
Assertion failed: %s, file %s, line %d
"FG1?OO23&]\OU3!%U;
.0;1#49 0(.7<;4',*>0,(.7<;4',*#49 0(.7<;4',*0;1#49 0(
&:3!"4'0)'
EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEFEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEGEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEDEEEEEEEEXEEEEXEEEEXEEEEXEEEEEEEEEEEGEEEEEEEEXEEEEXEEEEXEEEEXEEEEEEEEEEED&
&:3!"4'0)!
U.RU^U
EEEEEEEEXEEEEXEEEEXEEEEXEEEEEEEEEEEF
<0-%9:'0
&:3!"4'0)&
?&*<;?06!<:;&
[&:3!"4'0)!
)Z].EXL(_\)Zu
?&*<;?06!<:;8
H 4XAMGABAB@XF)Z].EXL(_\)Zu
%original file name%.exe_176_rwx_004FE000_00001000:
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.1.1.0" processorArchitecture="X86" name="Softonic.UniversalDownloader" type="win32"></assemblyIdentity><description>Universal Downloader Download Helper.</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
GDI32.dll
gdiplus.dll
IPHLPAPI.DLL
ole32.dll
OLEAUT32.dll
PSAPI.DLL
RPCRT4.dll
SHELL32.dll
SHLWAPI.dll
urlmon.dll
USER32.dll
VERSION.dll
WININET.dll
WLDAP32.dll
WSOCK32.dll
URLDownloadToFileW
[BEGIN DATA SEGMENT][KEY]WIDTH[VALUE]650[ENDVALUE][KEY]HEIGHT[VALUE]450[ENDVALUE][KEY]URL[VALUE]hXXp://mvp-baseball.sd.softonic.com/35586/universaldownloader-prefetch[ENDVALUE][KEY]NOINT_TITLE[VALUE]No se ha detectado conexi
n a Internet[ENDVALUE][KEY]NOINT_MSG[VALUE]Se necesita conexi
ntalo de nuevo. [ENDVALUE][KEY]PROGRESS_BAR_X[VALUE]20[ENDVALUE][KEY]PROGRESS_BAR_Y[VALUE]99[ENDVALUE][KEY]PROGRESS_BAR_HEIGHT[VALUE]30[ENDVALUE][KEY]START_HIDDEN[VALUE]true[ENDVALUE][KEY]LOADING_DIALOG_TEXT[VALUE]Por favor, espere...[ENDVALUE][KEY]LOADING_DIALOG_TITLE[VALUE]Descarga e instalaci
n de MVP Baseball[ENDVALUE][KEY]MIN_BUTTON_SIZE_X[VALUE]18[ENDVALUE][KEY]MIN_BUTTON_SIZE_Y[VALUE]17[ENDVALUE][KEY]MIN_PROGRAM_SIZE_X[VALUE]210[ENDVALUE][KEY]MIN_PROGRAM_SIZE_Y[VALUE]20[ENDVALUE][KEY]MIN_PROGRESS_TEXT_SIZE_X[VALUE]210[ENDVALUE][KEY]MIN_PROGRESS_TEXT_SIZE_Y[VALUE]20[ENDVALUE][KEY]MIN_PROGRESS_BAR_SIZE_X[VALUE]222[ENDVALUE][KEY]MIN_PROGRESS_BAR_SIZE_Y
1.41.8.17
%original file name%.exe_176_rwx_00500000_00010000:
SHELL32.DLL
ShellExecuteA
KERNEL32.DLL
%original file name%.exe
.rsrc
c:\%original file name%.exe
-a}"]q
hXXp://adinathbio.com/images/logo.gif
hXXp://active.cput.ac.za/images/image.gif
hXXp://fcgagra.ge/images/logo.gif
hXXp://ilmesters.edu.pk/images/bottom.gif
hXXp://diaxisperu.com/bottom.gif
hXXp://furkanbedir.com/img/icons/bottom.gif
hXXp://atlascobranca.com.br/atlascobranca01/bottom.gif
hXXp://riviera-palace.com/images/logo.gif
@annuncieprofili.com/logos.gif
iphuketschool.com/logos.gif
//antalyadovme.com/xs.jpg
.info/J
home.gifI888
.text
KERNEL32.dll
h.rata
Bkrnl.exe?
= =$=(=,=
322%2`.50728)
.klkjw:9fqwi
FamXf39.sys
.pBTa8
%s:*:
Bg.laXV
&?%x=
GUrlA'
Web%w|nc
HTTP)
2GUARDCMD.
.ENHCDM
PL/KPCKwWEB
MM.PFW.
.bssf
J:CRT
ADVAPI32.dll
MSVCRT.dll
SHELL32.dll
USER32.dll
WS2_32.dll
RegCloseKey
SHFileOperationA
%original file name%.exe_176_rwx_00B20000_0108E000:
c:\windows
hXXp://adinathbio.com/images/logo.gif
hXXp://active.cput.ac.za/images/image.gif
hXXp://fcgagra.ge/images/logo.gif
hXXp://ilmesters.edu.pk/images/bottom.gif
hXXp://diaxisperu.com/bottom.gif
hXXp://furkanbedir.com/img/icons/bottom.gif
hXXp://atlascobranca.com.br/atlascobranca01/bottom.gif
hXXp://riviera-palace.com/images/logo.gif
%System%\drivers\hepjpn.sys
-a}"]q
13017506571
SHELL32.DLL
ShellExecuteA
KERNEL32.DLL
.rsrc
hXXp://89.119.67.154/testo5/
hXXp://kukutrustnet777.info/home.gif
hXXp://kukutrustnet888.info/home.gif
hXXp://kukutrustnet987.info/home.gif
.text
KERNEL32.dll
USER32.dll
h.rdata
H.data
.reloc
ntoskrnl.exe
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50728)
Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Software\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Microsoft\Windows\CurrentVersion
hXXp://VVV.klkjwre9fqwieluoi.info/
hXXp://kukutrustnet777888.info/
Software\Microsoft\Windows\CurrentVersion\policies\system
Software\Microsoft\Windows\ShellNoRoam\MUICache
%s:*:Enabled:ipsec
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
GdiPlus.dll
hXXp://
ipfltdrv.sys
VVV.microsoft.com
?%x=%d
&%x=%d
SYSTEM.INI
USER32.DLL
.%c%s
\\.\amsint32
NTDLL.DLL
autorun.inf
ADVAPI32.DLL
win%s.exe
%s.exe
WININET.DLL
InternetOpenUrlA
avast! Web Scanner
Avira AntiVir Premium WebGuard
cmdGuard
cmdAgent
Eset HTTP Server
ProtoPort Firewall service
SpIDer FS Monitor for Windows NT
Symantec Password Validation
WebrootDesktopFirewallDataService
WebrootFirewall
%d%d.tmp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
%s\%s
%s\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
Software\Microsoft\Windows\CurrentVersion\Ext\Stats
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Explorer.exe
A2CMD.
ASHWEBSV.
AVGCC.AVGCHSVX.
DRWEB
DWEBLLIO
DWEBIO
FSGUIEXE.
MCVSSHLD.
NPFMSG.
SYMSPORT.
WEBSCANX.
.adata
M_%d_
%c%d_%d
?456789:;<=
!"#$%&'()* ,-./0123
GetProcessHeap
GetWindowsDirectoryA
RegEnumKeyExA
RegDeleteKeyA
RegOpenKeyExA
RegCreateKeyA
RegCloseKey
SHFileOperationA
&3&3&3&389
.rdata
.data
Bkrnl.exe?
= =$=(=,=
322%2`.50728)
.klkjw:9fqwi
FamXf39.sys
.pBTa8
%s:*:
Bg.laXV
&?%x=
GUrlA'
Web%w|nc
HTTP)
2GUARDCMD.
.ENHCDM
PL/KPCKwWEB
MM.PFW.
.bssf
J:CRT
ADVAPI32.dll
MSVCRT.dll
SHELL32.dll
WS2_32.dll
%original file name%.exe_176_rwx_020C0000_00002000:
SHELL32.DLL
ShellExecuteA
KERNEL32.DLL
.rsrc
-a}"]q
Explorer.EXE_1684_rwx_00EE0000_00002000:
SHELL32.DLL
ShellExecuteA
KERNEL32.DLL
.rsrc
-a}"]q
%original file name%.exe_176_rwx_021D0000_00001000:
|%original file name%.exeM_176_
Explorer.EXE_1684_rwx_00EF0000_00001000:
|explorer.exeM_1684_
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\1467b-753f8[1].js (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\moatad[1].js (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@softonic[2].txt (1849 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\ads.min[1].js (1709 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2d9b4-b586d[1].css (147 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[4].jpg (518 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@softonic[1].txt (2313 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\427b6-dd89a[1].js (421 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6d482-41450[1].js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\17ad7-e5cc5[1].js (403 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\pubads_impl_65[1].js (2144 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\universaldownloader-prefetch[1].htm (1525 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\measure.min[1].js (10 bytes)
C:\ermq.pif (103 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\CAILYHON.1435517394&ga_sid=1435517394&ga_hid=48384997&ga_wpids=UA-43493347-1 (8 bytes)
%Program Files%\Adobe\Reader 9.0\Reader\Reader_sl.exe (432 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (23040 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bid[1].com/35586/universaldownloader-prefetch&cb=9268520 (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\f[1].txt (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\adsense[2].js (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\hshegy.exe (741 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\textlink-ads[2].jpg (518 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\b5ae7-7a102[1].css (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\moatad[2].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\f[1].txt (7552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\px[1].js (346 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bid[1].com/35586/universaldownloader-prefetch&cb=6252925 (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\741c2-5ad42[1].js (4243 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\textlink-ads[1].jpg (518 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\OpenSans-CondBold-webfont[1].eot (907 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\font-icon[1].eot (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\universaldownloader-prefetch[1].htm (1525 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\font-icon[1].eot (8 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@doubleclick[1].txt (445 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\interface_sprite[1].png (5453 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\f[1].txt (5559 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\container[1].html (622 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[1].txt (207 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\universaldownloader-prefetch[1].htm (1525 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\4cd46-f5ea2[1].js (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\moatad[3].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\f[2].txt (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\icons_sprite[1].png (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\OpenSans-CondLight-webfont[1].eot (973 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\f[2].txt (776 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pagefair[1].txt (135 bytes)
%WinDir%\system.ini (72 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\OpenSans-CondBold-webfont[1].eot (907 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\f[3].txt (2873 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@revsci[2].txt (373 bytes)
C:\autorun.inf (250 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\ads.min[1].js (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gtm[1].js (2231 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\analytics[1].js (740 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\404[1].png (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\amzn_ads[1].js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\icons_sprite_ie6[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\container[1].htm (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\OpenSans-CondBold-webfont[1].eot (1357 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\font-icon[1].eot (8 bytes)
%Program Files%\Common Files\Java\Java Update\jusched.exe (856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\px[1].js (346 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\CASXEBKX.1435517394&ga_sid=1435517398&ga_hid=365457603&ga_wpids=UA-43493347-1 (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\f[2].txt (3300 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\CAKV81OB.1435517394&ga_sid=1435517394&ga_hid=48384997&ga_wpids=UA-43493347-1 (328 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\beacon[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\adsense[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pagefair[2].txt (276 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\OpenSans-CondLight-webfont[1].eot (973 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\adsense[3].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\measure.min[1].js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\universaldownloader-prefetch[2].htm (1525 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\f[1].txt (2158 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[3].jpg (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\a[1].js (46 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\font-icon[1].eot (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\90f12-4e468[1].css (4423 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (3557 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\10496[1].js (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\amzn_ads[2].js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\moatad[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (3011 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\f[2].txt (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\40c2e-79a51[1].js (6237 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\OpenSans-CondLight-webfont[1].eot (1465 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[1].jpg (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\textlink-ads[2].jpg (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\adsense[1].js (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\moatad[2].js (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@doubleclick[2].txt (433 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bid[1].com/35586/universaldownloader-prefetch&cb=3747179 (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\softonic-logo-inline[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\7c7aa-ad7c7[1].js (807 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bid[1].com/35586/universaldownloader-prefetch&cb=4126714 (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\10496[1].js (7 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@revsci[1].txt (373 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[2].txt (370 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.