Trojan.Generic.16756639_d086269a5f

by malwarelabrobot on May 25th, 2016 in Malware Descriptions.

Trojan.BAT.StartPage.cu (Kaspersky), Trojan.Generic.16756639 (B) (Emsisoft), Trojan.Generic.16756639 (AdAware), Trojan.Win32.IEDummy.FD, Worm.Win32.AutoIt.FD, mzpefinder_pcap_file.YR, WormAutoItGen.YR (Lavasoft MAS)
Behaviour: Trojan, Worm


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: d086269a5ff40ddca8307ee837524399
SHA1: 8f8b8514ba2dcde41e980d653983cb3adc025e44
SHA256: 698da29a260642a5ea562b09d60293f6a744bb423a60f7a107883a43bbc1ebbb
SSDeep: 24576:taHMv6Corjqnyi8iYlaVWHAHQUpoEpmw6NIj7tg8gMxcc4v5gv312bYicKze:t1vqjdi83acHAHVpS3NIPO836h7K
Size: 1736014 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2010-04-16 10:47:33
Analyzed on: WindowsXP SP3 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

IconBubble.exe:3608
attrib.exe:2136
attrib.exe:2144
%original file name%.exe:704
tasklist.exe:2168
PPTV(pplive)_forqd340.exe:2912
PPLiveU.exe:2540
regedit.exe:604
regedit.exe:1368
regedit.exe:1604
regedit.exe:1944
regedit.exe:1900
regedit.exe:1112
regedit.exe:1864
regedit.exe:264
regedit.exe:1500
regedit.exe:256
regedit.exe:492
regedit.exe:220
PPAP.exe:3584
PPAP.exe:3520
regsvr32.exe:3920
find.exe:2192
forqd340.exe:1076

The Trojan injects its code into the following process(es):

PPAP.exe:3776
PPLive.exe:3560

Mutexes

The following mutexes were created/opened:

VA_SharedData_Mutex_Stat
VA_SharedData_Mutex
ZonesLockedCacheCounterMutex
ZonesCacheCounterMutex
ZonesCounterMutex
RasPbFile
WininetProxyRegistryMutex
WininetConnectionMutex
WininetStartupMutex
c:!documents and settings!adm!local settings!history!history.ie5!
c:!documents and settings!adm!cookies!
c:!documents and settings!adm!local settings!temporary internet files!content.ie5!
_!MSFTHISTORY!_
ShimCacheMutex

File activity

The process %original file name%.exe:704 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\All Users\Application Data\vcry\kswebshield.dll (4025 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\pi3603.exe (254330 bytes)
%Documents and Settings%\Administrator\Application Data\Tencent\AXSEF\AXSEF.exe (1477492 bytes)
%Documents and Settings%\All Users\Application Data\vcry\kwssp.dll (3641 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\location[1].htm (91 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\d.tmp (91 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\gou3603.exe (320269 bytes)
%Documents and Settings%\All Users\Desktop\forqd340.exe (1137 bytes)
%Program Files%\Microsoft Cdobe Emulator\Internat Explorer\Desktop.ini (75 bytes)
%Documents and Settings%\%current user%\Desktop\Internat Explorer.HIE (37 bytes)
%Documents and Settings%\%current user%\Desktop\okregreg.reg (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut4.tmp (2897 bytes)
%Documents and Settings%\All Users\Application Data\vcry\kswbc.dll (5873 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut3.tmp (3089 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (1176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut5.tmp (3185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (3185 bytes)
%Documents and Settings%\%current user%\Application Data\360se\360se.ini (39 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Desktop\okregreg.reg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut4.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut5.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (0 bytes)

The process tasklist.exe:2168 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%System%\tasklist.txt (157100 bytes)

The process PPTV(pplive)_forqd340.exe:2912 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\PPLive\PPTV\skins\default\loading_list.gif (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_top_bg_bar.png (244 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_checked_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\PlayProgressThumb_down.png (312 bytes)
%Program Files%\PPLive\PPTV\ckdll.dll (2392 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\miniclose.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\checkstart.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\common\btn_close_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titletab_on_hover.png (844 bytes)
%Program Files%\PPLive\PPTV\skins\default\button_down.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic\s_close_hover.png (607 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_min_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_on_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\close_down.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\previous_down.png (775 bytes)
%Program Files%\Common Files\PPLiveNetwork\Converter.dll (4992 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_progress_r.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\muteplus_hover.png (680 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumbgripper_hover.bmp (67 bytes)
%Program Files%\PPLive\PPTV\skins\default\contrast.png (362 bytes)
%Program Files%\PPLive\PPTV\skins\default\play_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_expand.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\min_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\exbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_HD.png (544 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_update.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\common.js (1552 bytes)
%Program Files%\PPLive\PPTV\data\face\em26-±ã±ã.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\dt_tab_check.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\restore_hover.png (662 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\checkstop.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch2_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_close_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumb_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\notop_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\color_thumb.png (191 bytes)
%Program Files%\PPLive\PPTV\skins\default2\unmute_normal.png (378 bytes)
%Program Files%\PPLive\PPTV\skins\classic\checkstart.png (4 bytes)
%Program Files%\PPLive\PPTV\chrome\education\PPAPIsForbidden.xml (3 bytes)
%Program Files%\PPLive\PPTV\tab\3\1\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\restore_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mode.bmp (1 bytes)
%Program Files%\PPLive\PPTV\tab\tab2.xml (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\unfullscreen_hover.png (720 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\VAProxyD.dll (3616 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_pagedown_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_top.bmp (918 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute3_normal.png (579 bytes)
%Program Files%\PPLive\PPTV\tab\7\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_HD.png (1088 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute2_down.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\NewDownloadTask.xml.js (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_hot4.png (784 bytes)
%Program Files%\PPLive\PPTV\tab\5\2\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\ad_close.bmp (568 bytes)
%Program Files%\PPLive\PPTV\skins\default2\PPLive32by32.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_down.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\default\top_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pageup.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mode_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize2002.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumbgripper_hover.bmp (67 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute3_down.png (670 bytes)
%Program Files%\PPLive\PPTV\skins\common\small\frame_r.png (995 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\checkstart_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\tab\7\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mini_bottom_m.bmp (888 bytes)
%Program Files%\PPLive\PPTV\skins\default2\max_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_top1.bmp (694 bytes)
%Program Files%\PPLive\PPTV\skins\common\download\volume_check.bmp (2 bytes)
%Program Files%\PPLive\PPTV\data\pplive_schedule_main.gif (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_pageup.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_checked_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\user_vip.gif (169 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_min_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute4_down.png (668 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\stream_spot.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\arrow-default.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\exbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizetop2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\fullscreen_normal.png (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic\speed4.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch2_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\vol_bar2.bmp (5 bytes)
%Program Files%\PPLive\PPTV\components\PPFrame.dll (19096 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_collapsed_treebox1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\saturation.png (366 bytes)
%Program Files%\PPLive\PPTV\skins\default\unfullscreen_normal.png (338 bytes)
%Program Files%\PPLive\PPTV\data\face\em29-½ûÖ¹.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\stop_down.png (667 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\button.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\PlayProgressThumb_hover.png (312 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\checkbox_checked_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default2\in_bg_bot.bmp (150 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_on_down.png (771 bytes)
%Program Files%\PPLive\PPTV\skins\default\dt_tab_check.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\common\btn_min_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hot_5.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hot_0.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hot_3.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default2\ico-exit.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_upright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_up_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\downloadbtn_disable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_expanded_treebox2.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\control_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\newsbg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_bg_bottom.bmp (476 bytes)
%Program Files%\PPLive\PPTV\skins\classic\download_pause.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\check_ok.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\adselector_title.jpg (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mini_bottom_l.bmp (368 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resizemini2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_hot4.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dtconfig_3.xml (7 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize0501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_pageup_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\unfullscreen_normal.png (331 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mini_title_l.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mini_title_m.bmp (1 bytes)
%Program Files%\PPLive\PPTV\tab\6\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_left_top.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\fullscreen_disabled.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_info_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ex_button.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\exbg_left_top.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\default2\close_down.png (766 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\set_bg_right_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrolcommon.js (2392 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_cate_hot.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\unmute_normal.png (502 bytes)
%Program Files%\PPLive\PPTV\chrome\education\HDSwitch.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\menu_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_close_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\icons\2_3.ico (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumb_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\downloading.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\exbg_left.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\1.png (1 bytes)
%Program Files%\PPLive\PPTV\ppopt.dll (3616 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_uparrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\max_down.png (555 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_sch.png (890 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_bot.bmp (728 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_downleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgressThumb_down.png (297 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute4_normal.png (614 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\Controlbar.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_sch.png (890 bytes)
%Program Files%\PPLive\PPTV\data\UrlCache.List (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_close_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_table_vod.png (784 bytes)
%Program Files%\PPLive\PPTV\data\local\images\nolink.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\close_numTip_hover.png (320 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\menu.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\blue.xml (278 bytes)
%Program Files%\PPLive\PPTV\skins\default2\exbg_left.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_pageup_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\ex_button.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\close_numTip_hover.png (320 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\next_down.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\signin.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumbgripper.bmp (488 bytes)
%Program Files%\PPLive\PPTV\data\buffer.swf (3616 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mini_main_r.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mode.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\dt_tab_check.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\asc.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_downright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_so_bot1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mini_main_r.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\download_pause.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resizeback.bmp (146 bytes)
%Program Files%\PPLive\PPTV\chrome\BatchDownload.xml (4 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.3GP.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\common\small\frame_title.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_epg_close.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resizetop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\downloadbtn_hover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\infobtn.bmp (918 bytes)
%Program Files%\PPLive\PPTV\tab\5\3\2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\shift2new.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\download_fail.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_right.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pause_close.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\exbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\default\Controlbar.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hot_3.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\avatar_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\omng.dll (16944 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\contrast.png (362 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\play_disabled.png (997 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\checkbox.bmp (576 bytes)
%Program Files%\PPLive\PPTV\chrome\DeleteFileFailTip.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\close_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_close_down.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mini_main_r.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\default2\playerinfo.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute2_hover.png (663 bytes)
%Program Files%\PPLive\PPTV\chrome\signin.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mode_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\local\icon2.gif (732 bytes)
%Program Files%\PPLive\PPTV\chrome\Balloons.js (784 bytes)
%Program Files%\PPLive\PPTV\PPLive.url (46 bytes)
%Program Files%\PPLive\PPTV\skins\classic\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_close_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ico-exit.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_on.png (793 bytes)
%Program Files%\PPLive\PPTV\skins\default2\menu_down.png (279 bytes)
%Program Files%\PPLive\PPTV\tab\6\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize_gripper.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\small_title_m.png (1 bytes)
%Program Files%\PPLive\PPTV\uninst.exe (3179 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\PPLive\PPTV Website.lnk (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\close_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\restore_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\updatetipclose.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\common\small_title_r.png (3 bytes)
%Program Files%\PPLive\PPTV\data\face\em48-˼¿¼.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\SliderThumb_normal.png (267 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ico-setting.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\button_hover.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ad_close.bmp (568 bytes)
%Program Files%\PPLive\PPTV\skins\classic\checkstart_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\radio_checked.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\login_bg.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\button_down.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default\hot_5.bmp (344 bytes)
%Program Files%\PPLive\PPTV\PPP.dll (50224 bytes)
%Program Files%\PPLive\PPTV\skins\default\menu.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_epg_back.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_expand.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_fav.png (885 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\pause_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_thumb_hover.png (287 bytes)
%Program Files%\PPLive\PPTV\data\local\images\err_3.jpg (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\dt_header_normal_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_expanded_treebox1.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\expanding.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute_down.png (648 bytes)
%Program Files%\PPLive\PPTV\skins\default2\check_ok.bmp (886 bytes)
%Program Files%\PPLive\PPTV\chrome\videoshot.xml (6 bytes)
%Program Files%\PPLive\PPTV\chrome\CodecFail.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\play_down.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\Troubleshooter.xml (11 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\user_normal.gif (98 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_close.png (12088 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\stop_disabled.png (510 bytes)
%Program Files%\PPLive\PPTV\skins\classic\downloadbtn_hover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\loading.gif (3 bytes)
%Program Files%\Common Files\PPLiveNetwork\resource\PPTV.url (86 bytes)
%Program Files%\PPLive\PPTV\skins\classic\exbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_table.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_search.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\download_fail.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizemini1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\unfullscreen_down.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\EROTSER.dat (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_menu.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute2_hover.png (948 bytes)
%Program Files%\Common Files\PPLiveNetwork\uilib.dll (24832 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_play.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\blue_b.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\data\local\errorPage.htm (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ico-exit.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\VIPChannelTip.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\notop_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_downarrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\chrome\main.js (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgress3.bmp (716 bytes)
%Program Files%\PPLive\PPTV\chrome\NoAds.xml (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\checkbox_checked_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\classic\speed3.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\downloadbtn_normal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\shift2new.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\dt_tab_uncheck.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\radio_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_table_down.png (535 bytes)
%Program Files%\PPLive\PPTV\skins\default\capture_default.png (2392 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\radio_check_sel.gif (46 bytes)
%Program Files%\Common Files\PPLiveNetwork\admodule.dll (27704 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_collapsed_treebox2.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titlebar_bg_m.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_hover.png (7 bytes)
%Program Files%\PPLive\PPTV\skins\default2\shift2old_hover.png (628 bytes)
%Program Files%\PPLive\PPTV\skins\default2\set_bg_left_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_up_triangle.bmp (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\player\audioswitcher.ax (11048 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch2_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_bot.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_left_top.bmp (6 bytes)
%Program Files%\PPLive\PPTV\data\face\em14-ʧÍû.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\PPAP.exe (15168 bytes)
%Program Files%\PPLive\PPTV\data\portalbg.jpg (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\version.ini (111 bytes)
%Program Files%\PPLive\PPTV\skins\classic\avatar_bg.png (1856 bytes)
%Program Files%\PPLive\PPTV\skins\default2\unmute_down.png (2 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.RA.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\hj_expand.png (284 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\stream_spot.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default2\play_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizetop1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\pause_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_right_top.bmp (702 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\playhj.png (478 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pageup_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\chrome\education\Pause2Buffer.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\GetCommentsInfoDll.dll (1856 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute_disabled.png (307 bytes)
%Program Files%\PPLive\PPTV\skins\default\PPLive32by32.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_uparrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\unmute_normal.png (502 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\previous_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute3_hover.png (669 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_up.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\previous_disabled.png (489 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute_normal.png (533 bytes)
%Program Files%\PPLive\PPTV\skins\default\exbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\previous_normal.png (614 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hj_unexpand.png (295 bytes)
%Program Files%\PPLive\PPTV\skins\classic\min.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_downarrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_close_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\checkbox_checked_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\data\face\em11-Ôã¸â.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\min_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_left_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\stop_normal.png (337 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_epg_back2.bmp (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\list\catalog-1-0.xml (3 bytes)
%Program Files%\PPLive\PPTV\data\audio.swf (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\miniclose.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\s_close_hover.png (607 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_screenhover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\Troubleshooter.dll (9320 bytes)
%Program Files%\PPLive\PPTV\UPDATE\ICON.ico (4992 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_downarrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\components\PPChLocalManager.dll (9608 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_numTip.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_min_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\tomain.png (449 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_uparrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_uparrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\chrome\SkipAdsBalloon.xml (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\exbg_left_top.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pop_close.png (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn7.tmp (843408 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\SliderThumb_hover.png (247 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute4_disabled.png (614 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pageup_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\downloadbtn_disable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\tab\3\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_collapsed_treebox2.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\miniclose.bmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\cknsis.dll (1856 bytes)
%Program Files%\PPLive\PPTV\PlugOut\client_ap.dll (19096 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumbgripper_down.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_progress_in.png (947 bytes)
%Program Files%\PPLive\PPTV\skins\black.xml (280 bytes)
%Program Files%\Common Files\PPLiveNetwork\crashreporter.exe (7192 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\unfullscreen_normal.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\default2\muteplus_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_downleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch2_hover.png (989 bytes)
%Program Files%\PPLive\PPTV\skins\default\checkstop.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_search.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_updata_3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\speed1.png (1 bytes)
%Program Files%\PPLive\PPTV\icons\game.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\notop_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_screenhover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\dt_tab_uncheck.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize1001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mode_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\firewall.swf (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\capture_default.png (2392 bytes)
%Program Files%\PPLive\PPTV\skins\default2\login_ing.gif (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\MngModule.dll (32824 bytes)
%Program Files%\PPLive\PPTV\skins\default\next_hover.png (772 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\CommonFuncDll.dll (2392 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch_hover.png (797 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_menu.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\default\play_disabled.png (997 bytes)
%Program Files%\PPLive\PPTV\skins\default2\des.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_so_bot1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\check_alarm.bmp (822 bytes)
%Program Files%\PPLive\PPTV\data\local\images\bg_x_channel.png (355 bytes)
%Program Files%\PPLive\PPTV\skins\default2\restore.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\playhj.png (478 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hj_expand_new.png (299 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\top.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize1501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\stop_disabled.png (333 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_on.png (843 bytes)
%Program Files%\PPLive\PPTV\chrome\DownloadCodec.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute3_hover.png (957 bytes)
%Program Files%\PPLive\PPTV\skins\default\infobtn.bmp (918 bytes)
%Program Files%\PPLive\PPTV\skins\default2\vol_bar1.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\speed4.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\restore_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\PPLive32by32.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_top.bmp (4 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\live\Live.dll (7192 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\restore_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\updatetipclose.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\playhj.png (478 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\muteplus_down.png (682 bytes)
%Program Files%\PPLive\PPTV\skins\classic\exbg_left.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\radio_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_epg_back3.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em54-ËÄÒ¶²Ý.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\speed3.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_downarrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\unfullscreen_disabled.png (336 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_top1.bmp (694 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\expanding.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\button.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\common\small\frame_bottom.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_triangle.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\frame_r.png (995 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mini_bottom_l.bmp (368 bytes)
%Program Files%\PPLive\PPTV\chrome\VIPDownloadHD.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\shift_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\tab\5\0\2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\ex_button_hover.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_pageup_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\SliderThumb_down.png (267 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch_disabled.png (475 bytes)
%Program Files%\PPLive\PPTV\chrome\education\RegVip.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pdot.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mini_main_l.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute3_disabled.png (579 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\checkbox_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_top_bg_bar.png (229 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\SliderThumb_hover.png (344 bytes)
%Program Files%\PPLive\PPTV\chrome\userpopup.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\shift_disabled.png (286 bytes)
%Program Files%\PPLive\PPTV\data\Postpone.List (283 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_left.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\classic\adselector_title.jpg (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute4_disabled.png (338 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mini_title_l.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ie.png (895 bytes)
%Program Files%\PPLive\PPTV\skins\classic\downloadbtn_disable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_pageup_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute2_disabled.png (663 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ie.png (895 bytes)
%Program Files%\PPLive\PPTV\skins\classic\menu_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\restore.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrol2mini.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\default\mini_bottom_r.bmp (368 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\unfullscreen_hover.png (923 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_close.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\downloadbtn_normal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mode.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_left_top.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\previous_normal.png (467 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_right_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\chrome\education\AutoSeek.xml (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute4_disabled.png (671 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch_normal.png (672 bytes)
%Program Files%\PPLive\PPTV\skins\default2\max_hover.png (564 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_epg_close.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\adselector_title.jpg (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\stop_normal.png (505 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize_gripper.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\fullscreen_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumbgripper.bmp (67 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ad_close.bmp (568 bytes)
%Program Files%\PPLive\PPTV\skins\default\muteplus_normal.png (376 bytes)
%Program Files%\PPLive\PPTV\data\face\em34-Ììʹ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_close_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\frame_bottom_m.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_close.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\restore.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute_hover.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\FWUpnp.dll (5064 bytes)
%Program Files%\PPLive\PPTV\skins\default2\speed1.png (1 bytes)
%Program Files%\PPLive\PPTV\ProductUpdate.dll (23424 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_updata_3.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mini_main_l.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\top.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ex_button_down.bmp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\bind_en-us.ini (80 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_uparrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pop_hot_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_uparrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute2_hover.png (948 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_top.bmp (162 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_downarrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\menu_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\sort_list_btn.png (667 bytes)
%Program Files%\PPLive\PPTV\skins\default\next_down.png (777 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\speed0.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_cate_hot.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\notop_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pause_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\close_numTip_normal.png (204 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_downarrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\exbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\skins\default2\button.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\newsbg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\expanding.png (353 bytes)
%Program Files%\PPLive\PPTV\skins\classic\previous_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\stream_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_close_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\unfullscreen_disabled.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch2_disabled.png (761 bytes)
%Program Files%\PPLive\PPTV\skins\default2\exbg_left_bot.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\speed3.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_bot.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\unmute_normal.png (656 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_bot_bg_down.png (1856 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\SliderThumb_down.png (267 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_hover.gif (1856 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_livebtn.png (890 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute_disabled.png (533 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_expanded_treebox1.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\vol_bar1.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\PlayProgress3.bmp (296 bytes)
%Program Files%\PPLive\PPTV\skins\default2\PlayProgressThumb_normal.png (301 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_pagedown_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_menu_down.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\next_down.png (777 bytes)
%Program Files%\PPLive\PPTV\skins\default\button.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize2002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.WAV.ico (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\BindDLL.dll (1856 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pushplay.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hot_4.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\SliderThumb_down.png (357 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resizenotop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_expand.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_uparrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\avatar_bg_s.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\download_pause.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\checkstop_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resizetop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\checkstart.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\checkbox_checked.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute2_down.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\live\tpi.dll (30464 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\top.bmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\gtapi_signed.dll (2392 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_menu.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_bot_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\shift_hover.png (641 bytes)
%Program Files%\PPLive\PPTV\skins\classic\muteplus_disabled.png (556 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize2002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrolfullscreen.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_hot3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\exbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute2_normal.png (556 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_epg_bk.bmp (214 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_expanded_treebox1.png (1552 bytes)
%Program Files%\PPLive\PPTV\icons\2_1.ico (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_bg_m.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_close.bmp (822 bytes)
%Documents and Settings%\All Users\Application Data\Jlcm\profiles.ini (81 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute4_normal.png (374 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_pagedown.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\speed1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_updata_2.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_min_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\strengthenbtn02.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_pagedown_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\TestChannel.txt (451 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\dtconfig_3.xml (8 bytes)
%Program Files%\PPLive\PPTV\skins\classic\SliderThumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\config.xml (10 bytes)
%Program Files%\PPLive\PPTV\skins\classic\checkstart_down.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\downloading.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\updatetipclose.bmp (3 bytes)
%Program Files%\PPLive\PPTV\UPDATE\upgrade_bg1.bmp (5064 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize0501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\data\pptvpopo1.swf (6 bytes)
%Program Files%\PPLive\PPTV\skins\default\close_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_so_bar.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resizetop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\menu.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\autoshutdown.xml (5 bytes)
%Program Files%\PPLive\PPTV\Plugin\mframe.dll (21216 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_down_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\downloading.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_bot_hover.gif (1856 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\muteplus_normal.png (556 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_bot_bg_hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mini_bottom_l.bmp (368 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_delete.png (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_top_bg_right.png (456 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pageup.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\checkstart_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_so_bot1.png (1552 bytes)
%Program Files%\PPLive\PPTV\chrome\BatchDownload.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\components\condisp.dll (2392 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_expanded_treebox2.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_epg_bk.bmp (214 bytes)
%Program Files%\PPLive\PPTV\components\PPFlvCom.dll (2392 bytes)
%Program Files%\PPLive\PPTV\player\VSFilter.dll (33633 bytes)
%Program Files%\PPLive\PPTV\skins\classic\unmute_disabled.png (653 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\tab\6\3\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\menu_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\restore_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\radio_checked_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\unmute_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\PlayProgressThumb_normal.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\default\stream_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\fullscreen_normal.png (761 bytes)
%Program Files%\PPLive\PPTV\skins\default2\stop_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\button_disable.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_down.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hot_1.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\common\user_normal.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\unmute_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute4_normal.png (614 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\muteplus_disabled.png (680 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\default\min.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumb_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\notop_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pushplay.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\common\button_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_collapse.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumb_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\VolumePopDlg.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\shift_down.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\DownloadPPGame.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\min_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\notop_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\stop_normal.png (280 bytes)
%Program Files%\PPLive\PPTV\tab\6\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute2_disabled.png (663 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_top_bg_left.png (511 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\des.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\expanding.png (353 bytes)
%Program Files%\PPLive\PPTV\skins\default\top_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\avatar_bg.png (1856 bytes)
%Program Files%\PPLive\PPTV\skins\default\bright.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_uparrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\play_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em15-Öí.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_right_top.bmp (702 bytes)
%Program Files%\PPLive\PPTV\skins\default2\checkstop.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\set_bg_bot.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\default\PlayProgressThumb_normal.png (297 bytes)
%Program Files%\PPLive\PPTV\skins\classic\unfullscreen_normal.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\user_normal.gif (98 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumbgripper_down.bmp (67 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_update.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\PlayProgress1.bmp (13 bytes)
%Program Files%\Common Files\PPLiveNetwork\restore.dll (5064 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_upleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\tab\8\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\capture_default.png (2392 bytes)
%Program Files%\PPLive\PPTV\skins\common\download\dt_header_normal_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_downarrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\radio.png (3 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.AVI.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\min_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\playerinfo.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bdclose.png (198 bytes)
%Program Files%\PPLive\PPTV\data\face\em50-¶³ÝЦ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_on_hover.png (843 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_del_record.png (2 bytes)
%Program Files%\PPLive\PPTV\tab\4\3\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\speed3.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_left.bmp (134 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\radio.png (3 bytes)
%Program Files%\PPLive\PPTV\data\face\em16-Õð¾ª.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\checkstart.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\InetLoad.dll (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\infobtn.bmp (918 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mini_main_l.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_collapsed_treebox2.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\fullscreen_normal.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\default2\shift_normal.png (416 bytes)
%Program Files%\PPLive\PPTV\UPDATE\CH.INI (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\play_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\2\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\min_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\color_thumb.png (191 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_search.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\stream_spot.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default2\muteplus_disabled.png (326 bytes)
%Program Files%\PPLive\PPTV\skins\default\dt_tab_uncheck.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\small_frame_r.png (995 bytes)
%Program Files%\PPLive\PPTV\skins\default2\groupbox.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\checkstart_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize0502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_up.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\default\PlayProgress3.bmp (716 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\unmute_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\radio_checked_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute3_disabled.png (669 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\top_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\exbg_left_bot.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute4_disabled.png (671 bytes)
%System%\kindling.dll (23936 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resizenotop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\expanding.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\unmute_down.png (793 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumbgripper.bmp (67 bytes)
%Program Files%\PPLive\PPTV\chrome\VIPLogin.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\muteplus_hover.png (947 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_bot_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\chrome\mainframe2.xml (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_close.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\default\avatar_bg_s.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\downloadbtn_hover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute3_hover.png (669 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\checkstart.png (4 bytes)
%Program Files%\PPLive\PPTV\data\face\em53-»ð.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_downright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_min_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\dt_titlebar_m.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_top_bg_left.png (683 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_so_left.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\stop_down.png (667 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic\user_vip.gif (169 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bright.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\default\set_bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch2_disabled.png (761 bytes)
%Program Files%\PPLive\PPTV\InstallLog.txt (18517 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch2_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hj_unexpand_new.png (267 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\checkbox_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\muteplus_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\radio_checked_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\muteplus_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_top_bg_right.png (456 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pop_hot_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\dt_titlebar_m.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\download_wait.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumb_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute3_hover.png (957 bytes)
%Program Files%\PPLive\PPTV\skins\default2\min.png (233 bytes)
%Program Files%\PPLive\PPTV\player\CoreAAC.ax (11344 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumb_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_checked_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\next_disabled.png (449 bytes)
%Program Files%\PPLive\PPTV\skins\default2\default_pic.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.0.595\ppp.dll (8560 bytes)
%Program Files%\PPLive\PPTV\skins\classic\alert.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\SliderThumb_normal.png (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic\max_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em51-Ñ©ÈË.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\next_hover.png (998 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_livebtn_down.png (757 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\checkbox_checked_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\resizeback.bmp (146 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resizeratebg.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_new3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_left.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_updata_3.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_close_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\unfullscreen_normal.png (338 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\pause.png (449 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\play_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resizetop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\in_bg_left_bot.bmp (670 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_pagedown_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\next_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resizemini1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\max_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em38-ÌôüÍÂÉà.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hot_5.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_left.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\classic\shift2new_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\timingshutdown.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize_gripper.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\button_down.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\dtconfig_3.xml (8 bytes)
%Program Files%\PPLive\PPTV\skins\classic\regvip.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\default\set_bg_left_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\skins\default\restore_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_uparrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\strengthenbtn02.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\default\muteplus_disabled.png (680 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumbgripper.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mini_bottom_r.bmp (368 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_uparrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_down_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hot_3.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\downloadbtn_hover.bmp (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\Hookkernel.dll (10136 bytes)
%Program Files%\PPLive\PPTV\skins\default2\shift_disabled.png (397 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_collapsed_treebox1.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\radio_checked_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\common\btn_min_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumb.bmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\version[1].ini (111 bytes)
%Program Files%\PPLive\PPTV\tab\1\1\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_downarrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\download_wait.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\checkstop_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\data\face\em39-²»·þ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\dt_titlebar_r.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\close_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\exbg_left_top.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv.png (674 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\dt_tab_check.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\close_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pushplay.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pop_close.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_downarrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\stream_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\PPTVLicense.txt (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\set_bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\components\chctrl.dll (38495 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pause_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_pagedown_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\capture_default.png (12 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_pagedown_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\loading.gif (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\color_thumb.png (191 bytes)
%Program Files%\PPLive\PPTV\player\audioswitcher.ax (11048 bytes)
%Program Files%\PPLive\PPTV\chrome\PPPlayer.js (784 bytes)
%Program Files%\PPLive\PPTV\chrome\CodecFail.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\chrome\timingservice.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hot_1.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch_vip.png (443 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_down.png (7 bytes)
%Program Files%\PPLive\PPTV\tab\2\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\tab\4\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.MP4.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bright.bmp (15 bytes)
%Program Files%\PPLive\PPTV\sqlite3.dll (16288 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumbgripper_hover.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\default2\close_numTip_hover.png (320 bytes)
%Program Files%\PPLive\PPTV\skins\classic\Controlbar.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_close_down.bmp (822 bytes)
%Program Files%\PPLive\PPTV\data\face\em23-Ç×Ç×.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\restore.png (329 bytes)
%Program Files%\PPLive\PPTV\skins\default2\strengthenbtn01.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\classic\play_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\config.xml (10 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_downright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pop_close.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\logo.jpg (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\mini_title_l.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_titlebar_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hot_1.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_updata_2.gif (1856 bytes)
%Program Files%\PPLive\PPTV\skins\default\tab_background.png (153 bytes)
%Program Files%\PPLive\PPTV\chrome\coveredfile.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\check_alarm.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\default2\play_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\sort_list_btn.png (667 bytes)
%Program Files%\PPLive\PPTV\skins\default2\stop_disabled.png (280 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_downarrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\tab\1\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_min_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\speed1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\close_numTip_hover.png (320 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_uparrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute3_disabled.png (669 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resizeback.bmp (146 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\arrow-default.png (1552 bytes)
%Program Files%\PPLive\PPTV\components\IEBrowser.dll (8184 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute2_normal.png (362 bytes)
%Program Files%\PPLive\PPTV\icons\2_2.ico (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute3_disabled.png (579 bytes)
%Program Files%\PPLive\PPTV\skins\classic\PlayProgressThumb_down.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\fullscreen_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize1501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\components\Gallop.dll (2392 bytes)
%Program Files%\PPLive\PPTV\skins\default\pause_down.png (2 bytes)
%Program Files%\PPLive\PPTV\player\MP4Splitter.ax (17848 bytes)
%Program Files%\PPLive\PPTV\skins\classic\set_bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\data\face\em19-ÈÈ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\radio_checked_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\strengthenbtn01.bmp (8 bytes)
%Program Files%\PPLive\PPTV\chrome\mainframe2.js (6584 bytes)
%Program Files%\PPLive\PPTV\skins\default\max.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pdot.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\bdclose.png (198 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_left_bot.bmp (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\TipsClient.dll (8560 bytes)
%Program Files%\PPLive\PPTV\skins\default\previous_disabled.png (444 bytes)
%Program Files%\PPLive\PPTV\skins\default\updatetipclose.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hot_1.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_epg_back2.bmp (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\sop.dll (16424 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ico-setting.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\PlayProgressThumb_hover.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_numTip.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\hj_unexpand_new.png (267 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_pageup_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_top_bg_left.png (511 bytes)
%Program Files%\PPLive\PPTV\skins\default2\speed4.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\restore_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\stop_hover.png (664 bytes)
%Program Files%\PPLive\PPTV\skins\default2\fullscreen_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize1002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em55-²ö.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\contrast.png (362 bytes)
%Program Files%\PPLive\PPTV\NOISREV.DAT (31 bytes)
%Program Files%\PPLive\PPTV\skins\default\mini_main_l.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mini_bottom_r.bmp (368 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_close.png (12088 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\radio_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\mini_main_r.bmp (176 bytes)
%Program Files%\PPLive\PPTV\tab\2\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_close_hover.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\default\config.xml (10 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_down.png (1 bytes)
%Program Files%\PPLive\PPTV\What's new.txt (6 bytes)
%Program Files%\PPLive\PPTV\skins\default\ex_button_down.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\avatar_bg_s.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\color_thumb.png (191 bytes)
%Program Files%\PPLive\PPTV\skins\default2\restore_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute4_hover.png (671 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\checkstop_down.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize1001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrol2.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute4_normal.png (339 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\unmute_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_right.bmp (134 bytes)
%Program Files%\PPLive\PPTV\skins\default2\stream_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hot_0.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resizenotop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\mini_title_r.bmp (696 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_menu_hover.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_triangle.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\miniSite.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\speed2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\data\face\em18-¹ÄÁ³.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hj_expand.png (284 bytes)
%Program Files%\PPLive\PPTV\skins\default\next_normal.png (470 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_checked.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_hot3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\hj_expand_new.png (299 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mini_title_r.bmp (696 bytes)
%Program Files%\PPLive\PPTV\skins\default\expanding.png (353 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\unmute_hover.png (792 bytes)
%Program Files%\PPLive\PPTV\skins\common\small\control_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\top_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\mini_title_m.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\ieloading.swf (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_top_bg_left.png (683 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mini_title_m.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_update.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_upright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\exbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\classic\stream_spot.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\checkbox.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_collapsed_treebox2.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\brightness.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_menu_hover.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_uparrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\exbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_close_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_HD.png (1088 bytes)
%Program Files%\PPLive\PPTV\skins\default\vol_bar1.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_upleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\tab\4\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\download_fail.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_close_down.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\default\hot_4.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch_normal.png (672 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute_hover.png (929 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_menu_hover.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\asc.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hot_0.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\menu_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute4_down.png (2 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.0.595\mframe.dll (16944 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_downarrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_epg_back3.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\menu.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_cate_new.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\expanding.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\exbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_sch_down.png (757 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_right_top.bmp (702 bytes)
%Program Files%\PPLive\PPTV\skins\classic\checkstop.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\max_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\small_title_l.png (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\classic\shift2new_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\tab\4\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\stop_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\radio_check.gif (46 bytes)
%Program Files%\PPLive\PPTV\data\face\em46-ÓêÉ¡.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resizenotop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2.ppui (302 bytes)
%Program Files%\PPLive\PPTV\skins\default2\in_bg_left_top.bmp (670 bytes)
%Program Files%\PPLive\PPTV\skins\classic\fullscreen_normal.png (761 bytes)
%Program Files%\PPLive\PPTV\skins\default\dt_titlebar_l.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\stream_bg.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_table_down.png (535 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\frame_title.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\radio.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\top_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hj_unexpand.png (295 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_thumb_normal.png (274 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titlebar_m.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\info_arrow.bmp (138 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mini_bottom_r.bmp (368 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_top_bg_right.png (456 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\dt_selitem_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\below_title.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_expanded_treebox2.png (784 bytes)
%Program Files%\Common Files\PPLiveNetwork\IEBrowser.dll (16424 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\pnsis.dll (2392 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pause_disabled.png (525 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pdot.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\restore_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_downarrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize2002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_bar_1.png (995 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\volume.png (462 bytes)
%Program Files%\PPLive\PPTV\skins\default\restore.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pause_down.png (3 bytes)
%Program Files%\PPLive\PPTV\chrome\PPGameIsSetup.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch_disabled.png (672 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizenotop1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_cate_hot.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\unfullscreen_down.png (987 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_so_bar.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\PlayProgress2.bmp (784 bytes)
%Program Files%\PPLive\PPTV\tab\7\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_pagedown_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\set_bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\default2\close.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\hot_1.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_uparrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\loading_list.gif (520 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_collapse.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\asc.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_downarrow_down.bmp (938 bytes)
%Program Files%\Common Files\PPLiveNetwork\player\CoreAAC.ax (11344 bytes)
%Program Files%\PPLive\PPTV\skins\default2\min.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\RegUser.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\frame_bottom.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\Controlbar.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\parsing.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\7\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\small\frame_l.png (165 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close_hover.bmp (822 bytes)
%Program Files%\Common Files\PPLiveNetwork\GdiPlus.dll (51840 bytes)
%Program Files%\PPLive\PPTV\skins\default\resizeratebg.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\white_dot.png (130 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\exbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\default2\downloading.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\shift_down.png (462 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\arrow_right_sel.gif (59 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_bot.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize1001.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\set_bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\SliderThumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_close.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\arrow_right.gif (59 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_upright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\tomain_down.png (454 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\exbg_left_bot.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute2_disabled.png (556 bytes)
%Program Files%\PPLive\PPTV\skins\classic\loading_list.gif (520 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize1002.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch_normal.png (475 bytes)
%Program Files%\PPLive\PPTV\chrome\education\FindChannelTip.xml (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\arrow-hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_bot.bmp (728 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\volume_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\blue.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch_hover.png (797 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize1502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\checkbox_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\unmute_disabled.png (792 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute3_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\menu_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\checkbox_checked_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default2\downloadbtn_normal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_up.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\tab_background.png (153 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute_hover.png (647 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\dt_titlebar_l.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\strengthenbtn02.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\groupbox.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\resizetop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute3_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\play_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_downright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titletab_down.png (6 bytes)
%Program Files%\PPLive\PPTV\skins\default\set_bg_bot.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_expand.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_triangle.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\PlayProgress2.bmp (13 bytes)
%Program Files%\PPLive\PPTV\chrome\SkipAds.xml (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumbgripper_hover.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_close_hover.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_left_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_uparrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_bg_hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_close_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_right_top.bmp (702 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\stop_hover.png (960 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\infobtn.bmp (918 bytes)
%Program Files%\PPLive\PPTV\data\face\em04-ºÇºÇ.png (1 bytes)
%Program Files%\PPLive\PPTV\GdiPlus.dll (51840 bytes)
%Program Files%\PPLive\PPTV\skins\default\hot_0.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default2\unmute_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\shift_normal.png (307 bytes)
%Program Files%\PPLive\PPTV\chrome\BalloonCommon.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\set_bg_left_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pause_close.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_collapsed_treebox1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\speed2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\arrow-default.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_sch_down.png (757 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_collapse.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_top_bg_bar.png (229 bytes)
%Program Files%\PPLive\PPTV\skins\default2\frame_r.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\muteplus_down.png (682 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_min_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_screendisable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_close.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\notop.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute_normal.png (335 bytes)
%Program Files%\PPLive\PPTV\data\face\em03-´ô.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\check_alarm.bmp (822 bytes)
%Program Files%\PPLive\PPTV\chrome\education\MyPPTVTip.xml (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_collapsed_treebox1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\notop.bmp (1 bytes)
%Program Files%\PPLive\PPTV\tab\7\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumb.bmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bind_en-us[1].ini (80 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_right.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_left.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\default2\max_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\player\OPlayer.ocx (34186 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_downleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\checkbox_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\radio_checked.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\checkstart_down.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\checkstop.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\max_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_hot3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\checkstop_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resizemini2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch_disabled.png (672 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumbgripper_hover.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumb_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\icons\PPLive.ico (4992 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\exbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_bot_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\common\shift2new_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\mode_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_new3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\unfullscreen_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_left.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_bot_bg_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\loading_list.gif (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\mini_bottom_m.bmp (888 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\unmute_normal.png (656 bytes)
%Program Files%\PPLive\PPTV\skins\default2\contrast.png (362 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_close_down.png (2 bytes)
%Program Files%\PPLive\PPTV\crashreporter.exe (7192 bytes)
%Program Files%\PPLive\PPTV\chrome\coloradjust.xml (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_cate_new.png (784 bytes)
%Program Files%\PPLive\PPTV\data\face\em37-¾À½á.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_bot.bmp (728 bytes)
%Program Files%\PPLive\PPTV\skins\classic\dt_titlebar_m.png (1 bytes)
%Program Files%\PPLive\PPTV\data\local\page2.html (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\PPBindDAC.dll (1552 bytes)
%Program Files%\PPLive\PPTV\UPDATE\progress.gif (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\playerinfo.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\exbg_left.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_pagedown.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_Classic2New.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_checked.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\frame_bottom_r.png (929 bytes)
%Program Files%\PPLive\PPTV\data\face\em17-Àä.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\miniclose.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\set_bg_bot.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute3_disabled.png (333 bytes)
%Program Files%\PPLive\PPTV\data\face\em43-ßÖ×ìɵЦ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\skin.ini (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\exbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mini_title_l.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\default\hot_3.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\common\mini_bottom_r.bmp (140 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pageup_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\uilib.dll (24832 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\icons\3.ico (2 bytes)
%Program Files%\PPLive\PPTV\chrome\Troubleshooter.xml.js (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_top.bmp (918 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\white_dot.png (130 bytes)
%Program Files%\PPLive\PPTV\skins\default\saturation.png (366 bytes)
%Program Files%\PPLive\PPTV\skins\default\brightness.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\default\mini_bottom_l.bmp (368 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\set_bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\tab\5\0\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pagedown_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\stop_disabled.png (510 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch_normal.png (475 bytes)
%Program Files%\PPLive\PPTV\chrome\VIPDownloadLogin.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_tab_check.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\ch_vip.png (443 bytes)
%Program Files%\PPLive\PPTV\skins\default\play_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\PPLive32by32.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\common\mini_title_l.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_expanded_treebox1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_downarrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\muteplus_hover.png (947 bytes)
%Program Files%\PPLive\PPTV\skins\default2\unmute_disabled.png (378 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\shift2new.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_bot_hover.gif (1856 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\capture_default.png (12 bytes)
%Program Files%\PPLive\PPTV\skins\default\checkstart_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\data\face\em40-ÎÞÄÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize0501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\speed1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute_hover.png (929 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_progress_l.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pop_hot_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\tab_background.png (153 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\close_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_menu_down.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\radio_checked_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\min.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizeback.bmp (760 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hj_unexpand.png (295 bytes)
%Program Files%\PPLive\PPTV\skins\default\resizenotop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\min_hover.png (456 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_close.png (12088 bytes)
%Program Files%\PPLive\PPTV\skins\default\mode.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_info_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\SliderThumb_normal.png (267 bytes)
%Program Files%\PPLive\PPTV\data\PPLiveFlv.swf (14 bytes)
%Program Files%\PPLive\PPTV\skins\default2\nav_status_m.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_screendisable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\muteplus_disabled.png (556 bytes)
%Program Files%\PPLive\PPTV\skins\default\top.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\speed4.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\fullscreen_hover.png (657 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ex_button_hover.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\avatar_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pop_hot_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mini_title_l.bmp (6 bytes)
%Program Files%\Common Files\PPLiveNetwork\sqlite3.dll (17848 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\exbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\tab\7\1\2.png (2 bytes)
%Program Files%\PPLive\PPTV\chrome\Options.xml (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hj_expand_new.png (299 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\speed0.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute2_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_bot.png (1552 bytes)
%Program Files%\PPLive\PPTV\tab\5\1\2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pause_normal.png (525 bytes)
%Program Files%\PPLive\PPTV\PPLive.exe (15168 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hot_2.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumb_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\pptvpopo.swf (784 bytes)
%Program Files%\PPLive\PPTV\skins\common\close.png (311 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\shift2new_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\ex_button_down.bmp (730 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute4_hover.png (961 bytes)
%Program Files%\PPLive\PPTV\chrome\education\OldJumpAdTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\info_arrow.bmp (138 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_epg_back3.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_left_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_triangle.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hot_3.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_fav_down.png (757 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pause_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\next_normal.png (624 bytes)
%Program Files%\PPLive\PPTV\skins\default2\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch_down.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\icons\default.ico (4992 bytes)
%Program Files%\PPLive\PPTV\tab\3\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\arrow-default.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute2_hover.png (663 bytes)
%Program Files%\PPLive\PPTV\skins\default\pop_hot_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\6\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\min.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_search.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_top_bg_right.png (463 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_pageup_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\UPDATE\upgrade_title.bmp (1856 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\SliderThumb_hover.png (247 bytes)
%Program Files%\PPLive\PPTV\skins\default2\loading-2.gif (2 bytes)
%Program Files%\PPLive\PPTV\UPDATE\upgrade_bg2.bmp (5064 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\System.dll (11 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_screendisable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\chrome\education\FirewallForbidden.xml (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_so_bar.png (784 bytes)
%Program Files%\PPLive\PPTV\chrome\VIPDownload.xml (6 bytes)
%Program Files%\PPLive\PPTV\chrome\education\NewJumpAdTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\admodule.dll (31856 bytes)
%Program Files%\PPLive\PPTV\skins\classic\speed0.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_pagedown_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_HD.png (544 bytes)
%Program Files%\PPLive\PPTV\skins\default2\exbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_hot3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_close_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_fav.png (885 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_uparrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_bot_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_close_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\checkstop_down.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute3_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_left.bmp (134 bytes)
%Program Files%\PPLive\PPTV\skins\default\downloadbtn_normal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ie.png (895 bytes)
%Program Files%\PPLive\PPTV\skins\default\check_ok.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\classic\stop_hover.png (960 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\next_disabled.png (449 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\next_hover.png (998 bytes)
%Program Files%\PPLive\PPTV\skins\classic\max_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_bot_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\data\local\images\err_1.png (9 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute3_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_expanded_treebox1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_pagedown_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_livebtn.png (890 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_on_down.png (843 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_downleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default2\brightness.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\volume1_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bdclose.png (198 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\unfullscreen_hover.png (720 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch2_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em12-²»Êæ·þ.png (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em36-IloveUÊÖÊÆ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch2_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_new3.png (784 bytes)
%Program Files%\PPLive\PPTV\data\face\em24-Õ£ÑÛ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize2001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\muteplus_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\notop.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\pause_disabled.png (813 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_new3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pause_normal.png (525 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_upleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default2\shift2old.png (314 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\s_close_down.png (473 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\strengthenbtn02.bmp (8 bytes)
%Program Files%\PPLive\PPTV\chrome\OffLine.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\min_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pageup_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.RM.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_left.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize0501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_close_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\close.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumbgripper_hover.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize_gripper.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_sch_down.png (757 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch2_hover.png (989 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute_normal.png (335 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pagedown_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\frame_l.png (3 bytes)
%Program Files%\PPLive\PPTV\data\local\images\404.png (7 bytes)
%Program Files%\PPLive\PPTV\IconBubble.exe (5064 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\downloadbtn_hover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\mini_title_r.bmp (696 bytes)
%Program Files%\PPLive\PPTV\data\vip.swf (4992 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_uparrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_collapsed_treebox2.png (784 bytes)
%Program Files%\Common Files\PPLiveNetwork\player\CoreAVC.2.0.0.0.ax (9608 bytes)
%Program Files%\PPLive\PPTV\skins\default2\speed0.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize2001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\local\images\menu.png (7 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_HD.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\2.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\5\2\2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\fullscreen_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\chrome\push_pop.xml (10 bytes)
%Program Files%\PPLive\PPTV\data\face\em45-¿§·È.png (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em28-¶ñħ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\white_dot.png (130 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_class_bg.png (140 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_pagedown_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch2_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_del_record.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\mini_main_l.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\download_fail.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\close.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_left_top.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mini_bottom_m.bmp (888 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_uparrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_table.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_left.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_down.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\radio_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_new3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\next_hover.png (772 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot.png (1552 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.AMR.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizenotop2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\data\face\em06-Á³ºì.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\stop_hover.png (664 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_bk.bmp (214 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_screenhover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute2_normal.png (556 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hj_expand.png (284 bytes)
%Program Files%\PPLive\PPTV\skins\classic\muteplus_normal.png (556 bytes)
%Program Files%\PPLive\PPTV\skins\classic\dt_selitem_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\hoverinfo.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\hj_unexpand.png (295 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_left_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_min_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_down_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ico-setting.png (1 bytes)
%Program Files%\PPLive\PPTV\data\local\nolink.htm (944 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_downarrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\data\face\em27-Æ¡¾Æ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute2_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_updata_3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_bot_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\chrome\downloadTipDlg.xml (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\vol_bar1.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\max_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_min_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_min_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.WMA.ico (784 bytes)
%Program Files%\Common Files\PPLiveNetwork\player\CoreAVC.ax (6584 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_min_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\newsbg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\user_normal.gif (98 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\FindProcDLL.dll (784 bytes)
%Program Files%\PPLive\PPTV\tab\3\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\check_alarm.bmp (822 bytes)
%Program Files%\PPLive\PPTV\tab\8\3\2.png (3 bytes)
%Program Files%\PPLive\PPTV\pprepair.dll (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_close_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\loading_list.gif (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\infobtn.bmp (918 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\exbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute4_disabled.png (614 bytes)
%Program Files%\PPLive\PPTV\skins\default\ico-setting.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\shift_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_bot_bg_hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_so_bot1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pause_down.png (2 bytes)
%Program Files%\PPLive\PPTV\data\face\em21-ÍÂÉà.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_info_normal.png (480 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\tab\7\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\data\face\em31-Ç®.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute4_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hot_4.bmp (344 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\Loader.exe (2392 bytes)
%Program Files%\PPLive\PPTV\tab\5\3\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_top_bg_left.png (511 bytes)
%Program Files%\PPLive\PPTV\skins\default2\download_pause.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\muteplus_hover.png (680 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_update.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hot_2.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\play_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\ETADPU.DAT (498 bytes)
%Program Files%\PPLive\PPTV\skins\default\color_thumb.png (191 bytes)
%Program Files%\PPLive\PPTV\tab\1\2\2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ex_button_down.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_begin.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\previous_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute4_normal.png (374 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titlebar_r.png (9 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_close_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_checked_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize2001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\avatar_bg_s.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_downarrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\data\face\em02-Ìôü.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\play_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\PPLiveU.exe (15168 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\pause_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\data\cntvppl.html (5 bytes)
%Program Files%\PPLive\PPTV\skins\default\dt_header_normal_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\downloadbtn_disable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\ad_close.bmp (568 bytes)
%Program Files%\PPLive\PPTV\skins\classic\white_dot.png (130 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_info_disabled.png (458 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\chrome\DownloadTaskConflict.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_menu.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic\sort_list_btn.png (817 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\info_arrow.bmp (138 bytes)
%Program Files%\PPLive\PPTV\skins\common\close_down.png (766 bytes)
%Program Files%\PPLive\PPTV\data\face\em30-ÉÁµç.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ico-exit.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hot_4.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\adselector_title.jpg (6 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_epg_bk.bmp (214 bytes)
%Program Files%\PPLive\PPTV\player\CoreAVC.ax (6584 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumb_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_epg_bk.bmp (214 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_hot4.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_Classic2New.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_close_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\data\face\em56-ÖíÍ·.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute4_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\previous_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch2_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizewz1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\radio_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\radio_checked_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\data\local\icon.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\top_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_close_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pause_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\sch_list_class_bg.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mini_bottom_m.bmp (888 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pagedown.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\skin.ini (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_screendisable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_checked_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mini_title_r.bmp (696 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_update.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\des.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\sch_list_class_bg.bmp (2 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.video.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_up.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\classic\fullscreen_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\Controlbar.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ex_button_hover.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_so_bar.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\radio_check_dis.gif (46 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titlebar_bg_r.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\contrast.png (362 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\dt_titlebar_l.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_downarrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\play_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\previous_down.png (2 bytes)
%Program Files%\PPLive\PPTV\chrome\PPGameFail.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\stop_normal.png (505 bytes)
%Program Files%\PPLive\PPTV\skins\default\close_numTip_normal.png (204 bytes)
%Program Files%\PPLive\PPTV\chrome\DownloadTaskConflict2.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\default\shift_hover.png (463 bytes)
%Program Files%\PPLive\PPTV\skins\classic\SliderThumb_down.png (357 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\stop_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hj_expand_new.png (299 bytes)
%Program Files%\PPLive\PPTV\skins\default2\in_bg_right_top.bmp (670 bytes)
%Program Files%\PPLive\PPTV\skins\classic\s_close.png (607 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\GetVersion.dll (5 bytes)
%Program Files%\PPLive\PPTV\tab\2\1\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\dt_selitem_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch2_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize1002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_pagedown.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_left_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_pageup_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\data\face\em44-ã¶×¡.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\4\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize1502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_triangle.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pause_disabled.png (525 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_bg_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mini_bottom_m.bmp (888 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.SWF.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\common\shift2new_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\notop_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\icons\Offline.ico (894 bytes)
%Program Files%\PPLive\PPTV\data\pplive_schedule.html (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_menu.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resizenotop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\mainframe.xml.js (8184 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_table_vod_down.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumbgripper_down.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mode_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_screenhover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resizeratebg.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_top_bg_right.png (463 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\fullscreen_normal.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pagedown_down.bmp (938 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\PPLive\Uninstall PPTV.lnk (565 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_hot3.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\set_bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\classic\PlayProgress3.bmp (716 bytes)
%Program Files%\PPLive\PPTV\skins\default2\play_normal.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\asc.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_header_separator.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\avatar_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizeratebg.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\parsing.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\stop_down.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\product.ini (367 bytes)
%Program Files%\PPLive\PPTV\skins\default\des.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\set_bg_left_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_right.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\check_ok.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\default\dt_titlebar_m.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_close.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute3_down.png (670 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_header_asc.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\exbg_left_top.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\common\btn_close_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\play_disabled.png (522 bytes)
%Program Files%\PPLive\PPTV\skins\common\user_vip.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\volume1.png (494 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\cbox_check_dis.gif (60 bytes)
%Program Files%\PPLive\PPTV\tab\6\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_expand.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\previous_normal.png (467 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ad_close.bmp (568 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize0502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_so_left.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\3\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_numTip.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\shift_hover.png (463 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\notop_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pause_close.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\exbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_class_bg.png (173 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mini_main_r.bmp (176 bytes)
%Program Files%\PPLive\PPTV\data\face\em52-ÊÜÉË.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\radio_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute_disabled.png (533 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\P2PDetail.xml (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_numTip.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\logo.jpg (784 bytes)
%Program Files%\PPLive\PPTV\chrome\education\Classic2NewTip.xml (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\alert.png (2 bytes)
%Program Files%\PPLive\PPTV\tab\6\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_right_top.bmp (702 bytes)
%Program Files%\PPLive\PPTV\skins\classic\expanding.png (353 bytes)
%Program Files%\PPLive\PPTV\skins\black.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\skins\default\max_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\min_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_pageup.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_close.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\s_close.png (607 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mini_bottom_l.bmp (368 bytes)
%Program Files%\PPLive\PPTV\tab\8\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\2.png (1 bytes)
%Program Files%\PPLive\PPTV\ui.dll (30464 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\menu_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\checkbox_checked_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\unfullscreen_down.png (987 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\default2\exbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\logo.jpg (784 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_downarrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\chrome\NavigateStatus.xml (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pageup_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\sort_list_btn.png (817 bytes)
%Program Files%\PPLive\PPTV\skins\default\notop_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\unmute_down.png (793 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\muteplus_normal.png (376 bytes)
%Program Files%\PPLive\PPTV\components\IEProxy.dll (8560 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\time.dll (10 bytes)
%Program Files%\PPLive\PPTV\skins\classic\PlayProgress2.bmp (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\previous_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titlebar_front_l.png (784 bytes)
%Program Files%\PPLive\PPTV\data\face\em25-ÆøÌå.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_left_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_class_bg.png (140 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_screennormal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pdot.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\checkbox_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\classic\dtconfig_3.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\regvip.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\default\mode_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\tab\1\0\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\mini_bottom_l.bmp (140 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize2001.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute_normal.png (307 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_menu_hover.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\radio_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_checked.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pause_normal.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\radio_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\checkstop_down.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\saturation.png (366 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\parsing.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\PlayProgress3.bmp (716 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving.xml (294 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute_normal.png (533 bytes)
%Program Files%\PPLive\PPTV\skins\common\button_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_so_bot1.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\notop_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\sch_list_class_bg.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\dt_titlebar_l.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\set_bg_bot.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\default\strengthenbtn01.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resizemini1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_pageup.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\expanding.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bdclose.png (198 bytes)
%Program Files%\PPLive\PPTV\chrome\tabs.js (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\next_disabled.png (490 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_screendisable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ex_button_down.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\common\btn_close_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\menu_hover.png (369 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mute3_normal.png (579 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_close.png (12088 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute_down.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\hoverinfo.xml.js (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\parsing.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\fullscreen_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_uparrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\max.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\restore.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\dt_titlebar_r.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\1\2\1.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\8\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\previous_down.png (775 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\close.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\menu.png (268 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\unfullscreen_disabled.png (336 bytes)
%Program Files%\PPLive\PPTV\skins\default2\button_down.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic\info_arrow.bmp (138 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_class_bg.png (140 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\skin.ini (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\dtconfig_3.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\close_down.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\stream_spot.bmp (104 bytes)
%Program Files%\PPLive\PPTV\chrome\ChannelNumTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\unmute_hover.png (792 bytes)
%Program Files%\PPLive\PPTV\skins\default2\in_bg_right.bmp (174 bytes)
%Program Files%\PPLive\PPTV\chrome\DownloadCodec.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\playerinfo.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\shift2old_down.png (618 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_back2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute_hover.png (647 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\alert.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\next_normal.png (432 bytes)
%Program Files%\PPLive\PPTV\skins\default2\saturation.png (366 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize1501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute4_down.png (668 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\shift_normal.png (510 bytes)
%Program Files%\PPLive\PPTV\skins\classic\loading.gif (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\next_disabled.png (405 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgressThumb_hover.png (288 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_close_down.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hot_4.bmp (344 bytes)
%Program Files%\PPLive\PPTV\data\face\em09-Ë®µÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_close_hover.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\cbox_check.gif (62 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_download_playing.png (2 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.FLV.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\radio_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\fullscreen_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\top_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\player\HTTP_ASF_SOURCE.ax (17848 bytes)
%Program Files%\PPLive\PPTV\skins\classic\top_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\tab\8\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_header_des.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_checked_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\hot_2.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_right.bmp (134 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\data\face\em47-ºÚÈË.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\menu.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\next_normal.png (470 bytes)
%Program Files%\PPLive\PPTV\skins\classic\menu_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\attemptclose.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\frame_bottom_l.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_downarrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\shift2new_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\alert.png (2 bytes)
%Program Files%\PPLive\PPTV\chrome\NewDownloadTask.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_epg_close.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumb_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_close_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\close_hover.png (769 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize_gripper.png (2 bytes)
%Program Files%\PPLive\PPTV\components\filepick.dll (3312 bytes)
%Program Files%\PPLive\PPTV\tab\4\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_up.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_left.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_bot.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pageup_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pause_close.bmp (2 bytes)
%Program Files%\PPLive\PPTV\tab\3\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\checkbox_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrol2.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_VIP.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_sch.png (890 bytes)
%Program Files%\PPLive\PPTV\IP (7 bytes)
%Program Files%\Common Files\PPLiveNetwork\player\VSFilter.dll (33633 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_left.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch_vip.png (443 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\arrow-hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\playerinfo.bmp (3 bytes)
%Program Files%\PPLive\PPTV\tab\4\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch_vip.png (443 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_top.bmp (162 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\close_numTip_normal.png (204 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mode.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_thumb_down.png (287 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\radio_checked_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\data\face\em10-µ¹Á¢.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\fullscreen_disabled.png (344 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\dt_titlebar_r.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\nav_status_l.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\stop_disabled.png (333 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_updata_2.gif (1856 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_cate_hot.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_back3.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_tab_uncheck.png (6 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumb_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pause_hover.png (943 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\stream_bg.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute2_normal.png (322 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\brightness.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\shift_disabled.png (471 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\shift_hover.png (641 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\checkbox_checked.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default2\previous_normal.png (443 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hot_0.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pushplay.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\check_ok.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\default2\ico-setting.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgress2.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow.png (660 bytes)
%Program Files%\PPLive\PPTV\skins\default\min_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\next_disabled.png (490 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hj_unexpand_new.png (267 bytes)
%Program Files%\PPLive\PPTV\data\face\em33-Ì¾Æø.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\newsbg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\dt_header_normal_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\config.xml (10 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titletab_on_down.png (844 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_screennormal.bmp (2 bytes)
%Documents and Settings%\All Users\Desktop\PPTV Online Video.lnk (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\player\HTTP_ASF_SOURCE.ax (17848 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\exbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_menu_down.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic\exbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute4_hover.png (671 bytes)
%Program Files%\PPLive\PPTV\chrome\push_pop2.xml (13 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_livebtn_down.png (757 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\menu_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_livebtn_down.png (757 bytes)
%Program Files%\PPLive\PPTV\skins\default\pushplay.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_pagedown_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resizemini1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_hot4.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_bot.bmp (728 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\exbg_left.bmp (1 bytes)
%Program Files%\PPLive\PPTV\tab\7\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pause_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\1.png (1 bytes)
%Program Files%\PPLive\PPTV\EROTSER.dat (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\unfullscreen_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\downloading.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\downloadbtn_normal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\checkbox_checked_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_expanded_treebox2.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_close_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_top1.bmp (694 bytes)
%Program Files%\PPLive\PPTV\tab\4\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\tab\2\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\ex_button_hover.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch2_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resize0502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\arrow-hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\tab\2\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\close_hover.png (769 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\play.png (543 bytes)
%Program Files%\PPLive\PPTV\skins\default2\gbg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\exbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titlebar_bg_l.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_menu_down.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_epg_close.bmp (886 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_top1.bmp (694 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic\arrow-hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\PlayProgress1.bmp (440 bytes)
%Program Files%\PPLive\PPTV\skins\default2\white_dot.png (130 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumbgripper_down.bmp (67 bytes)
%Program Files%\PPLive\PPTV\tab\8\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hj_expand_new.png (299 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ex_button.bmp (4 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrol.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\exbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\exbg_left_bot.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\resizemini2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\frame_l.png (165 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_menu_down.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\notop.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\passport_menu_hover.gif (13 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_pagedown_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\tab\8\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resizeratebg.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\PlayProgressThumb_hover.png (288 bytes)
%Program Files%\PPLive\PPTV\data\face\em08-ÐÄ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_downright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_pageup.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize1501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_top.bmp (918 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\PPInstallLog.dll (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\fullscreen_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\exbg_left_bot.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\min_down.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\PlayProgressThumb_normal.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\classic\download_fail.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\pdot.png (784 bytes)
%Program Files%\PPLive\PPTV\tab\8\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\tab\1\3\1.png (1 bytes)
%Program Files%\PPLive\PPTV\data\face\em13-¾Æ±­.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\max.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_top_bg_bar.png (244 bytes)
%Program Files%\PPLive\PPTV\skins\default2\top.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute2_disabled.png (556 bytes)
%Program Files%\PPLive\PPTV\skins\default2\asc.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\button_down.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\checkstop_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_class_bg.png (173 bytes)
%Program Files%\PPLive\PPTV\skins\classic\logo.jpg (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\exbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\speed2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mini_title_r.bmp (696 bytes)
%Program Files%\PPLive\PPTV\skins\common\mini_title_m.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resizemini2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\shift_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\arrow-default.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close.bmp (822 bytes)
%Program Files%\PPLive\PPTV\icons\2_4.ico (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize1502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_checked_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\icons\ikan-p.ico (4992 bytes)
%Program Files%\PPLive\PPTV\skins\classic\check_alarm.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pagedown.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_expanded_treebox2.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\play_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\2\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\data\local\cjs\err.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\play_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\restore_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_search.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\pause_disabled.png (813 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\checkbox_checked.bmp (576 bytes)
%Program Files%\PPLive\PPTV\chrome\education\New2ClassicTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\download_wait.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_so_bar.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\unmute_disabled.png (792 bytes)
%Program Files%\PPLive\PPTV\data\face\em01-΢Ц.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\resizenotop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\skin.ini (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_Classic2New.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\groupbox.png (784 bytes)
%Program Files%\PPLive\PPTV\chrome\signin2.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hot_2.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_uparrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close_down.bmp (822 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_upleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\exbg_left_top.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\classic\unfullscreen_hover.png (923 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\max.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_upright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\default\shift_normal.png (307 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_close.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hj_unexpand.png (295 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_updata_2.gif (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\small_frame_bottom.png (1 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.WMV.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\user_normal.gif (98 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_pause.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\dt_tab_uncheck.png (2 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.MPG.ico (784 bytes)
%Program Files%\PPLive\PPTV\data\face\em32-Æà²Ò.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumb_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\play_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\cbox_check_sel.gif (832 bytes)
%Program Files%\PPLive\PPTV\skins\default\passport_bot_bg_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumbgripper.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\default2\SliderThumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\DataRateChangeWnd.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pagedown_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titlebar_front_r.png (9 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bg_right.bmp (134 bytes)
%Program Files%\PPLive\PPTV\chrome\DownloadPPGame.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrol.xml (7 bytes)
%Program Files%\PPLive\PPTV\skins\classic\groupbox.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_updata_3.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_table_vod_down.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_close_1.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumbgripper_down.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\groupbox.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\checkbox.bmp (576 bytes)
%Program Files%\PPLive\PPTV\data\face\em20-ÞÏÞÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hot_2.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default2\arrow-hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\set_bg_right_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_downarrow_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\SliderThumb_hover.png (344 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\checkbox_checked_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute_down.png (648 bytes)
%Program Files%\PPLive\PPTV\skins\default\info_arrow.bmp (138 bytes)
%Program Files%\PPLive\PPTV\skins\default2\task_noplay.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\loading.gif (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hot_5.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_item_gap.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\live\mir.dll (33747 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\radio_checked_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\alert.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_checked_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\pause_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\PPLive32by32.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_bot_hover.gif (1856 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute3_normal.png (372 bytes)
%Program Files%\PPLive\PPTV\components\PPOptions.dll (19096 bytes)
%Program Files%\PPLive\PPTV\skins\default2\bdclose.png (198 bytes)
%Program Files%\PPLive\PPTV\skins\default\previous_hover.png (771 bytes)
%Program Files%\PPLive\PPTV\skins\classic\hj_expand.png (284 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\speed3.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\ie.png (895 bytes)
%Program Files%\PPLive\PPTV\chrome\education\BDSwitch.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_cate_hot.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_close_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\chrome\openurl.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\radio_checked.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\tomain_hover.png (475 bytes)
%Program Files%\PPLive\PPTV\skins\default2\speed2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\pause_disabled.png (376 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_downarrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pagedown_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\data\face\em49-·ßÅ­.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\close.bmp (1 bytes)
%Program Files%\PPLive\PPTV\PPVodDownload.dll (33263 bytes)
%Program Files%\PPLive\PPTV\skins\classic\gbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_cate_new.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hot_5.bmp (344 bytes)
%Program Files%\PPLive\PPTV\skins\classic\dt_titlebar_r.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_pageup_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bright.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_fav_down.png (757 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\checkbox_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\radio_checked_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\strengthenbtn02.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgress1.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\hj_unexpand_new.png (267 bytes)
%Program Files%\PPLive\PPTV\skins\default2\restore_down.png (660 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_top1.bmp (694 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\exbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\classic\set_bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\skins\classic\close_numTip_hover.png (320 bytes)
%Program Files%\PPLive\PPTV\data\NoCache.List (683 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\PPLive\PPTV .lnk (753 bytes)
%Program Files%\PPLive\PPTV\chrome\UserSkipAds.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\button.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\checkstop_down.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\fullscreen_disabled.png (761 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_upright.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\classic\brightness.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\sch_list_class_bg.bmp (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\player\OPlayer.ocx (34186 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\min_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\in_bg_right_bot.bmp (670 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute_disabled.png (647 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\PlayProgressThumb_down.png (278 bytes)
%Program Files%\PPLive\PPTV\data\face\em41-ϲÔÃ.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mode_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\local\images\err.css (4 bytes)
%Program Files%\PPLive\PPTV\icons\PPTV.MKV.ico (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\close_numTip_normal.png (204 bytes)
%Program Files%\PPLive\PPTV\skins\default2\edu2_up_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\logo.swf (1552 bytes)
%Program Files%\PPLive\PPTV\player\CoreAVC.2.0.0.0.ax (9608 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\previous_hover.png (771 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_top_bg_bar.png (229 bytes)
%Program Files%\PPLive\PPTV\skins\default\fullscreen_hover.png (657 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_down.bmp (120 bytes)
%Program Files%\PPLive\PPTV\chrome\miniplayer.xml (8 bytes)
%Program Files%\PPLive\PPTV\skins\classic\shift_normal.png (510 bytes)
%Program Files%\PPLive\PPTV\chrome\adselector.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizemini2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\previous_normal.png (614 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_downarrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_min_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\stream_bg.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_screennormal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\unmute_disabled.png (653 bytes)
%Program Files%\PPLive\PPTV\chrome\mainframe.xml (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize1002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\pop_close.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\PlayProgressThumb_hover.png (278 bytes)
%Program Files%\PPLive\PPTV\skins\classic\previous_disabled.png (489 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\previous_disabled.png (444 bytes)
%Program Files%\PPLive\PPTV\data\face\em23-ÉúÆø.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\3\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\user_vip.gif (169 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\radio_checked_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\radio.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\top_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mode_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\miniclose.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\unfullscreen_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\PlayProgress1.bmp (13 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\radio_checked.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\ex_button.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\task_play.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute3_normal.png (333 bytes)
%Program Files%\PPLive\PPTV\data\face\em22-ÐÄËé.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_bg_top.bmp (476 bytes)
%Program Files%\PPLive\PPTV\greprefs\all.js (9 bytes)
%Program Files%\PPLive\PPTV\skins\default2\max.png (288 bytes)
%Program Files%\PPLive\PPTV\skins\classic\2.png (1 bytes)
%Program Files%\PPLive\PPTV\chrome\VIPDownloadHDLogin.xml (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_bg_hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\common\small_frame_l.png (995 bytes)
%Program Files%\PPLive\PPTV\skins\default2\nav_status_r.bmp (344 bytes)
%Program Files%\PPLive\PPTV\tab\1\1\2.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\InstallLog.txt (14482 bytes)
%Program Files%\PPLive\PPTV\skins\default2\in_bg_top.bmp (150 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_fav_down.png (757 bytes)
%Program Files%\PPLive\PPTV\ipcfg.ini (343 bytes)
%Program Files%\PPLive\PPTV\skins\default\pop_close.png (784 bytes)
%Program Files%\PPLive\PPTV\components\cmdline.dll (1856 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch2_normal.png (761 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ex_button.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\muteplus_normal.png (326 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_left.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_bot.bmp (728 bytes)
%Program Files%\PPLive\PPTV\tab\3\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\next_normal.png (624 bytes)
%Program Files%\PPLive\PPTV\skins\classic\min_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\speed0.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\5\1\1.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titletab.png (1 bytes)
%Program Files%\PPLive\PPTV\data\SpecifyPath.List (25 bytes)
%Program Files%\PPLive\PPTV\skins\default2\stream_bg.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_upleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\radio_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\close_hover.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\previous_disabled.png (418 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_down_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\download_pause.png (1 bytes)
%Program Files%\PPLive\PPTV\data\local\page.html (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\SliderThumb_normal.png (344 bytes)
%Program Files%\PPLive\PPTV\skins\default\stream_bg.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize1001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\vol_bar2.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\in_bg_left.bmp (174 bytes)
%Program Files%\PPLive\PPTV\data\local\images\err_2.jpg (9 bytes)
%Program Files%\PPLive\PPTV\skins\default2\top_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_min_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\close_numTip_normal.png (204 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mini_title_m.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute3_normal.png (372 bytes)
%Program Files%\PPLive\PPTV\skins\common\mini_main_r.bmp (176 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\strengthenbtn01.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\des.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\speed4.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_uparrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_Classic2New.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\resizewz2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumbgripper.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_cate_new.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\mini_bottom_r.bmp (368 bytes)
%Program Files%\PPLive\PPTV\tab\1\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize2001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize1501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\button.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\next_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_close_hover.bmp (822 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrolmini.xml (6 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize1002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_min_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_epg_back3.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\exbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\components\NCList.dll (29256 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titletab_hover.png (6 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_bot_bg_hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\shift_down.png (462 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Startup\PPTV.lnk (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\btn_min_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_uparrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\radio_checked_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\edu2_up_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\button_hover.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize2002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu\arrow_right_disabled.gif (59 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize1502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\tab_background.png (133 bytes)
%Program Files%\PPLive\PPTV\data\face\em42-Ť¶¯.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_checked_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\PlayProgressThumb_down.png (297 bytes)
%Program Files%\PPLive\PPTV\skins\classic\button_hover.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_collapse.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_hover.gif (1856 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mini_main_l.bmp (176 bytes)
%Program Files%\PPLive\PPTV\data\face\em07-´óÊå.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\checkbox_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\speed2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\fullscreen_disabled.png (761 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_down_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bg_left_top.bmp (6 bytes)
%Program Files%\PPLive\PPTV\skins\default\regvip.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\button_hover.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_right.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\classic\avatar_bg_s.png (784 bytes)
%Program Files%\PPLive\PPTV\chrome\PPGameIsSetup.xml (3 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\checkbox_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute2_down.png (661 bytes)
%Program Files%\PPLive\PPTV\data\face\em35-»Ò.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\play_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\tab\2\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\checkstop_hover.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\unfullscreen_disabled.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\sort_list_btn.png (667 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute4_hover.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\peer.dll (51087 bytes)
%Program Files%\PPLive\PPTV\skins\default\ie.png (895 bytes)
%Program Files%\PPLive\PPTV\skins\default\checkstop_down.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_hot4.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute_disabled.png (647 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\saturation.png (366 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mode_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_pagedown.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\btn_screenhover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\gbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resizeback.bmp (146 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\btn_close_2.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\sch_list_class_bg.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\PlayProgress1.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_pageup_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize0502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\ch_down.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\Send_Log_Kernel_Module.dll (8560 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common\radio_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ch_vip.png (443 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mode_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_check.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\list_table_vod.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\play_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\mute2_down.png (661 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_pageup_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\vol_bar1.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic\max.bmp (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\resource\ikan-p.ico (4992 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\classic\next_down.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_selitem_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_back.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\unfullscreen_disabled.png (331 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_updata_2.gif (1856 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\radio_down.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\volume_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\close.png (311 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_bg_down.png (1856 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_downarrow_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_epg_back.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mute4_hover.png (961 bytes)
%Documents and Settings%\All Users\Desktop\PPTV .lnk (741 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_livebtn.png (890 bytes)
%Program Files%\PPLive\PPTV\skins\default\edu2_right.bmp (116 bytes)
%Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumbgripper_down.bmp (488 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_up_triangle.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\list_HD.png (544 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\expanding.png (353 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b.xml (293 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\close_hover.bmp (784 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_uparrow_down.bmp (938 bytes)
%Program Files%\Common Files\PPLiveNetwork\player\MP4Splitter.ax (17848 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small\volume1_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resizetop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\UPDATE\upgrade_title2.bmp (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\resize0501.bmp (2 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Internet Explorer\Quick Launch\PPTV .lnk (759 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\default\pause_close.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\dt_selitem_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\gbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\skins\classic\bg_numTip.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\titletab_on.png (844 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_uparrow_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default2\skin.ini (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\download_wait.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_header_select_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\bg_Classic2New.png (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\resizetop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\crossdomain.xml (121 bytes)
%Program Files%\PPLive\PPTV\skins\classic\strengthenbtn01.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\gbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\menu_down.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\vol_bar2.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pagedown_disabled.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\common\scrollbar_uparrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\default\button_hover.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_cate_new.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\stream_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\data\pushvideo.swf (15 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_down.bmp (120 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\newsbg.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\dt_header_normal_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\UPDATE\upgrade_bg3.bmp (5064 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\bg_left.bmp (134 bytes)
%Program Files%\PPLive\PPTV\skins\default2\hj_unexpand_new.png (267 bytes)
%Program Files%\PPLive\PPTV\skins\default2\adselector_title.jpg (6 bytes)
%Program Files%\Common Files\PPLiveNetwork\kernel\PPHookShell.dll (9320 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mini_title_m.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\updatetipclose.bmp (3 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resize1001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_del_record.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic\notop.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_downarrow.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\edu2_downleft.bmp (104 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\ch2_normal.png (761 bytes)
%Program Files%\PPLive\PPTV\skins\default2\set_bg_right_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\data\face\em05-Ë§Æø.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\fullscreen_disabled.png (459 bytes)
%Program Files%\PPLive\PPTV\skins\default\resize1502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close_down.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_pageup_down.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\bright.bmp (15 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\classic\ex_button_hover.bmp (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\mini_title_r.bmp (696 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resizenotop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\s_close_down.png (473 bytes)
%Program Files%\PPLive\PPTV\chrome\signin2.xml (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\set_bg_right_bot.bmp (70 bytes)
%Program Files%\PPLive\PPTV\skins\default\common\radio.png (3 bytes)
%Program Files%\PPLive\PPTV\chrome\About.xml (5 bytes)
%Program Files%\PPLive\PPTV\skins\common\common\checkbox_checked_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\common\mini_bottom_m.bmp (280 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default\ico-exit.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\vol_bar2.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_progress_m.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\default2\PlayProgress2.bmp (440 bytes)
%Program Files%\PPLive\PPTV\skins\default\stop_normal.png (337 bytes)
%Program Files%\PPLive\PPTV\skins\default\ch_disabled.png (475 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\hj_expand.png (284 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\list_del_record.png (2 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgressThumb_normal.png (297 bytes)
%Program Files%\PPLive\PPTV\skins\default2\loading.gif (3 bytes)
%Program Files%\PPLive\PPTV\tab\6\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default\shift_disabled.png (286 bytes)
%Program Files%\PPLive\PPTV\skins\classic\passport_collapse.png (1552 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\downloadbtn_disable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\dt_header_normal_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\data\pplive_schedule_buttons.gif (2 bytes)
%Program Files%\PPLive\PPTV\skins\common\btn_min_3.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_close.png (12088 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\resizetop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\skins\default2\volume_bar_2.png (1 bytes)
%Program Files%\PPLive\PPTV\skins\classic\tab_background.png (133 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\user_vip.gif (169 bytes)
%Program Files%\PPLive\PPTV\restore.dll (5064 bytes)
%Program Files%\PPLive\PPTV\skins\default\logo.jpg (784 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\mute2_normal.png (362 bytes)
%Program Files%\PPLive\PPTV\skins\default\btn_screennormal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\resize0502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\vol_bar2.bmp (5 bytes)
%Program Files%\PPLive\PPTV\skins\classic\list_collapsed_treebox1.png (784 bytes)
%Program Files%\PPLive\PPTV\skins\default\list_fav.png (885 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\regvip.bmp (8 bytes)
%Program Files%\PPLive\PPTV\skins\classic\pause_hover.png (943 bytes)
%Program Files%\PPLive\PPTV\skins\classic\btn_screennormal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\skins\default2\scrollbar_pageup_hover.bmp (938 bytes)
%Program Files%\PPLive\PPTV\skins\classic\shift_disabled.png (471 bytes)
%Program Files%\PPLive\PPTV\skins\default\resizemini1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\skins\default\max_hover.bmp (1 bytes)
%Program Files%\PPLive\PPTV\chrome\education\NewDownload.xml (2 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\pplugin2.dll (9320 bytes)
%Program Files%\PPLive\PPTV\skins\default2\download_wait.png (3 bytes)
%Program Files%\PPLive\PPTV\skins\default2\mute2_disabled.png (321 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\InetLoad.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\gtapi_signed.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\Favorites (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\PPInstallLog.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\FindProcDLL.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\version.ini (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\PPBindDAC.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\pnsis.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\CommonFuncDll.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\GetCommentsInfoDll.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\cknsis.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\GetVersion.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\time.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\BindDLL.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx6.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\Loader.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\IconCache.db (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\bind_en-us.ini (0 bytes)

The process PPLiveU.exe:2540 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\PPTV_Update.ini (2202 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\peer.dll (717377 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\UPDB.tmp (380 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\UPDB.tmp (0 bytes)

The process PPAP.exe:3584 makes changes in the file system.
The Trojan deletes the following file(s):

%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\TrustUpload\2016052402000537761.dat (0 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\TrustUpload\2016052402000637762.dat (0 bytes)

The process PPAP.exe:3776 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM (4 bytes)
%Program Files%\PPLive\PPTV\UPDATE (4 bytes)
%Program Files%\PPLive\PPTV\chrome\education (4 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving\common (4 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Internet Explorer\Quick Launch (4 bytes)
%Program Files%\PPLive\PPTV\chrome\playcontrol (4 bytes)
%Program Files%\PPLive\PPTV\data\face (28 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\resconfig\ResourceInfo.dat.tmp (2508 bytes)
%Documents and Settings%\%current user%\Application Data\PPLive\PPTV\xml\control.xml (11 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\resconfig\ppvaconfig.ini (1600 bytes)
%Program Files%\PPLive\PPTV\icons (4 bytes)
%Program Files%\PPLive\PPTV\skins\default2\small (4 bytes)
%Documents and Settings%\All Users\APPLICATION DATA (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b (673 bytes)
%Program Files%\PPLive\PPTV\skins\default2 (673 bytes)
%Program Files%\PPLive\PPTV\skins\common\menu (4 bytes)
%Program Files%\PPLive\PPTV\skins\default\common (4 bytes)
%Program Files%\PPLive\PPTV\player (4 bytes)
%Documents and Settings%\All Users\Desktop (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\index.dat (2900 bytes)
%Program Files%\PPLive\PPTV\skins\default (673 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\MSHist012016052420160525\index.dat (388 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\resconfig\pptl (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\webcache (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wireshark.txt (533 bytes)
C:\ (4 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\Config.ini (68 bytes)
%Program Files%\PPLive\PPTV\data (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\getcitycode[1] (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp (4 bytes)
%Program Files%\PPLive\PPTV (4 bytes)
%Program Files%\PPLive\PPTV\components (4 bytes)
%Documents and Settings%\All Users (4 bytes)
%Program Files%\PPLive\PPTV\data\local\images (4 bytes)
C:\FavoriteVideo\InvisibleFolder\peer_2.5.0.8761.dll.tpp (97 bytes)
%Program Files%\PPLive\PPTV\skins\common\small (4 bytes)
%WinDir% (96 bytes)
%Documents and Settings%\All Users\Documents\My Music (4 bytes)
C:\$Directory (576 bytes)
%Program Files%\PPLive\PPTV\skins\classic_b\common (4 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content (4 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\MngConfig.s3db (295 bytes)
C:\FavoriteVideo\InvisibleFolder\externtab(3.2.1.1).zip.tpp (536 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\TrustUpload\2016052402000637762.dat (263 bytes)
%System% (1384 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\Converter.ini (66 bytes)
%Program Files%\PPLive\PPTV\chrome (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J (4 bytes)
%Program Files%\PPLive\PPTV\skins\classic\common (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pptv[1] (14780 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData (4 bytes)
%Program Files%\PPLive\PPTV\tab (4 bytes)
%Documents and Settings%\All Users\Documents (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[1].xml (1716 bytes)
%Program Files%\PPLive\PPTV\skins\3xgiving (673 bytes)
%Documents and Settings%\%current user%\My Documents (4 bytes)
%Documents and Settings%\%current user%\APPLICATION DATA (4 bytes)
%System%\config (100 bytes)
%Program Files%\PPLive\PPTV\skins\common (24 bytes)
C:\FavoriteVideo\readme.txt (543 bytes)
%Program Files%\PPLive\PPTV\data\local (4 bytes)
%Documents and Settings%\All Users\Start Menu (4 bytes)
%Program Files%\PPLive\PPTV\skins\common\common (4 bytes)
C:\FavoriteVideo\InvisibleFolder\pplss2.swf.tpp (1074 bytes)
%WinDir%\Prefetch (672 bytes)
%Documents and Settings%\%current user% (8 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\index.dat (484 bytes)
%WinDir%\Temp\Perflib_Perfdata_668.dat (4 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\pluginad\AdConfig.ini (8281 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp (4 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\MngConfig.s3db-journal (4998 bytes)
%Documents and Settings%\%current user%\Cookies (384 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\TrustUpload\2016052402000537761.dat (195 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (4 bytes)
%Documents and Settings%\All Users\Start Menu\Programs (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pptv[1].htm (19245 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[2].xml (2645 bytes)
%Program Files%\PPLive\PPTV\skins (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data (4 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites (4 bytes)
%Documents and Settings%\%current user%\LOCAL SETTINGS (4 bytes)

The Trojan deletes the following file(s):

C:\FavoriteVideo\fafsfsfsfsfsa.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pptv[1] (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[1].xml (0 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\MngConfig.s3db-journal (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\getcitycode[1] (0 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\Core\MngConfig.s3db (0 bytes)

The process find.exe:2192 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%System%\find.txt (27 bytes)

The process PPLive.exe:3560 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\3\1.png (3 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5 (164 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\catalog[1].xml (2590 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\1\2.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\UPD9.tmp (380 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\3\1.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\17072340777[1].jpg (1080 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\getcitycode[1] (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\15264463677[1].jpg (50 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pptv[1].txt (1648 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\1\1.png (4 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\1\1.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\pptv[1] (17386 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\3\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\2\2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\imgLogo[1].gif (295 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bg_bottom[1].png (335 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\0\1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\0\1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\3\1.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\13433875515[1].jpg (2857 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\2\1.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bg_portal[1].jpg (98 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\1\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\2\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\1\1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\0\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\0\1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\0\1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\2\1.png (1 bytes)
%Documents and Settings%\%current user%\Application Data\PPLive\PPTV\prefs.js (202 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\0\1.png (3 bytes)
%Documents and Settings%\%current user%\Application Data\PPLive\PPTV\xml\control.xml (11 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (6268 bytes)
%Documents and Settings%\%current user%\Application Data\PPLive\PPTV\2.7.3.0009\compreg.dat.tmp (41776 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\0\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\3\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\screensaver\pplss1.swf (37 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\beacon[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\logo[1].swf (6844 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\312369caa76e476ecc8f28afeaabe1be (2531 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites\watchlog.s3db-journal (4760 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\0\1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\0\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\3\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\1\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\2\2.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\common2[1].js (11 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\1\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\2\2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\webcache\3\312369caa76e476ecc8f28afeaabe1be (21913 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites\watchlog.s3db (1017 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites\Common.s3db-journal (512 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\3\1.png (3 bytes)
%Documents and Settings%\%current user%\Application Data\PPLive\PPTV\2.7.3.0009\xpti.dat.tmp (1119 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\1\2.png (2 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[1].txt (207 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\3\1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\3\1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\3\2.png (3 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4 (37 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\2\1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\2\1.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\09585262495[1].jpg (1076 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\12345[1].htm (526 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\2\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\3\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\2\1.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\10110990986[1].jpg (98 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\1\1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\3\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\0\1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\2\2.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\19041266534[1].jpg (1076 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\1\1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\3\2.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[3].css (22 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\1\2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\1\1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\0\2.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\catalog[2].xml (196 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\2\2.png (1 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5 (933 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ppvadownloadbyurl_35601[1] (16777 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\3\1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\2\1.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[1].xml (660 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\tab2.xml (879 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\UPDA.tmp (380 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\2\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\0\1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\2\1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\2\1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\1\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\1\1.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\logo[1].jpg (4302 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\tab.xml (516 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\webcache\3\312369caa76e476ecc8f28afeaabe1be.type (1 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4 (240 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\3\1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\2\1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\1\2.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\img_fill[1].gif (43 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\0\2.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\common2[1].js (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\3\2.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[2].xml (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sta[1] (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\list\catalog-1-0.xml (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\download[1].png (415 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\2\1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\3\2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\0\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\3\2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[2].css (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\tab.ini (38 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\1\2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\0\2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites\Common.s3db (4369 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\img[1].gif (1036 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\13470667633[1].jpg (98 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\1\1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\3\1.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sta[2] (5 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\1\1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\webcache\index.dat (76 bytes)
%Documents and Settings%\%current user%\Application Data\PPLive\PPTV\xml\pop.xml (8281 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\0\1.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ppvadownloadbyurl[1] (33537 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\0\1.png (4 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\1\1.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\10144547146[1].jpg (1925 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\2\2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\2\2.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\NewPopup[1].Xml (146068 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pptv[2].txt (1138 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\18092704918[1].jpg (98 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\menu[1].png (50 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\0\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\3\1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\tab3.2.1.1.zip (1281 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\1\2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\0\2.png (3 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[2].txt (370 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\0\2.png (2 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Application Data\PPLive\PPTV\2.7.3.0009\xpti.dat (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pptv[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\catalog[1].xml (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\common2[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[2].xml (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[1].xml (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[2].css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\UPD9.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sta[1] (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pptv[1].htm (0 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\tab3.2.1.1.zip (0 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites\watchlog.s3db-journal (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\UPDA.tmp (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pptv[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[1].txt (0 bytes)
%Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites\Common.s3db-journal (0 bytes)

The process forqd340.exe:1076 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\PPTV(pplive)_forqd340[1].exe (2596152 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\PPTV(pplive)_forqd340.exe (86230 bytes)

Registry activity

The process IconBubble.exe:3608 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "48 13 CA 13 22 AD 98 C5 EB BB 52 72 9F D2 CC 5B"

[HKCR\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win32]
"(Default)" = "%System%\oleacc.dll"

The process attrib.exe:2136 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6A 30 A8 8B 1E 6C 6C 10 6A 8C 03 CE 59 3C 64 A5"

The process attrib.exe:2144 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "02 E3 31 AE 32 E7 71 C0 8B 86 18 AA 78 0B 0B BB"

The process %original file name%.exe:704 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\ODUJ\DefaultIcon]
"(Default)" = "%Program Files%\Internet Explorer\IEXPLORE.EXE"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 21 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"GlobalUserOffline" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E5 7C 99 4E 67 4C 23 EB E2 A5 11 37 EC 98 54 B8"

[HKCR\.HIE]
"(Default)" = "ODUJ"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCR\ODUJ\shell\open\command]
"(Default)" = "explorer %Program Files%\Microsoft %C%8o›Ž Emulator\Internat Explorer"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process tasklist.exe:2168 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "EB 08 5D 8C B7 B1 72 50 36 C8 5C 4B 0B 7B 9E 6F"

The process PPTV(pplive)_forqd340.exe:2912 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\ppl\DefaultIcon]
"(Default)" = "%Program Files%\PPLive\PPTV\PPLive.exe"

[HKCR\pptv\Shell\Open\Command]
"(Default)" = "%Program Files%\PPLive\PPTV\PPLive.exe %1"

[HKCR\*\shellex\ContextMenuHandlers\{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}]
"(Default)" = "{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion]
"ppdiskid" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{95B3F550-91C4-4627-BCC4-521288C52977}]
"HotIcon" = "%Program Files%\PPLive\PPTV\icons\PPLive.ico"

[HKCR\CLSID\{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}\ProgID]
"(Default)" = ""

[HKCR\TypeLib\{C5A164AA-482B-4322-842D-9C9DD3852F8E}\1.0\0\win32]
"(Default)" = "%System%\kindling.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCR\Interface\{27B91D23-7428-46F4-AC61-E1869F374072}\TypeLib]
"(Default)" = "{C5A164AA-482B-4322-842D-9C9DD3852F8E}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPLive]
"DisplayName" = "PPTV V2.7.3.0009"

[HKCR\pptv]
"URL Protocol" = ""

[HKCU\Software\PPLive\Config\PlaySet]
"prefervr" = "4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPLive]
"Publisher" = "PPLive Corporation"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 26 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{95B3F550-91C4-4627-BCC4-521288C52977}]
"MenuText" = "PPLive"

[HKCR\Interface\{27B91D23-7428-46F4-AC61-E1869F374072}]
"(Default)" = "IPPTVFire"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Security Center\BlueShield]
"{db8d1a66-fb49-4e92-98e9-e51efe4f2372}" = "BC 65 DE 05 0B F3 00 7D 47 95 5A F1 AE 60 3F B2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsd8.tmp\BindDLL.dll,"

[HKCR\pptv]
"(Default)" = "URL:synacast Protocol"

[HKCR\ppl]
"URL Protocol" = ""

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKCU\Software\PPLive\Config\Layout]
"playwidth" = "590"

[HKCR\Interface\{27B91D23-7428-46F4-AC61-E1869F374072}\TypeLib]
"Version" = "1.0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKCR\ppl]
"(Default)" = "URL:synacast Protocol"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCR\TypeLib\{C5A164AA-482B-4322-842D-9C9DD3852F8E}\1.0]
"(Default)" = "ShellFire 1.0 Type Library"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion]
"PPID" = "17DBEBA6-3F2D-450C-9C8E-1D60002FE6B6"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{95B3F550-91C4-4627-BCC4-521288C52977}]
"Icon" = "%Program Files%\PPLive\PPTV\icons\PPLive.ico"

[HKCR\Synacast]
"(Default)" = "URL:synacast Protocol"

[HKCR\TypeLib\{C5A164AA-482B-4322-842D-9C9DD3852F8E}\1.0\FLAGS]
"(Default)" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"

[HKLM\SOFTWARE\CoreCodec\CoreAVC Pro]
"User" = ""

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PPLive.exe]
"(Default)" = "%Program Files%\PPLive\PPTV\PPLive.exe"

[HKCR\TypeLib\{C5A164AA-482B-4322-842D-9C9DD3852F8E}\1.0\HELPDIR]
"(Default)" = "%System%"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PPLive.exe]
"Path" = "%Program Files%\PPLive\PPTV"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPLive]
"DisplayVersion" = "2.7.3"

[HKLM\SOFTWARE\CoreCodec\CoreAVC Pro]
"serial" = "IQIKB-6F7KD-CORE-IXRJW-IGUHC"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{95B3F550-91C4-4627-BCC4-521288C52977}]
"exec" = "%Program Files%\PPLive\PPTV\PPLive.exe"

[HKCR\Synacast]
"Customer" = "forqd340"

[HKCR\ppl]
"Version" = "2.7.3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCR\Synacast\DefaultIcon]
"(Default)" = "%Program Files%\PPLive\PPTV\PPLive.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPLive]
"DisplayIcon" = "%Program Files%\PPLive\PPTV\PPLive.exe"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{95B3F550-91C4-4627-BCC4-521288C52977}]
"Default Visible" = "Yes"

[HKCR\pptv]
"Version" = "2.7.3"

[HKCU\Software\PPLive\Config\PlaySet]
"avcdecoder" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCR\CLSID\{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PPTV.exe]
"(Default)" = "%Program Files%\PPLive\PPTV\PPLive.exe"

[HKCR\Synacast]
"Version" = "2.7.3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}" = "ShellFire extesnsion"

[HKCU\Software\PPLive]
"InstallTime" = "131085288030010000"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPLive]
"UninstallString" = "%Program Files%\PPLive\PPTV\uninst.exe"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "13 89 08 1D D7 91 63 6F C1 D8 B8 DA 0C 2C 53 01"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPLive]
"URLInfoAbout" = "http://www.pptv.com/"

[HKCR\CLSID\{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}\InprocServer32]
"(Default)" = "%System%\kindling.dll"

[HKCR\pptv\DefaultIcon]
"(Default)" = "%Program Files%\PPLive\PPTV\PPLive.exe"

[HKCU\Software\PPLive\PPTV]
"IconBubble" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{95B3F550-91C4-4627-BCC4-521288C52977}]
"ButtonText" = "PPLive"

[HKCR\CLSID\{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}\VersionIndependentProgID]
"(Default)" = ""

[HKCU\Software\PPLive\Config\Other]
"pptvstartup" = "1"

[HKCR\CLSID\{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}\TypeLib]
"(Default)" = "{C5A164AA-482B-4322-842D-9C9DD3852F8E}"

[HKCR\Synacast]
"URL Protocol" = ""

[HKCR\Interface\{27B91D23-7428-46F4-AC61-E1869F374072}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCR\Synacast]
"InstallerName" = "PPTV(pplive)_forqd340"
"Custom" = "qd-all-slient-open-nlaunch-nscreen"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{95B3F550-91C4-4627-BCC4-521288C52977}]
"MenuStatusBar" = "PPLive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCR\Synacast\Shell\Open\Command]
"(Default)" = "%Program Files%\PPLive\PPTV\PPLive.exe %1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

[HKCR\Interface\{27B91D23-7428-46F4-AC61-E1869F374072}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPLive]
"InstallLocation" = "%Program Files%\PPLive\PPTV"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"

[HKCR\CLSID\{4C5A0DA6-C2DA-422D-89E1-457978AB87B5}]
"(Default)" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\PPLive\Config\Layout]
"Type" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCU\Software\PPLive\Config\Other]
"AutoMemoryManagement" = "0"

[HKCU\Software\PPLive\Config\PlaySet]
"ForceRGB" = "0"

[HKCR\ppl\Shell\Open\Command]
"(Default)" = "%Program Files%\PPLive\PPTV\PPLive.exe %1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"

[HKCU\Software\PPLive\Preferences]
"AutoReg" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{95B3F550-91C4-4627-BCC4-521288C52977}]
"CLSID" = "{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"PPAP" = "%Program Files%\Common Files\PPLiveNetwork\PPAP.exe -background"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\PPLive\PPTV]
"PPLive.exe"

The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"PPLive"

The process PPLiveU.exe:2540 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 2A 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B3 F9 A6 B4 94 54 0E C2 AF 98 13 F8 8D 8A 2C BF"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process regedit.exe:604 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "78 F4 2D 0B 56 15 F6 08 07 A7 DC 69 83 4E 7B D4"

The process regedit.exe:1368 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "87 7D 80 84 A8 69 53 CF B4 9E DC 77 C5 B3 00 DF"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Atfmon.exe" = "D:\Stion\tmp....................................\a.{D71C5380-D2A0-CD69-E3EE-E1002B3A309E}.. hh.exe"

The process regedit.exe:1604 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "61 0C BE 0E DF 52 2B DA B5 44 11 94 11 33 68 77"

The process regedit.exe:1944 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E2 C0 EE EA C4 1B 64 98 DC 38 11 58 F2 3C BD 90"

The process regedit.exe:1900 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5E 9E 12 E5 B0 18 09 BC 1C 2C A0 C6 4E 48 52 C2"

The process regedit.exe:1112 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1B 9A 12 2B 95 11 A8 47 1F 93 79 47 7B E4 43 3F"

The process regedit.exe:1864 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "87 B9 31 15 38 B6 18 D3 BD 36 49 F4 07 10 B0 F3"

The process regedit.exe:264 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1C A8 1B 0A 68 8F BD 0F 21 2F 82 64 09 7C F5 BD"

The process regedit.exe:1500 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5A 33 5A 2D 76 11 55 1D 94 DE 70 F6 36 41 6D A3"

The process regedit.exe:256 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "15 93 82 93 51 69 C2 C0 A3 FF 73 56 3C 3B C4 43"

The process regedit.exe:492 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "68 7C 56 33 B3 9C 2E 8B 57 68 13 C1 75 0E 2F 5D"

The process regedit.exe:220 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5E B3 69 1F D3 34 EA ED 17 51 CF E8 6C CF EA AF"

The process PPAP.exe:3584 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\PPLive]
"ppdiskid" = "0x000c29fd550f21"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 28 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5C 11 AB 32 AA 14 1D 42 3A AF 27 4C D6 99 FC 8B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process PPAP.exe:3776 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\PPLive]
"citycode" = "1121"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKLM\System\CurrentControlSet\Services\PerfOS\Performance]
"Disable Performance Counters" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\PPLive\PPAPSendUserInfo]
"senddate" = "2016-05-24"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 29 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "52 E4 9D 67 02 3A 1C 86 7C 98 F4 DB E4 A9 3F 6C"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKLM\System\CurrentControlSet\Services\PerfProc\Performance]
"Disable Performance Counters" = "0"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

[HKLM\System\CurrentControlSet\Services\PerfProc\Performance]
"Error Count"

The process PPAP.exe:3520 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Interface\{203AFF7C-C6A8-46F5-B32C-C6A7F4E79A62}\TypeLib]
"(Default)" = "{377AC21C-4921-4C3F-9240-7756548790FB}"

[HKCR\CLSID\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}\VersionIndependentProgID]
"(Default)" = "MngModule.Manager.2"

[HKCR\Interface\{04987413-5E4A-472F-9899-0A092233239E}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}\LocalServer32]
"(Default)" = "%Program Files%\Common Files\PPLiveNetwork\PPAP.exe"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}]
"AppName" = "PPAP.exe"

[HKCR\TypeLib\{377AC21C-4921-4C3F-9240-7756548790FB}\1.0]
"(Default)" = "MngModule"

[HKCR\MngModule.Manager\CurVer]
"(Default)" = "MngModule.Manager.2"

[HKCR\CLSID\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}]
"(Default)" = "Manager Class"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}]
"AppPath" = "%CommonProgramFiles%\PPLiveNetwork"

[HKCR\Interface\{203AFF7C-C6A8-46F5-B32C-C6A7F4E79A62}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{377AC21C-4921-4C3F-9240-7756548790FB}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\CLSID\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}\ProgID]
"(Default)" = "MngModule.Manager.2"

[HKCR\CLSID\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}\InprocServer32]
"(Default)" = "%Program Files%\Common Files\PPLiveNetwork\MngModule.dll"

[HKCR\Interface\{04987413-5E4A-472F-9899-0A092233239E}]
"(Default)" = "IManager"

[HKCR\MngModule.Manager.1\CLSID]
"(Default)" = "{9F0F8700-A4D8-4E24-A3E0-1CA654CB5179}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}]
"Policy" = "3"

[HKCR\CLSID\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{04987413-5E4A-472F-9899-0A092233239E}\TypeLib]
"(Default)" = "{377AC21C-4921-4C3F-9240-7756548790FB}"

[HKCR\TypeLib\{377AC21C-4921-4C3F-9240-7756548790FB}\1.0\0\win32]
"(Default)" = "%Program Files%\Common Files\PPLiveNetwork\MngModule.dll"

[HKCR\MngModule.Manager.2\CLSID]
"(Default)" = "{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}"

[HKCR\MngModule.Manager\CLSID]
"(Default)" = "{9F0F8700-A4D8-4E24-A3E0-1CA654CB5179}"

[HKCR\Interface\{04987413-5E4A-472F-9899-0A092233239E}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{203AFF7C-C6A8-46F5-B32C-C6A7F4E79A62}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Interface\{203AFF7C-C6A8-46F5-B32C-C6A7F4E79A62}]
"(Default)" = "_IManagerEvents"

[HKCR\Interface\{203AFF7C-C6A8-46F5-B32C-C6A7F4E79A62}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BB 02 BB DD C4 36 C8 3E 0D 11 8A 9C 09 45 96 3C"

[HKCR\Interface\{04987413-5E4A-472F-9899-0A092233239E}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\MngModule.Manager.1]
"(Default)" = "Manager Class"

[HKCR\MngModule.Manager]
"(Default)" = "Manager Class"

[HKCR\MngModule.Manager.2]
"(Default)" = "Manager Class"

[HKCR\TypeLib\{377AC21C-4921-4C3F-9240-7756548790FB}\1.0\HELPDIR]
"(Default)" = "%Program Files%\Common Files\PPLiveNetwork"

[HKCR\CLSID\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}\TypeLib]
"(Default)" = "{377AC21C-4921-4c3f-9240-7756548790FB}"

[HKCR\CLSID\{CA7DFF65-E473-4efe-ADF0-FC1E50CDFC82}\LocalServer32]
"ThreadingModel" = "Apartment"

The process regsvr32.exe:3920 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}\TypeLib]
"Version" = "1.0"

[HKCR\Ifupt.Update.1]
"(Default)" = "Update Class"

[HKCR\PPLive.Lite.1\CLSID]
"(Default)" = "{EF0D1A14-1033-41A2-A589-240C01EDC078}"

[HKCR\PPLive.Lite.1]
"(Default)" = "PPLive Lite Class"

[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}]
"(Default)" = "PPLive Lite Class"

[HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls]
"{EF0D1A14-1033-41A2-A589-240C01EDC078}" = "0"

[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}\TypeLib]
"Version" = "1.0"

[HKCR\Ifupt.DPlugin]
"(Default)" = "DPlugin Class"

[HKCR\TypeLib\{6F770594-0FC9-44DB-AD75-47C808CB7B44}\1.0\0\win32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\pplugin2.dll"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\TypeLib]
"(Default)" = "{6F770594-0FC9-44DB-AD75-47C808CB7B44}"

[HKCR\Ifupt.DPlugin\CLSID]
"(Default)" = "{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\VersionIndependentProgID]
"(Default)" = "PPLive.Lite"

[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\InprocServer32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\pplugin2.dll"

[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}\InprocServer32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\pplugin2.dll"

[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}\TypeLib]
"(Default)" = "{6F770594-0FC9-44DB-AD75-47C808CB7B44}"

[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}\TypeLib]
"(Default)" = "{6F770594-0FC9-44DB-AD75-47C808CB7B44}"

[HKCR\Ifupt.DPlugin\CurVer]
"(Default)" = "Ifupt.DPlugin.1"

[HKCR\PPLive.Lite\CurVer]
"(Default)" = "PPLive.Lite.1"

[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}\InprocServer32]
"ThreadingModel" = "both"

[HKCR\Ifupt.Update\CLSID]
"(Default)" = "{E62D3029-1430-49F8-9470-2A192B02E433}"

[HKCR\TypeLib\{6F770594-0FC9-44DB-AD75-47C808CB7B44}\1.0\HELPDIR]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\"

[HKCR\TypeLib\{6F770594-0FC9-44DB-AD75-47C808CB7B44}\1.0]
"(Default)" = "pplugin 1.0 Type Library"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\ProgID]
"(Default)" = "Ifupt.DPlugin.1"

[HKCR\PPLive.Lite\CLSID]
"(Default)" = "{EF0D1A14-1033-41A2-A589-240C01EDC078}"

[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{6F770594-0FC9-44DB-AD75-47C808CB7B44}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}]
"(Default)" = "DPlugin Class"

[HKCR\Ifupt.Update]
"(Default)" = "Update Class"

[HKCR\Ifupt.DPlugin.1]
"(Default)" = "DPlugin Class"

[HKCR\Ifupt.Update.1\CLSID]
"(Default)" = "{E62D3029-1430-49F8-9470-2A192B02E433}"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\Version]
"(Default)" = "1.0"

[HKCR\PPLive.Lite]
"(Default)" = "PPLive Lite Class"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}]
"(Default)" = "IEwaOCX"

[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}]
"(Default)" = "_IEwaOCXEvents"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\InprocServer32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\pplugin2.dll"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "71 B4 06 6D F4 A2 FF 49 04 24 94 71 51 70 EA E4"

[HKCR\Ifupt.DPlugin.1\CLSID]
"(Default)" = "{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}"

[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}\VersionIndependentProgID]
"(Default)" = "Ifupt.Update"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\MiscStatus]
"(Default)" = "0"

[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}\TypeLib]
"(Default)" = "{6F770594-0FC9-44DB-AD75-47C808CB7B44}"

[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\TypeLib]
"(Default)" = "{7163F003-E2FD-4C06-A268-F36C1083FBC0}"

[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\VersionIndependentProgID]
"(Default)" = "Ifupt.DPlugin"

[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}\ProgID]
"(Default)" = "Ifupt.Update.1"

[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}]
"(Default)" = "ISerializer"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\ToolboxBitmap32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\pplugin2.dll, 101"

[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\ProgID]
"(Default)" = "PPLive.Lite.1"

[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}]
"(Default)" = "Update Class"

The Trojan deletes the following registry key(s):

[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\InprocServer32]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\ProgID]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\VersionIndependentProgID]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\Programmable]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\TypeLib]

The process find.exe:2192 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "42 F0 E7 5B 75 DB 5D 36 B4 75 77 62 F3 92 F3 34"

The process PPLive.exe:3560 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping]
"{95B3F550-91C4-4627-BCC4-521288C52977}" = "8194"

[HKCU\Software\PPLive\SecondUp]
"PPTV" = "218475300"

[HKCU\Software\PPLive]
"citycode" = "1121"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 27 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\PPLive\RunState]
"channeltime" = "Tue, 24 May 2016 02:00:03 GMT"

[HKCU\Software\PPLive\PPTV\WakeUp]
"0_Date" = "131085180038130000"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKCU\Software\PPLive\PPTV\UserEdu]
"Classic2NewTip" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\PPLive\PPTV\UserEdu]
"tipstime" = "Thu Jan 13 17:02:38 UTC 0800 2011"

[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "PPLive.exe"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\Microsoft\Windows Script\Settings]
"JITDebug" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"

[HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping]
"NextId" = "8195"

[HKCU\Software\PPLive\PPTV]
"LastSimpleCheckTime" = "218475301"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1305859803"

[HKCU\Software\PPLive\RunState]
"channelcount" = "350701"

[HKCU\Software\PPLive\abmad]
"minimizeshow" = "0"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "38 FE C3 F0 7D 04 5E C1 F2 3E 8F BF B0 E3 68 91"

[HKCU\Software\PPLive\abmad]
"spacetime" = "600"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKCU\Software\PPLive\Preferences]
"AutoReg" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\PPLive\PPTV\UserEdu]
"RegVip" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\PPLive\abmad]
"adcfgurl" = "http://live.v2.pplive.com/zh-cn/ad/adconfig3.html"

[HKCU\Software\PPLive\PPTV\WakeUp]
"0_Time" = "0"

[HKCU\Software\PPLive\PPPWnd]
"PPPWndHandle" = "66538"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process forqd340.exe:1076 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 20 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "18 AD D7 30 A4 4E E7 EF 5D 34 93 8B 8A 07 2A DF"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

Dropped PE files

MD5 File path
d30a691367d5b7d14e690c8896c155b9 c:\Documents and Settings\Administrator\Application Data\Tencent\AXSEF\AXSEF.exe
76d1736f2bd7405598ddaa7146defdd4 c:\Documents and Settings\All Users\Application Data\vcry\kswbc.dll
7851449473178f9782263d51bc5e3bbc c:\Documents and Settings\All Users\Application Data\vcry\kswebshield.dll
bf5dcfd9da0514334d41cbd80d2a9138 c:\Documents and Settings\All Users\Application Data\vcry\kwssp.dll
f56a9f4fb234f8e9d99d0d1f5df7a7c8 c:\Documents and Settings\All Users\Desktop\forqd340.exe
525bf0271b6ef28762b778aade8e4b78 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\pi3603.exe
5b97eda528f54d13c3adcbbf83a7b466 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\PPTV(pplive)_forqd340[1].exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name:
Product Name:
Product Version:
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 3, 3, 6, 1
File Description:
Comments:
Language: Chinese (Simplified, PRC)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 524311 524800 4.59884 be1208f841dc92012d5f6bbdd832e6d9
.rdata 532480 55644 55808 3.15707 f6f8c907d8737bc8580a33fc54f93268
.data 589824 107800 26624 1.52615 e5d77411f751d28c6eee48a743606795
.rsrc 700416 12144 12288 3.42739 d00bce8ffb9d256f404c92a7bee6d555

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

Total found: 2
288f63ed926a2dfea22c60a24d8e5c26
ae3318944fdd27487fb60e38fa33b443

URLs

URL IP
hxxp://www.81830.info/tg14.html 199.59.243.120
hxxp://c01.i07.rpnic.lv3.cloudglb.com/PPTV(pplive)_forqd340.exe
hxxp://api.liqwei.com/location/ 119.254.0.9
hxxp://www.3929.cn/?tn=sun 122.114.60.218
hxxp://www.3929.cn/index.html 122.114.60.218
hxxp://www.3929.cn/template/4567/images/style.css 122.114.60.218
hxxp://www.3929.cn/js/jquery-1.7.1.min.js 122.114.60.218
hxxp://www.3929.cn/js/jquery.SuperSlide.2.1.js 122.114.60.218
hxxp://www.3929.cn/js/common.js 122.114.60.218
hxxp://www.3929.cn/js/function.js 122.114.60.218
hxxp://www.3929.cn/cron/index.asp?t=0.38952771224541083 122.114.60.218
hxxp://www.3929.cn/template/4567/images/menu.png 122.114.60.218
hxxp://www.3929.cn/template/4567/images/serbtn.png 122.114.60.218
hxxp://hm.e.shifen.com/hm.js?3767faaa77a89d77b80cba3753456e42
hxxp://www.3929.cn/template/4567/images/logo.gif 122.114.60.218
hxxp://www.3929.cn/js/ads/index01.js 122.114.60.218
hxxp://hm.e.shifen.com/hm.gif?cc=0&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1691788267&si=3767faaa77a89d77b80cba3753456e42&st=1&v=1.1.26&lv=1&tt=吉吉影音官网-吉吉电影-吉吉免费电影网-吉吉影音在线观看-吉吉影院
hxxp://www.3929.cn/template/4567/images/i.png 122.114.60.218
hxxp://www.3929.cn/pic/gg/960-90-1.gif 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2016-5/201651411255697119.jpg 122.114.60.218
hxxp://www.3929.cn/images/play-img.png 122.114.60.218
hxxp://www.3929.cn/template/4567/images/lazyload.gif 122.114.60.218
hxxp://webcdn.cloudxns.pptv.com/config/pptv/qd-all-slient-open-nlaunch-nscreen/version.ini
hxxp://www.3929.cn/pic/uploadimg/2015-7/20122.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-9/16865.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2015-4/19502.jpg 122.114.60.218
hxxp://lb.shbnj.cloudxns.pptv.com/config/pptv/qd-all-slient-open-nlaunch-nscreen/forqd340/bind_en-us.ini
hxxp://www.3929.cn/pic/uploadimg/2015-9/20568.jpg 122.114.60.218
hxxp://e6845.dscb1.akamaiedge.net/pca3.crl
hxxp://e6845.dscb1.akamaiedge.net/CSC3-2009-2.crl
hxxp://shtlvs.cloudxns.pptv.com/getcitycode
hxxp://webcdn.cloudxns.pptv.com/catalog.xml
hxxp://web.data.lvs.cloudxns.pplive.com/1.html?sdPg0uXTraCSqrOblrKpmpyordbb2 fJo6Scj7qioOicmabIoqnSzauaoNaempyqraGgn6qVpKSgmaqLtq2cj72iop6jl6mLuK2dj7 iwMDAv57V4NzV39uOz9bb2 fJo6Scj8Cilrupj8KioJa5psWwlr6pmZy0raE=
hxxp://web.data.lvs.cloudxns.pplive.com/1.html?sdPg0uXTraCSqrOalrKpmpyoraGSrbOWlrWpj7yioOicmabIoqnSzauaoNaempysraGgn6qVpKSgmauLuK2cj7 ioJa2pqaLvK2dl6aToJ6hoquLva2ej8SioA==
hxxp://web.data.lvs.cloudxns.pplive.com/1.html?sdPg0uXTraCSqrOXoZaupqbdoKCczKie1tShnqbLoqGSrLOa7KHom6yVoOye5afhoOy/zujb2dPRicbG09uMnPKLtK211 rK3Ji kpao3 LRkcqymZDVoKOZp6ecibm1xZCsiamTpKCzsfCLta2fnK XlrapmpysraWenK2boJa0pqyToJ6eoqaVnqWhmqg=
hxxp://www.3929.cn/pic/uploadimg/2015-10/20785.jpg 122.114.60.218
hxxp://shtlvs.cloudxns.pptv.com/zh-cn/ad/adconfig3.html
hxxp://pptv.xdwscache.speedcdns.com/v2/logo.jpg
hxxp://www.3929.cn/pic/uploadimg/2015-10/20745.jpg 122.114.60.218
hxxp://webcdn.cloudxns.pptv.com/
hxxp://web.data.lvs.cloudxns.pplive.com/1.html?sdPg0uXTraCSqrOalrKpm5yoraGSrbOWlrWpz XX4dSfnaaLtq2c4aaVoNOeotzJpaWcz6iWlrepmqqbpKCgnaqVqJa0pqaLua2cj8CioZa4pqicoKOcmaaelr2pmZyzraCSuLOXoaikj8aioQ==
hxxp://webcdn.cloudxns.pptv.com/portal/12345.html
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/images/build/v_09151721/style.css
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/js/common2.js?v=09151721
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/images/build/v_09151721/menu.png
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/images/build/v_09151721/download.png
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/images/build/v_09151721/bg_portal.jpg
hxxp://www.3929.cn/pic/uploadimg/2015-4/19703.jpg 122.114.60.218
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/images/build/v_09151721/bg_bottom.png
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/images/build/v_09151721/img.gif
hxxp://pptv.xdwscache.speedcdns.com/sp96/2013/03/28/18092704918.jpg
hxxp://pptv.xdwscache.speedcdns.com/images/2013/01/09/10110990986.jpg
hxxp://pptv.xdwscache.speedcdns.com/images/2012/07/04/13433875515.jpg
hxxp://pptv.xdwscache.speedcdns.com/images/2013/01/09/10144547146.jpg
hxxp://pptv.xdwscache.speedcdns.com/v2/logo.swf
hxxp://pptv.xdwscache.speedcdns.com/sp96/2013/02/27/15264463677.jpg
hxxp://pptv.xdwscache.speedcdns.com/sp96/2013/05/21/19041266534.jpg
hxxp://pptv.xdwscache.speedcdns.com/sp96/2012/10/26/13470667633.jpg
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/images/build/v_09151721/imgLogo.gif
hxxp://pptv.xdwscache.speedcdns.com/sp96/2013/05/18/17072340777.jpg
hxxp://pptv.xdwscache.speedcdns.com/mini/portal/111205/images/build/v_09151721/img_fill.gif
hxxp://adcdn.cloudxns.pptv.com/webdelivery/webafp?ap=201401&ct=js
hxxp://pptv.xdwscache.speedcdns.com/sp96/2011/08/03/09585262495.jpg
hxxp://a1294.w20.akamai.net/beacon.js
hxxp://a1294.w20.akamai.net/b?c1=2&c2=9288713&c4=2&ns__t=1464044415657&ns_c=windows-1252&ns_if=1&cv=3.1&c8=_PPLive&c7=http://client-mini.pptv.com/portal/12345.html&c9=
hxxp://a1294.w20.akamai.net/b2?c1=2&c2=9288713&c4=2&ns__t=1464044415657&ns_c=windows-1252&ns_if=1&cv=3.1&c8=_PPLive&c7=http://client-mini.pptv.com/portal/12345.html&c9=
hxxp://www.3929.cn/pic/uploadimg/2015-12/20884.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-11/18154.jpg 122.114.60.218
hxxp://pptv.xdwscache.speedcdns.com/sta.js/
hxxp://web.data.lvs.cloudxns.pplive.com/pv/1.html?plt=clt&adr=hxxp://client-mini.pptv.com/portal/12345.html&radr=&puid=9d03cc1eb8c7469496c7fc5fc376c2ca&uid=&vip=0&o=&src=clt&r=0.5800773738672186
hxxp://www.3929.cn/js/ads/index02.js 122.114.60.218
hxxp://www.3929.cn/template/4567/images/shot.gif 122.114.60.218
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-03-16/20163161112025664.png 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-6/20164618361516790.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-6/20164611133711460.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-03-23/201632311402423396.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-4/2016442312891676.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-5/20164521161384572.jpg 173.245.60.142
hxxp://www.3929.cn/pic/uploadimg/2014-7/14333.jpg 122.114.60.218
hxxp://webcdn.cloudxns.pptv.com/pptv/ic/all/self_all.ini
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-5/20164520192928806.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-5/20164520571918233.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-1/20164119442353035.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-6/2016461171089433.jpg 173.245.60.142
hxxp://www.3929.cn/pic/uploadimg/2014-6/4899.jpg 122.114.60.218
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-03-21/201632116233468316.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-6/2016461625537987.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-6/20164613211592031.png 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-6/20164611265812548.png 173.245.60.142
hxxp://www.3929.cn/pic/gg/960-90-2.gif 122.114.60.218
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-6/201646931670541.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2016-04-6/20164619445529347.jpg 173.245.60.142
hxxp://img.677dy.com.cname.yunjiasu-cdn.net/upload/vod/2015-05-25/201552512203979861.jpg 173.245.60.142
hxxp://www.3929.cn/pic/uploadimg/2014-6/6363.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-4/20140103141146500.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-4/20140210203041585.jpg 122.114.60.218
hxxp://c01.i07.rpnic.lv3.cloudglb.com/peer/2.5.0.8761/peer_2.5.0.8761.dll
hxxp://www.3929.cn/pic/uploadimg/2014-4/20140210202824891.jpg 122.114.60.218
hxxp://www.3929.cn/template/4567/images/g.gif 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-4/20140210201622899.jpg 122.114.60.218
hxxp://webcdn.cloudxns.pptv.com/config/control.xml
hxxp://www.3929.cn/pic/uploadimg/2014-4/20140210201418264.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-4/20130304191422116.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-4/20140410235243256.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-4/20121129171512084.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-6/6383.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-6/6364.jpg 122.114.60.218
hxxp://shtlvs.cloudxns.pptv.com/zh-cn/xml/NewPopup.Xml
hxxp://www.3929.cn/pic/uploadimg/2014-6/6372.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-6/6349.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-6/6354.jpg 122.114.60.218
hxxp://www.3929.cn/pic/uploadimg/2014-6/6344.jpg 122.114.60.218
hxxp://client-mini.pptv.com/portal/12345.html 140.207.204.101
hxxp://img.677dy.com/upload/vod/2016-04-6/2016461171089433.jpg 173.245.60.142
hxxp://img.677dy.com/upload/vod/2016-04-4/2016442312891676.jpg 173.245.60.142
hxxp://download.pplive.com/PPTV(pplive)_forqd340.exe 123.147.166.14
hxxp://download.pplive.com/peer/2.5.0.8761/peer_2.5.0.8761.dll 123.147.166.14
hxxp://hm.baidu.com/hm.gif?cc=0&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1691788267&si=3767faaa77a89d77b80cba3753456e42&st=1&v=1.1.26&lv=1&tt=吉吉影音官网-吉吉电影-吉吉免费电影网-吉吉影音在线观看-吉吉影院 220.181.7.190
hxxp://s1.pplive.cn/sta.js/ 203.130.61.21
hxxp://h.synacast.com/1.html?sdPg0uXTraCSqrOXoZaupqbdoKCczKie1tShnqbLoqGSrLOa7KHom6yVoOye5afhoOy/zujb2dPRicbG09uMnPKLtK211 rK3Ji kpao3 LRkcqymZDVoKOZp6ecibm1xZCsiamTpKCzsfCLta2fnK XlrapmpysraWenK2boJa0pqyToJ6eoqaVnqWhmqg= 114.80.72.111
hxxp://img32.pplive.cn/sp96/2012/10/26/13470667633.jpg 203.130.61.21
hxxp://b.scorecardresearch.com/b?c1=2&c2=9288713&c4=2&ns__t=1464044415657&ns_c=windows-1252&ns_if=1&cv=3.1&c8=_PPLive&c7=http://client-mini.pptv.com/portal/12345.html&c9= 212.30.134.168
hxxp://img32.pplive.cn/sp96/2013/05/21/19041266534.jpg 203.130.61.21
hxxp://img.677dy.com/upload/vod/2016-04-1/20164119442353035.jpg 173.245.60.142
hxxp://img.677dy.com/upload/vod/2016-04-6/20164611133711460.jpg 173.245.60.142
hxxp://h.synacast.com/1.html?sdPg0uXTraCSqrOalrKpm5yoraGSrbOWlrWpz XX4dSfnaaLtq2c4aaVoNOeotzJpaWcz6iWlrepmqqbpKCgnaqVqJa0pqaLua2cj8CioZa4pqicoKOcmaaelr2pmZyzraCSuLOXoaikj8aioQ== 114.80.72.111
hxxp://img.677dy.com/upload/vod/2016-04-6/20164611265812548.png 173.245.60.142
hxxp://b.scorecardresearch.com/beacon.js 212.30.134.168
hxxp://img.677dy.com/upload/vod/2016-04-5/20164521161384572.jpg 173.245.60.142
hxxp://static1.pplive.cn/v2/logo.jpg 203.130.61.17
hxxp://b.scorecardresearch.com/b2?c1=2&c2=9288713&c4=2&ns__t=1464044415657&ns_c=windows-1252&ns_if=1&cv=3.1&c8=_PPLive&c7=http://client-mini.pptv.com/portal/12345.html&c9= 212.30.134.168
hxxp://up.pplive.com/pptv/ic/all/self_all.ini 118.187.1.104
hxxp://img.677dy.com/upload/vod/2016-04-6/20164618361516790.jpg 173.245.60.142
hxxp://static1.pplive.cn/mini/portal/111205/images/build/v_09151721/menu.png 203.130.61.17
hxxp://img.677dy.com/upload/vod/2016-03-16/20163161112025664.png 173.245.60.142
hxxp://img32.pplive.cn/sp96/2013/02/27/15264463677.jpg 203.130.61.21
hxxp://img.677dy.com/upload/vod/2016-04-6/20164613211592031.png 173.245.60.142
hxxp://img.677dy.com/upload/vod/2015-05-25/201552512203979861.jpg 173.245.60.142
hxxp://img.677dy.com/upload/vod/2016-04-6/201646931670541.jpg 173.245.60.142
hxxp://img.677dy.com/upload/vod/2016-04-5/20164520192928806.jpg 173.245.60.142
hxxp://live.v2.pplive.com/zh-cn/xml/NewPopup.Xml 180.153.106.24
hxxp://ins.pplive.com/config/pptv/qd-all-slient-open-nlaunch-nscreen/forqd340/bind_en-us.ini 114.80.72.57
hxxp://static1.pplive.cn/mini/portal/111205/images/build/v_09151721/img_fill.gif 203.130.61.17
hxxp://client-list.pptv.com/catalog.xml 118.187.1.104
hxxp://img32.pplive.cn/sp96/2013/05/18/17072340777.jpg 203.130.61.21
hxxp://static1.pplive.cn/mini/portal/111205/images/build/v_09151721/img.gif 203.130.61.17
hxxp://h.synacast.com/1.html?sdPg0uXTraCSqrOblrKpmpyordbb2 fJo6Scj7qioOicmabIoqnSzauaoNaempyqraGgn6qVpKSgmaqLtq2cj72iop6jl6mLuK2dj7 iwMDAv57V4NzV39uOz9bb2 fJo6Scj8Cilrupj8KioJa5psWwlr6pmZy0raE= 114.80.72.111
hxxp://web.data.pplive.com/pv/1.html?plt=clt&adr=hxxp://client-mini.pptv.com/portal/12345.html&radr=&puid=9d03cc1eb8c7469496c7fc5fc376c2ca&uid=&vip=0&o=&src=clt&r=0.5800773738672186 114.80.72.110
hxxp://hm.baidu.com/hm.js?3767faaa77a89d77b80cba3753456e42 220.181.7.190
hxxp://ins-version.pplive.com/config/pptv/qd-all-slient-open-nlaunch-nscreen/version.ini 118.187.1.104
hxxp://wafp.pptv.com/webdelivery/webafp?ap=201401&ct=js 180.153.106.87
hxxp://img1.pplive.cn/images/2012/07/04/13433875515.jpg 203.130.61.17
hxxp://static1.pplive.cn/mini/portal/111205/images/build/v_09151721/style.css 203.130.61.17
hxxp://live.v2.pplive.com/zh-cn/ad/adconfig3.html 180.153.106.24
hxxp://img.677dy.com/upload/vod/2016-03-21/201632116233468316.jpg 173.245.60.142
hxxp://static1.pplive.cn/mini/portal/111205/images/build/v_09151721/bg_bottom.png 203.130.61.17
hxxp://static1.pplive.cn/mini/portal/111205/js/common2.js?v=09151721 203.130.61.17
hxxp://crl.verisign.com/pca3.crl 23.37.37.163
hxxp://img33.pplive.cn/sp96/2013/03/28/18092704918.jpg 203.130.61.21
hxxp://img.677dy.com/upload/vod/2016-04-6/20164619445529347.jpg 173.245.60.142
hxxp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl 23.37.37.163
hxxp://img1.pplive.cn/images/2013/01/09/10110990986.jpg 203.130.61.17
hxxp://www.pptv.com/ 118.187.1.104
hxxp://img.677dy.com/upload/vod/2016-04-6/2016461625537987.jpg 173.245.60.142
hxxp://img1.pplive.cn/images/2013/01/09/10144547146.jpg 203.130.61.17
hxxp://static1.pplive.cn/mini/portal/111205/images/build/v_09151721/bg_portal.jpg 203.130.61.17
hxxp://img.677dy.com/upload/vod/2016-04-5/20164520571918233.jpg 173.245.60.142
hxxp://h.synacast.com/1.html?sdPg0uXTraCSqrOalrKpmpyoraGSrbOWlrWpj7yioOicmabIoqnSzauaoNaempysraGgn6qVpKSgmauLuK2cj7 ioJa2pqaLvK2dl6aToJ6hoquLva2ej8SioA== 114.80.72.111
hxxp://iptable.pplive.com/getcitycode 180.153.106.27
hxxp://img.677dy.com/upload/vod/2016-03-23/201632311402423396.jpg 173.245.60.142
hxxp://pp.pplive.com/config/control.xml 140.207.204.101
hxxp://img34.pplive.cn/sp96/2011/08/03/09585262495.jpg 203.130.61.17
hxxp://static1.pplive.cn/v2/logo.swf 203.130.61.17
hxxp://static1.pplive.cn/mini/portal/111205/images/build/v_09151721/download.png 203.130.61.17
hxxp://static1.pplive.cn/mini/portal/111205/images/build/v_09151721/imgLogo.gif 203.130.61.17
pp3.g1d.net 114.80.72.22
2010.g1d.net 114.80.72.111
down.cdnhy.com 42.120.158.78
ppvabs.pplive.com 59.151.36.112


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile
ET POLICY Outdated Windows Flash Version IE

Traffic

GET /upload/vod/2016-03-16/20163161112025664.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:17 GMT
Content-Type: image/png
Content-Length: 172603
Connection: keep-alive
Set-Cookie: __cfduid=d35dba885a855bc3db40766192692b64d1464044417; expires=Tue, 23-May-17 23:00:17 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 16 Mar 2016 03:12:00 GMT
ETag: "30ff569b317fd11:314"
CF-Cache-Status: HIT
Expires: Tue, 24 May 2016 03:00:17 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f8964840a54-ARN
.PNG........IHDR.......=......(.\....bKGD..............pHYs.......... 
.... .IDATx...i.,..%..3DD.w~....H.T..TI%..(.............O2.......p....
.v. [email protected]<...9.p....d....5...!qofddD.u.^{.}[email protected]
DT..?....a...H..c...3...?...1....i..a...0.]..V..B.YDT?.1.XDd..{...o...
.....8.4....gm.....9..g2C.D.tR......r.c.......?~.[...d.......>...k.
.......wA..O?..<]..a..~P...O&c_9B...9......!..D.Z..G..5.$*. "9I....
......."e.ED..r..Vrr.....e".=3{..u*.....*.D..$*.0.m...ZI).....!.0....n
P......=-'P.UA..{Ay..(......@v.. ."[email protected].)...c.1)..R.Y"b.2...h.[d.
......9....7.......|.{.....A`y_Dr.......5U-...j4.5MCD.0....\W.#....UUU
F..cL.4....B.1F&...u.R.1..[k.h.Y%..a...s.D&fk.s...{......j.%...|X....A
7.....cI..h.........U!EDf2.E..j$BP....e........Y .1.r...BTU...kLJYE...
1.Tu..uN9...T...1..SFd"...U@D&d.U.df4.r.Y........%oG...!.*.. ...2..`..
P..s.,o......h<......U?.../..!e..B.)....Co........o.....ADE..E.....
.0=.......S..9WUUUU.ZDL).v .a.]..]<#"..v4.9..a..........N...I41#.e"
.1.................'....b$.....b<.5MUU.d2..F.4....AA........A."JI..
.GB D..1Q...R...%...c...........C.*.......S..0.CJ...0....Afbc....3..Q.
I..:....Dc....,YT.jV..iBBD..p.&^..".3""H........!.O6f<....8_.V...r*
3.&...s..Z...C.2.....A....c.....T.og./<[email protected].".[;..N..c
...S..\j...a....);[email protected].....{O..S-..;g.a...9. .......u].=.YW.&
.#.u...ecRJ..JU _11[...En......`&f!NY...DU..7..Qw9..... ...6.c....6.`L
@B".CX........j.R..J..aP U.&b"c...." .......1%.LDH....'..n.t...7....R.
D@@..9..!.l....:[...to.X.br.1s.q.<w\V...C.......1_.............

<<< skipped >>>

GET /upload/vod/2016-03-23/201632311402423396.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:18 GMT
Content-Type: image/jpeg
Content-Length: 133728
Connection: keep-alive
Set-Cookie: __cfduid=d35dba885a855bc3db40766192692b64d1464044417; expires=Tue, 23-May-17 23:00:17 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 23 Mar 2016 03:40:24 GMT
ETag: "e25b85bbb584d11:314"
CF-Cache-Status: REVALIDATED
Expires: Tue, 24 May 2016 03:00:18 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f8b44b40a54-ARN
......JFIF.............C..............................................
......................C...............................................
........................X.T.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?........
r.......-..f..=.:W....5..&..Z....2.$z1......[.q...*5..L.......W...t...
w2..,x....X..'.r...s.....f.[......T....|y.*.M....H.a....\........5..j.
.w.7X.t..o5).H.p.#I.......Z....OH.Y.o5.....!.x.uf8...v.:.....k....no.;
...l.....dd.n?J.u..^....B...Vr.....b>b.........V.:!GK.....^..|.N...
o.3.m.8. ......<v.H.{.....'...........D.d./?x...._".......7z.1y....
;..F^6..w/..u..hi.(..m...R1......9^.".'........m.JVZn}.l.. ........d..
.O...,~%.........Bd..T(.A..E....1.$zWo5..!........`..?...O..d$.Nf...D`
@..M.....?..._....~%.m<gk...f........U|..O..Q.n1....."...=.T....L..
.....rZ/........r..!.WP..,}N...Z_.}do......1qn.H..p.ZF.z..r#*F..2A....
.ti.E..?.....f?'.....*X%WP............i.....q..h..pG .s......D@.<..
.....Cp.i..r..Y0.C..2L....:[email protected].,v...i....1....E$ i!...|y.S....$mp..
...Z.`.F2OBEW...........O")[email protected].".....)...y.eN
pTs......2...ca.T./[email protected]#...Gr}........pK.kz.V....uq4

<<< skipped >>>

GET /upload/vod/2016-04-5/20164521161384572.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:18 GMT
Content-Type: image/jpeg
Content-Length: 20383
Connection: keep-alive
Set-Cookie: __cfduid=dee85ef855de83e0d715cc1768f6e369c1464044418; expires=Tue, 23-May-17 23:00:18 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Tue, 05 Apr 2016 13:16:13 GMT
ETag: "74dcfc533d8fd11:314"
CF-Cache-Status: REVALIDATED
Expires: Tue, 24 May 2016 03:00:18 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f8ef5150a54-ARN
......JFIF.....`.`.....C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222...........".....................................
...........................................T...J.G,.i._H ..........?h.
<2.5.D.r.B...3".'.1..pm.xN.(........;x...n.Ix..7.........#....B....
.S6?^H_:A.CKzD.v..4v...a...W..C.B...m..Z9.a...34.]..Ag=k.n.s.9DZ.:....
l.Z/........F.Zx=.x.F}.f...=4.3........U....'3.8._....7.*X...9...... H
c',%..........A.V8.S..... db.NZ...(P]."r.8C...D.........y5...`...kH..1
.h...2N).....o.=.%mR.Bf!...Wx.........X..Lr.J-S.....0XH....6..DkT.x..m
......k..gP..7.....k... D......H....eYA.....-H..x..<>.....R.....
.A.'$.t^V...oQ;-%-.N....U...6.$.jBd..h,..p}....O.eL....1Io...siwF.s$%B
.Bj...4z_..........Td..S.R%.u.I..~[..^.6$.:.>..-.....N.......S^M.Q.
q......OL..\&U..,am`._%[email protected]<..<.......|.#.9..'....i..@
;.`.6..(...A ...8`d.......G...!c...).).!....$..^h...3.uGZfp...I.....5.
...D.....x.X.E..%.Ax..H..T5.X#......<.. oX.i....`..zK,.x.LN....h..L
-...N..z..cQ.P.....>..&Nj....:V.E...:....yc...E.I.NB6.|.Lg....; ...
QJ.;Wj....i....SJC...Dte.o.62...p*c.BD...R.L.4h...d.......8.........&l
t;'....y-...Mn4.l.D}3t...F...-.K..v......].....s.`4..4\..BV...5.......
..CZ.I .x.-..L.......z5..Ty......;>.x...w..5.....e.`........i.`..3.
..m.....-.....WFl...4a.PMt...B`.1.D..).n6"A.;4C.;sW3..bB.#u.ou....;.h.
..C. w..^"..^.[..u....[.{V.........f...B.SWn.4........V......E..:=.F..
:...Z..YB......... ..........................!"..#123. 4A$BC......

<<< skipped >>>

GET /upload/vod/2016-04-5/20164520192928806.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:18 GMT
Content-Type: image/jpeg
Content-Length: 10836
Connection: keep-alive
Set-Cookie: __cfduid=dee85ef855de83e0d715cc1768f6e369c1464044418; expires=Tue, 23-May-17 23:00:18 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Tue, 05 Apr 2016 12:19:29 GMT
ETag: "d6bf3d67358fd11:314"
CF-Cache-Status: HIT
Expires: Tue, 24 May 2016 03:00:18 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f91b55b0a54-ARN
......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222...........".....................................
..........................................{).},.....a...H..h...-.e..}.
.0i.........9.pY [email protected]}4Z?..c|y...}..v..3..Q..........jc..O
i.......4.5..k.......)..K.i@?"..^........K.Y....n;.'.}|_3%>....b8Y6
.:RcwU.G%vS!.M*i"...$..l..>.j..H.4.N4.y7%.()e..y42.r...3..1....|U..
e..x...&.*.fVy....-.....;.HXk.%`....[SU.....DuW...^..k...z.nMs.E.....n
R...=.]5..t...OY..C..l....C...r...Rh&.4.G....u.:....{.......PZC.W..g]*
._...M..%.t.......,...M...KpV1...1....z..&SQ.i....k.fW......^Su.....b.
[email protected]...={.:..:....Z.....U...k.U..&.(.lsb..O..!.....i
...........gq...[.... e..M..._..5^.y........,......'..................
.........!"1.2.#$A3.................8L.....fz..s....'......2~......%..
Q...L.J@3pa]J.uD.P.q...F..7Y.s...v.=.8S....H..8....k.....8..&1......y.
..7.N~XC.......I......!h.2.e........F......ec.....0......;#.}?.O......
..[.DV.f........s..#5.g8<^.....;.OlH....... ....32D...f...1.F..6...
%K..........K.. .......b.48..Q...\.2..$Io;.._....2...p...0..nm# .8...*
q..{Y..N ..gmT:..{.Gv6..u...M........."-1..".....s{,. .r.A...Mf.s.c.}.
.$nq.OC....g.O...ly>.)..H..B...WcoV_V...m.-.X....)..W.m0..q.M......
W.n/.].?.B.a2..e..-....D;...&AS.O..O57./nn8.,......#pY...Ey.[!Vn1f.0'.
&..B..K..r....U.....k....,...i... &8.a..5...m.....(.S.. ..}M9~..D.Z..1
..dG..s.|.DeYk....-h......~A..\..y)WB..C*B...0."6....Sr.o.6H'..XS.

<<< skipped >>>

GET /upload/vod/2016-04-5/20164520571918233.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:19 GMT
Content-Type: image/jpeg
Content-Length: 23839
Connection: keep-alive
Set-Cookie: __cfduid=dee85ef855de83e0d715cc1768f6e369c1464044418; expires=Tue, 23-May-17 23:00:18 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Tue, 05 Apr 2016 12:57:19 GMT
ETag: "8e48c8af3a8fd11:314"
CF-Cache-Status: REVALIDATED
Expires: Tue, 24 May 2016 03:00:19 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f9225650a54-ARN
......JFIF.....`.`.....C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......4....".....................................
........................................2....y.. v^:..WB.;O........aS.
l...q......Z..N....DE....8...V.....L. ..K.....I\.y.=.....S.r.s.Y..iSm.
...SyZn3.=P.K........I....'G.../go.].FB/WQ..$,..]R.iy.R..}..Agm.GY.Yc.
...K...VY.y.....!..i......K.a})..ms6.......VQ....}.`...B.t...#%$.'I*WY
......\d..v..%m.d...p....3....$..Q...^...R...@ 5Gs..T\\..............#
:OD ....[E.0....h.6...z.<.$..#y..{.Z.2..s6O.V..u.......B..RYAC...LW
.W...^.Hr/...r...x.<....c.x.."...........z.7.....mMN..1:@..[.......
}[email protected]..!..4.W-..j>.c.T...#."..0../U....g\....
2R..1...v.B..u...t..>.8.T..]\..........$.l..3.3.t`..6.......ii..J..
Z.N..R.J...DM.Hbm...FF....p..=X...j....1.9...'.i.. M.1..h.....vsF4.[.?
[email protected]..^o].3[.aB..V.q..Y..3 .Y...........n.}.}..uqAH...!...
q7......:./...QH....n...`[email protected]..:tw9M.K/[U.[zw...;h.W..h.#.8../`.
G|....4.kX.a...)....Z..iy.v..I./ ...f).....=. ~.PO.w...[>z.S.......
5.x...\..6.5sZw...k...r-..D$Kl6K;Y..B..>...w(in...j.'..,...9..&A...
>....c?...\.l.%...m.........l.~p..ey...NZ..N...z.....,*..>...'J.
W..~B...F.....F,:.g.. ....U.8"..&.:HQ1^O.5T...a..q...'..od.-.;..JI..J.
..b>..vFFQ*.....VFE.%.A..a..5\.........._.....6.b.....L|P<..Pl..
$.........g.k;..Y....nW.H.0.R..))g.J............)c'...%..%.."U.X..X.q4
..?...*..........................!"..12#A. $´.............6.....

<<< skipped >>>

GET /upload/vod/2016-04-1/20164119442353035.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:19 GMT
Content-Type: image/jpeg
Content-Length: 33191
Connection: keep-alive
Set-Cookie: __cfduid=d7a073d511de4c8ad000a9fd61cacb80b1464044419; expires=Tue, 23-May-17 23:00:19 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Fri, 01 Apr 2016 11:44:23 GMT
ETag: "de814fd6b8cd11:314"
CF-Cache-Status: HIT
Expires: Tue, 24 May 2016 03:00:19 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f94f5b90a54-ARN
......JFIF.....`.`.....C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222........3..".....................................
............................................QQU..5.U..Q..@r4p*#E.*.h.r
2=...^.{.... ...b.2.......*....QEV..#.U.i........q.F\$.#Q..N..d.K^.5V.
#..QU..........E.Af.GJ...&V:)Vw./?ki..\.x..Z..X.V....-mp..NU.h.....h..
F*..j....h......p.....m..u..k<u.....#..).,N.. Ys]...(..D...T.".*...
p...&.U..x.{.'...<...^9#.. ^..1..Y...K..J1.."6Y.#h.rk......(>i.$
...t.P..0.j.......g.z..{..8.t<.{..:..[.....v..V....r....V...}..|w..
..S~`.k.:..Lzb{K.....DU.7...i.~Z..|;].n...W.p47h...k.~................
zo.M..<.Z..........:x.......b....,.....<\......r....nw..7.u...&g
t;....>.....;...9..d...ZNG\..ks"K.v......k.....[..]:.....8D&...>
../. ..A.....>..9_~|.7....'..2u..>...[.....=.n..5%ms.=X.|.o..|.7
...\3y/B.....Q6e...w9.\FN.~.....K'..?...V 5..~...$....6.k..9....3.....
.7N...3..2pyS..._B8~...........h...<)...z.p.I....?~GGG..........l..
yL4.......=db....F(.....W\.q,<.u.tN.k..q93!....&y.C......9.D.)5.$..
......7/>....5...w.5.....4....k....y.Ql.q..M.3n..L<9n.x..h....n.
..wx...".<,.7s....&...9...Z.S.G..{c.H]5..9U..27I.^.._3d.:..J..2....
.dws......-.;N.....d..i.o....=K....:m..m.X.....Ib..z...S.P O{......d..
G..C.....RF,.,. ..^..[.....ht..._C..,.<0iS.....k".rc3GOT..#..M.E.4D
k5`..... TD..3.{k..<..:. .O4...a..(..........}....6`..vN.1>Z....
%J..W<6.....h.VlzA...3P.......u._G...?/.rE....]nx..x.Ws@....?U.

<<< skipped >>>

GET /upload/vod/2016-04-6/2016461171089433.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:19 GMT
Content-Type: image/jpeg
Content-Length: 113466
Connection: keep-alive
Set-Cookie: __cfduid=d7a073d511de4c8ad000a9fd61cacb80b1464044419; expires=Tue, 23-May-17 23:00:19 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Tue, 05 Apr 2016 17:17:10 GMT
ETag: "2a64ccfc5e8fd11:314"
CF-Cache-Status: REVALIDATED
Expires: Tue, 24 May 2016 03:00:19 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f9585cb0a54-ARN
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..:.....
.ai.;.............`I...{R......`.|X.X.y.>#.......9.}.W1 .cdw.6ZM...
...[..1...l([email protected]...|...../.....?..U.\ZNl..$........y...6O\. C
.... ...5i.2x..-......(.m....d.....P..#.s..f..<.f'..u..xsy!X..,.HIa
..t.._..O.~..>......7....q.....(".>T..QH.N..k..:.e..T...%.2.....
....._|I.`.|M..X......A.FX."V....{9|......T.?.<_..........4x...E.=k
M..n.cQp.G)?......w`....C...y..3......^....c.-..4B.....^$...bnm.*HV...
..[..~%..<....8..{...K..\...-...;..i.m..ur..i.y~...........S.!...t.
.0 ....0=I..u5.......[C.......G..O..M..W.[.$..ms..3........W:..u...q..
......,...E.G ....<:<)..V.........K..cn.Y..Eg......1\.......{...
.>/.........-..k...'O..K!im.kH.D.3JY ....p....1|l..KI~)...C...O...
WS.....l.G..~:kZ^...k>..f6F..;....U"........r..3c#....:....j/.Z.[.f
..V...o..vS..dq..gi..<d.{g.?....2....K. ......Se?..c3.5....f......0
<.....|@.5........].x".......}..bT......).I.1$W....Km.V.>6..

<<< skipped >>>

GET /upload/vod/2016-03-21/201632116233468316.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:20 GMT
Content-Type: image/jpeg
Content-Length: 128119
Connection: keep-alive
Set-Cookie: __cfduid=d88aa9f20f043433607df4e7b3962b86f1464044420; expires=Tue, 23-May-17 23:00:20 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Mon, 21 Mar 2016 08:23:34 GMT
ETag: "1a1fd2f54a83d11:314"
CF-Cache-Status: REVALIDATED
Expires: Tue, 24 May 2016 03:00:20 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f9916290a54-ARN
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?........
...r.?..P..Cv;|.'..]..Z\....e...u..{K.)......k.RM..K[..w..y.lz.Nk.,[&l
t;......T..W.*I......4.E.6....[-.(..d6..$...5..(P.X.`..............bA.
..~'..l.3..;.9....Y.l.....{}k..O.`FO...f......F.q...XN......u$t.U..b..
'.....H.5.A=.....KmR.w=.V...<.?....q.t..R.(....FEt..B.e...1..qx~;.U
H.....*.U... ...1......xu.[[email protected].. m.Sl.......S.Ym..........=........
.0.d.t.....0..!..A. Qn..2......i.\.,..=.Z\..Ts.xu9....<f.5..!.]y...
.]][email protected]...>.KU.)-...c.#5^..>T......eP.:..n..<..c.O.8.]..i
[email protected]...'......X.d.g.<...&......5.@}......`/..z..OSua..
.....y...@..=NMDU.|..:......*F}.z,. dJ.%..'ooJ7..I..q.B.......H.#.....
h...X.e..9...y./..V:..H.#...1]...Gry.g..\..o;..\.=.E..?%.....v0....=x.
[email protected];.]...K......3......S{....1"....P[...O.f.e.........I........
.9..=j..W8........>.qQf..&...g.8...9,y=.2W.u...."9.Q.....!.bx....3.
..T.i..9...x...|.....jVu}........6..x...F.*@....$..3n.d...DM.?1.1X

<<< skipped >>>

GET /upload/vod/2016-04-6/2016461625537987.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:20 GMT
Content-Type: image/jpeg
Content-Length: 91698
Connection: keep-alive
Set-Cookie: __cfduid=d88aa9f20f043433607df4e7b3962b86f1464044420; expires=Tue, 23-May-17 23:00:20 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 06 Apr 2016 08:02:55 GMT
ETag: "4afcd5b9da8fd11:314"
CF-Cache-Status: HIT
Expires: Tue, 24 May 2016 03:00:20 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f9c969e0a54-ARN
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?....../\
.<b.z..KX...Y-"x..e.p....n?!B.U#..'.{.x.E.?...%.E.[m?....&....f.b&g
t;q..m{;g......cEp.b..6n....E.R...u3.X..........y..,$n\......?5r.v....
.G....ms`..<.....a'...8.T..R......O~M.]?.C.........<o.^........7
......k.|..7S.x'......2.#..Ee......;.r...Y.fo.(G.#..m......l:.....n.;G
.1......Z;.h..i...yJ..?...y.=.Cm...a....Y.u.d..Z.Jw..{Z.......... ...y
e../`...8.{.N6......f|.E}.......#.........S...=.............`..V......
..'........>K}V.*.y..........>1..U.*.\[Qz.V......5.}E...H.`g...c
8.U".j.rr.9BiE.{J- =tkt|.Eh.... .G..|/..2KK.G.<.u.d.G..A.pA.v....}?
._.u=..S.....sn *<..Q6.0;F.....s....0O.R_.I;.tv.V.t|.U...s..&....i.
..%..(.7...k.J.n..<...[.?...t}..T.|M.q...4...b..$N....eW.8b{s..?...
>8.{........jzz\K.6..B.....W... X.o..-.~.{......>.x.,...W...s...
qRPmKg.I/.c.. .?ho.kC.7....'_..F...3s......Ux."..9..c5.|..%k...P.U.o..
.".>.[=9.b.\.B3..W....c...Q....k..o.-/g{..m.v..>g....e.U...E

<<< skipped >>>

GET /upload/vod/2016-04-6/20164613211592031.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:21 GMT
Content-Type: image/png
Content-Length: 128409
Connection: keep-alive
Set-Cookie: __cfduid=d88aa9f20f043433607df4e7b3962b86f1464044420; expires=Tue, 23-May-17 23:00:20 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 06 Apr 2016 05:21:15 GMT
ETag: "4ca98724c48fd11:314"
CF-Cache-Status: EXPIRED
Expires: Tue, 24 May 2016 03:00:21 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f9d96b40a54-ARN
.PNG........IHDR.......B.....W`W.....bKGD..............pHYs.......... 
.... .IDATx...i.e.u...............F.l....... M..%.!%*.-:."*...b)*))G..
).I..;%[rI.W...hQ.i..I..(..@.$. .4...7.{.9{.......{..T..)......s..g.5|
.[k.Gg.........fff...|...._G.......&.uDPmR..d....;...a.V.7..X;......Ll
[email protected]''..n.x.U.&.....p.t.-...^.WD.......wwfn...L.D.ws.Lx...
......0.....}.J..>..O... ... .........f.N..........@$......y..*..f.
D..n."..;.........'Rf.y.c.CYfL..0.;.QtT......j.h.juS.Zcf..9...w.>.@
...;[email protected].... ...E....2.:(...d...
L......`[email protected]...'........O..[.v...^....~`!?.Z~..f.....=crPd..
..G..l.gQw.J..&.{#...v..4.tf:N'g.1.Z..... ....IU.HU.L.....`a....)c..'.
.H.>i..9...sL......`6........R....A.T.i.(.Q.\i.;.......v.v.........
...m.a....!`....b.n.d;..."Q..HB...4.O..8.I.....".S MD.fp..;.J...=....R
...Ywo.Uw..x..VU"[email protected].."...G..L.[....eyh.-.B..7HjI$......
AL..\.AA4.......@D..;..z...9.9.....j.dDj..A8.38.......s.......{.<..
..G/..C.Meb..Y.9.Q..( . <.Dq..u.;=...].....9....E...f.e:...9.3....
..1F.H.X.p7.d......5I{..gt.....i..|*...{g.................C)DD.C.K`...
.%...J.".9..*...............x....V7j.U.....D".y.Ig..}.O.w".....Hh"..[.
v...H.X.Z.Fp.[..!..1*.g....|[email protected](}u..." g.....
2....4M...;'.%........%....ew. ."....._.f...&MB.F.n.......VDrb.. `D..&
gt;.>...u!..c4S.."sc..J......E..'.%.K7$....JF.pr.tq.4.x.4..:....b..
......k ..D.i.U......YuO..e.h..\...Q......../...~..jQ^...8.s..[.a.x...
.1sY ..;.......)X.j.L ..$E..F.0...,..*7....a..c"a.s)Y` .2..}Y-.(..

<<< skipped >>>

GET /upload/vod/2016-04-6/201646931670541.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:22 GMT
Content-Type: image/jpeg
Content-Length: 171070
Connection: keep-alive
Set-Cookie: __cfduid=dd53fd73fd2a67346231b153ccc27afcb1464044422; expires=Tue, 23-May-17 23:00:22 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 06 Apr 2016 01:03:16 GMT
ETag: "5c7b1a1aa08fd11:314"
CF-Cache-Status: EXPIRED
Expires: Tue, 24 May 2016 03:00:22 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1fa637a70a54-ARN
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?........
..(.w....._.<.{.....4..hz|-%....%.(.g.......$..5.7....9......B.U.N.
....I...h....'#..;Q.:.c...p....&...O.........f.>$|K.G.O.^..... ....
..q3u8..ug8.Q.5...7....&...CC...$i._..G6....Y....l..kkj.V...j).I._....
..S..(..)...K.l.&..X.....me.F.......F...M.C0.1..6.*<..}.....-w.....
...]O.f....S...D....K.B)..~c..hP......J..5~%x....n|o.h..-.".4O#...T.w|
.d.....!Gm.......zMv?.Kyu.K..K...xEiX.H..q^.'..u..^%....>2.......6.
i....>SH...i.......<u(.........../..A....`:....kV..0z.2.s..v..=*
[email protected].....=.O...i-.."u.K..VU...C.)............{x
...."K&0C"-.bb........W....r....Lk....dw...........".....&..d.P2..s..l
.....>=...'...&.. ....L....`$.U..s.G95...T..Qi.'[email protected].[..I
.n...v...'o.....(I...5c...7..1...]F......VQq.G..#..d...g....W...W...7.
6......-....3.>.sk./.Z...b...._ ...9.......Z.<.oi,#M..8......3.;
aPw.3....u.~...h..[j.....E.V.c....Z.B. *1dT|.....`..U .t/.Tz.O.K..

<<< skipped >>>

GET /sp96/2013/05/18/17072340777.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img32.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:12 GMT
Date: Sun, 01 May 2016 12:54:12 GMT
Server: PPWS/2.1.1
Content-Type: image/jpeg
Content-Length: 5517
Last-Modified: Sat, 18 May 2013 09:07:23 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-147-2 ( [uScHs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:8106 (Cdn Cache Server V2.0), 1.1 lsh196:80 (Cdn Cache Server V2.0), 1.1 fra21:3 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), qu
ality = 85....C..............................................!........
."$".$.......C........................................................
.................`..".................................................
...........}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
......................................................................
.................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*
56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz................................
....................................................?....5g..e.u..cw.D
K..b.m..;......n...zm......$#...%.......J..?..Y..............Z....#...
.K........K.r.0Xe6.v.......R...[d.n..K|,j........nW.9=}....S...L..-..V
...{.......HK.#...*.....<.r.3.V.z7...........9L....9...q.]...Z..A.Q
.....S.[xU...d$.Em*\.]...T...n....wz.U.k.o.....n#.Y.......$0%}.bx._...
7}w.n.6l.....(..*3m...%.s......:.'..b. A..b.....d.d...T.....f.O......q
$.HY.........|..H|L[.v...D{l...w1..0...V........O]O9..._..s.\Oqww;.H.q
f....}..9x.P..D.>.z$..n<...2.X|..`C........h...].......;..2Kc..z
...=....m.U...c...y..r..d.99..Yb.Pmt:.AI....W.&.l.....b..N...y...X..;g
..F.../.........3$/..d....s.hi:..o..s...,.y..$ |....q.5...v;....U.B!e@
....Fv...c8.)SR.....1...kc..".D..$....Kp....,.8.=s.k.|!.....n..h.m.E..
d l.......|...K...>!..#.&!4......A.7.8.j..=ND...X...,..6..?...W.. .
....:jN.r.R...|M..{....A&.?t`..i|1....:.?b...N6..r.=k..(.w.k.....;

<<< skipped >>>

GET /pic/uploadimg/2014-6/6364.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:38 GMT
Content-Length: 16834
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-6/6364.jpg
Last-Modified: Fri, 20 Jun 2014 07:00:09 GMT
Accept-Ranges: bytes
ETag: "b89e5f46558ccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....d.d......Ducky.......2......Adobe.d....................
.......................................#"""#''''''''''................
..................................!! !!''''''''''......3....".........
......................................................................
.....!..1AQ"..aq.2.B....R#.br.3......Cc$4..S5..e......................
!1.A.Qa."q2........BR34.br....C5............?....VFlg.D.y.6.f..>F..
.k..2!(.r...?...Q.Ym...:Q..`..3..|/^B.g-GA....VP.[...........LK.......
|>.U..P=.iH.\...<.~..y..f..5....Y>h*...n...0E.&...r..q.......
G.C....6..u.gv.w.m....7= Y..K y..u.J.g..C.y......j.Mb.2AfX..........{.
`T.(....RO..r.h..]tQk.......y:\.....8m{.......@..._._.B....l......VAga
.w..[Y.....$..W...7...bJ.i..6...P0. ..m....]..w.o..*:..N.....$A......2
..O.{.....|. ......'...N.mR~T..7..V.q...o....#...~7?...2...p6M...1^...
6;.\..LOm,b.-...*........#..i..RjU.......l.......V. .a..;....../.|A.9r
..J.YN....G...K.z.X..H......jf.{Cb......d;...c.A.G.....I.P0.W.........
....V..5....c.w.......|h....CL.......s7.q5.........0....<L.I..H.BN.
w:W....X.{..E4.v........u.IQ...WZ...oRa....~....F7A..,..p...!.H....&.5
:...s.X.. 0.</C........Z9qL.#o 6. 'i..p...R.... x.G .G.3.../.R...J.
...<..?/Aq..C'..\.?.....C.S.4..k..".&...)....Sav=..U..7%......I .._
[email protected]{....}.M.....g.......C.....o...$...I?.....G.B.....-
...&<..... ..|..*<.=.^MX.j..&....x..k.w......j21i..'....d.VY#...
t......k*.Sk...........\~o..M.7*G..:..L...H...I.Q{..T../..^.s`<C...
..H<.j.....Z...s.....{}j..d..0.....ca....L|s?....Pj..is...UA...

<<< skipped >>>

GET /pic/uploadimg/2014-6/6372.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:40 GMT
Content-Length: 7520
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-6/6372.jpg
Last-Modified: Fri, 20 Jun 2014 07:12:10 GMT
Accept-Ranges: bytes
ETag: "edeb14f4568ccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222...........".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?..8..
...T......9."....u.M...4...G..X..).U............D..w7a..4 .U....<V.
...SJ.a..K..K.].FL.V8.....=*..<1..[^6z^.k..0$yr..,c [email protected] ...
0h.EX.....4..Q`.J.G.Ro..`..=.4;...E;....sN.*(OZ.t.`/z...M..........O].
..........5..p....f...I......*.X..,.'..u.H.~......lZ q........O....=..
..f.[... h\.I9<..5..f_)[email protected].),..E.8(pF....p1
..oaia,.F. ..q..9|o.o.xj.....x.R.5mM.a,[email protected]...........}{
.kW..&/c....\..I.._;.`. .p.<..KO.1.xz8.xb....6L.$R.2.f%..F..@.. .t4
..<C.....x.....O....p..gs7.NI.I.q.y....}KS......{ws!Yl.-.6(..-....[
.8..B..D..)[email protected]*:s..M.@......{.......C.E.....%.A%....%W...s..|L.
..?...J*..j........'.T....%.;2H......A.H)1.....3@?/...5...%s.f...:.nE.
....]...#.v......5K....fs.`.u..q.....8.t....m.#......[[)T.\.........I.
.........&7.d...o.ME.N. ...zW..i!S.S.....[A........r$..PZ..,..W..X..$.
.s...Q.y....b..<.w..V{h...x.i...vl`...2........>.V.......Ea.

<<< skipped >>>

GET /pic/uploadimg/2014-6/6349.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:40 GMT
Content-Length: 9514
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-6/6349.jpg
Last-Modified: Fri, 20 Jun 2014 07:00:14 GMT
Accept-Ranges: bytes
ETag: "b495fd48558ccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......tencent-youtu....C..............................................
......................C...............................................
............................."........................................
.A..........................!.1."AQ.aq..2..#B...3R...$r....Cb.........
.......?...V..E.....h8.<..}......|D...a9....}.Mt.....\O..;->."*3
t.....kxuXB..J=.....M.d:.1..}{...&[.w. .>L..................{.}...l
..R.....*......B.'J.[W..%@r......)|.R.Uy...6.....)...#.z...|'jk..gVF..
.f.oL.V....h.#?.S.\&#...A#iV..B.._S9.Q.>...(.d.....o...i.w9s..t"..F
..$~'..%.2Id%...T...I.FR7'.....t. .......M[...%.R.S.{*N....`....;...V.
E...T..i... *.|S$wT3.....U.{.F..j;E.d. ..Z.z}*[email protected].)%!Cm
K....{......M..A.=.)..q,.....x[.PYZ.#%#)..B...%D.w$......-.V.l`4.....~
l....*...k.aF...p..b..h.t..^x.(e..S{..J.Cj.i#<..!.W|<j}.h..;..2.
.....[f`S.8.S......)..#r.p.....Oj..4.........?C.K......o#..X>....F_
MeZ.....n...8...N.^.[.....E).....*........$..W. .W....(WetS..SRt.K....
....|.\"......DC.....Q;...U..\nRg#...Ci.u.x.z......V.qk.j..<.;U.V..
c...Q.........[|2./7..3q\i-.T%.6R..;[RV.8h([email protected]{...k.i..40.yim
......S.)!...b......A!.B.Cu.G......Y.>.....e..I.;.}....-...$...p.R.
.*..Qtp.3....J#..z....L.gX....D.d.#;%...,I....mR.o.m..8.Xp...#....(.R3
.q.hP.R....@.. ..4.9..XvAm.4(P..3.C.6..H![.q......H`./.*..R.3I.i.R....
B..P.L...?<b....g&."...Z..g..nKHP)u....mGvHJ.P3.>^.U&..n...... f
[email protected]../o.............Q....5q.$]5%..:.X..Q.....d)*......'!jW$.
.....}A.A]........t~...Loti.X[..D..R.TH.y>.O..40..A...........[

<<< skipped >>>

GET /pic/uploadimg/2014-6/6354.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:41 GMT
Content-Length: 6864
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-6/6354.jpg
Last-Modified: Fri, 20 Jun 2014 07:00:15 GMT
Accept-Ranges: bytes
ETag: "e8408a49558ccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222...........".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?....R
`S.K.Wm.(.&.k....VG.r;.u.l$..i....0x.Z.(.d....).....2. ..].B.j........
.......dc-.8...`...Zf$$.-r......./.....N..#7.f......~..i#.-e.J.6.....0
q.i.I.l^:|........p.Jj.....Z4./.0 ..:.Q6.k.P..b.!x.O9...6.....*.4....~
.i..Fc...&.C.U..........@e(cp..w....?.B.<..."..0.b.aRI(........b..v
..,0.. .'?.I..b.I.( ..~.V...I..'..*h.Q.O.......&.......T..;....o].*.Z.
..$Lf..W.Y...cj...B=..WAoe.e.D........Uh..F,......v.3.<.3.......Y`.
y.. X .(cB....*[email protected]@.N.......E&K...... .. #....Z.8..
)1K.j..6..:..).V...H....I..1.0...i.D.FE ..)..r,.9........X.eF..R..noZ.
...V.'.7...s.....}*.7>P..?.rN-..9.n.M.....UE.\...9..^...l:....f.i#;
W....d..sEej...............#.(4c.Z.8.....jN.....ZJ.JLS..&).V..i....U&"
<RS..B)....)..aM..iE2K.(.`.R.....2.3.z.....-L.7m.vj...X.y..q.Tv/.T`
..G./.\.....EC$.%.[o8.(. .3z......^..X. Y:.....-......q....q...'r.Zv.,
..3$....>.j#}l.'...`.OQ.aZ..w.X,.1.......J.Y....1...Y..,W......

<<< skipped >>>

GET /pic/uploadimg/2014-6/6344.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:41 GMT
Content-Length: 12130
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-6/6344.jpg
Last-Modified: Fri, 20 Jun 2014 07:00:13 GMT
Accept-Ranges: bytes
ETag: "94117848558ccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF..............Exif..II*.................hXXp://ns.adobe.com/
xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> &
lt;x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060
61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="ht
tp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf
:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="h
ttp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.ad
obe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:9F28FE7083DCE2118E
A7AB1C433B9158" xmpMM:DocumentID="xmp.did:C9F6AF1B265D11E3A633D42CEC5D
1AD4" xmpMM:InstanceID="xmp.iid:C9F6AF1A265D11E3A633D42CEC5D1AD4" xmp:
CreatorTool="Adobe Photoshop CS5 (12.0x20100115 [20100115.m.998 2010/0
1/15:02:00:00 cutoff; m branch]) Windows"> <xmpMM:DerivedFrom s
tRef:instanceID="xmp.iid:9F28FE7083DCE2118EA7AB1C433B9158" stRef:docum
entID="xmp.did:9F28FE7083DCE2118EA7AB1C433B9158"/> </rdf:Descrip
tion> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
...C..............................................!........."$".$.....
..C...................................................................
..................................................S...................
.......!1.A.Qa..."27Rq....#Ust..B.....n...$34Cbru....&5ce...........
........................6........................!..14AQaq.."R......2.
#$3..Bb............?..|<......Eby5....K..sE).w...GK. .........L..;.
m..%....}J....c.)..J..WO.|.`_R.....H.....U.._1X...|i...)..G.Ut...V

<<< skipped >>>

GET /mini/portal/111205/images/build/v_09151721/imgLogo.gif HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:13 GMT
Date: Sun, 01 May 2016 12:54:13 GMT
Server: PPWS/1.1.4
Content-Type: image/gif
Content-Length: 295
Last-Modified: Mon, 19 Dec 2011 08:26:54 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-117-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8105 (Cdn Cache Server V2.0), 1.1 lsh196:8104 (Cdn Cache Server V2.0), 1.1 fra17:2 (Cdn Cache Server V2.0)
Connection: keep-alive
GIF89a6..................!!!.........!.......,....6........#.c.)..3...
..V}...".B...aS.t.U.W.$.....U...6E...x0....#B...Mv.I?..s..>...3Z!@.
2g6M.,..b......ikU1~..X}|p.n8.;G.&..|{,:J d&.TeK..nv.PLi........PQ..Ix
yr.C.>....rY.n...n..........,w.................J.<=...z.......-.
a.W.....I6..0...q..-H..;HTTP/1.1 200 OK..Expires: Sat, 30 Jul 2016 12:
54:13 GMT..Date: Sun, 01 May 2016 12:54:13 GMT..Server: PPWS/1.1.4..Co
ntent-Type: image/gif..Content-Length: 295..Last-Modified: Mon, 19 Dec
2011 08:26:54 GMT..Cache-Control: max-age=7776000..Via: http/1.1 shnj
-b-ats-157-117-2 ( [uScRs f p eN:t cCHi p s ])..Age: 1..X-Via: 1.1 dxi
n239:8105 (Cdn Cache Server V2.0), 1.1 lsh196:8104 (Cdn Cache Server V
2.0), 1.1 fra17:2 (Cdn Cache Server V2.0)..Connection: keep-alive..GIF
89a6..................!!!.........!.......,....6........#.c.)..3.....V
}...".B...aS.t.U.W.$.....U...6E...x0....#B...Mv.I?..s..>[email protected]
M.,..b......ikU1~..X}|p.n8.;G.&..|{,:J d&.TeK..nv.PLi........PQ..Ixyr.
C.>....rY.n...n..........,w.................J.<=...z.......-.a.W
.....I6..0...q..-H..;..

<<< skipped >>>

GET /getcitycode HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: iptable.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:04 GMT
Content-Length: 4
Connection: keep-alive
1121HTTP/1.1 200 OK..Date: Mon, 23 May 2016 23:00:04 GMT..Content-Leng
th: 4..Connection: keep-alive..1121..


GET /template/4567/images/g.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:33 GMT
Content-Length: 1887
Content-Type: image/gif
Content-Location: hXXp://VVV.3929.cn/template/4567/images/g.gif
Last-Modified: Thu, 19 Jun 2014 05:14:52 GMT
Accept-Ranges: bytes
ETag: "7b91ad667d8bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
GIF89a................................................................
......................................................................
....................................................................}.
.............}.....s..z..f..i..c..[..c.....g.._..S..Z..Z..Y..]..J..R..
[email protected]........<...........?..P...........L..;..:...
.....3..1.....L...gr2..*..0..)..............6..3..!........Jt..~.....O
`9t..{..N^.?D.t..r.yO..2;.\..Z..\.....................................
......................................................................
......................................................................
......................................................................
......................................................................
..............!.......,............... `.....JZ.P`..3...AbAB..-D......
..b.. [email protected][email protected]...!.@.:t.|...O. ...h4!../w... ...1g4..Bf
N.UeZ0``...$.6..C.....jP:....Ag....eB..,...q._.>..8.8....#K.L.....3
k....g..B..M..F..0.&}....(V.n..6..$4,`.......?...Dp.$./.......VH..B.i.
.4...........^.."..!...........]......Q`x......MG][email protected].^..=.`. h .
[email protected]... .(..$.h..(z...,.hY..^....h.c.8....<..#.tD.Y$^....E
....FZ...P..$e.....SNV..Yj...]z..dA.h..h....l....p.)'e).i..)).'.A.0..z
.I..H(!..w....g....Z$.R...1..)%aG....(.Y..H. ....W4.A....A.T....#..1F.
-|..Y.... ....!..@.........`...,[email protected].@.".X..#G.G....j..`.....9..!
.`.a{.......I...\..............a$..g4.....a.F.Clq.......w.F...0P......
5.Q..*plr.D..q.2o...vT0.......v`........GW...*.-4.xT........O....U

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:33 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /pptv/ic/all/self_all.ini HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: up.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:18 GMT
Content-Type: text/plain
Content-Length: 13806
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Fri, 08 Apr 2016 20:42:40 GMT
Expires: Tue, 24 May 2016 01:26:17 GMT
Cache-Control: max-age=18000
Accept-Ranges: bytes
Age: 16573
Via: http/1.1 nb-b-ats-190-67-2 ( [uIcRs f p eN:t cCNi p s ]), http/1.1 bjzw-t-ats-1-15-1 (ApacheTrafficServer/4.2.3 [uScRs f p eN:t cCHi p s ])
Vary: Accept-Encoding
[Full]..ModuleList=player\oplayer.ocx,%commondir%\PPLiveNetwork\kernel
\peer.dll,%commondir%\PPLiveNetwork\logclient.dll,%commondir%\PPLiveNe
twork\tipsdone.dll,%commondir%\PPLiveNetwork\tipsstatistic.dll,player\
avcvideodec.ax,pprepair.dll,packet,admodule.dll,uilib.dll,productupdat
e.dll,troubleshooter.dll..ModuleList2=player\oplayer.ocx,components\pp
frame.dll,player\avcvideodec.ax,pprepair.dll,%commonversiondir%\kernel
\fwupnp.dll,%commonversiondir%\logclient.dll,%commonversiondir%\tipsdo
ne.dll,%commonversiondir%\kernel\peer.dll,%commonversiondir%\tipsclien
t.dll,components\ppdlna.dll,components\filepick.dll,player\vsfilter.dl
l,player\realmediasplitter.ax,packet,admodule.dll,uilib.dll,productupd
ate.dll,components\nclist.dll,%commonversiondir%\mngmodule.dll,%common
versiondir%\tipsflash.dll,troubleshooter.dll,%commonversiondir%\bubble
ctrl.dll..ProtocolType=1..UpdateDate=201604071128..[player\oplayer.ocx
]..SectionCount=1..[player\oplayer.ocx0]..Ratio=100..UseP2P=1..rid=763
260D47D097C24B311BEF67034347A&filelength=1732432&blocknum=1&blocksize=
2097152&blockmd5=41EAC7DD01EB1ADBAED345BE53CE4D1A..min=3.5.6.0062..max
=3.5.6.0095..Version=3.5.6.0095..FileCount=1..File0=hXXp://download.pp
live.com/oplayer/3.5.6.0095/oplayer_3.5.6.0095.ocx..[components\ppfram
e.dll]..SectionCount=1..[components\ppframe.dll0]..Ratio=100..UseP2P=1
..rid=05424559226B1F8113825C672BAD2C0E&filelength=789840&blocknum=1&bl
ocksize=2097152&blockmd5=8A00D6CC02C5D8DB7011CF92DCBC6E55..min=3.1.8.6
061..max=3.1.8.6070..Version=3.1.8.6070..FileCount=1..File0=http:/

<<< skipped >>>

GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:41 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /config/pptv/qd-all-slient-open-nlaunch-nscreen/forqd340/bind_en-us.ini HTTP/1.1
User-Agent: NSIS_InetLoad (Mozilla)
Host: ins.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:00 GMT
Content-Type: text/plain; charset=gb2312
Content-Length: 80
Connection: keep-alive
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
[Bind]..PageCount=0..ForceCount=0..PopupPage=..IsStart=1..IsStartWithW
indows=1..HTTP/1.1 200 OK..Date: Mon, 23 May 2016 23:00:00 GMT..Conten
t-Type: text/plain; charset=gb2312..Content-Length: 80..Connection: ke
ep-alive..X-Powered-By: ASP.NET..X-AspNet-Version: 2.0.50727..Cache-Co
ntrol: private..[Bind]..PageCount=0..ForceCount=0..PopupPage=..IsStart
=1..IsStartWithWindows=1....


GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:28 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /beacon.js HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: b.scorecardresearch.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Expires: Mon, 06 Jun 2016 23:00:13 GMT
Date: Mon, 23 May 2016 23:00:13 GMT
Content-Length: 901
Connection: keep-alive
Cache-Control: private, no-transform, max-age=1209600
..........mT.k.6..W.e.....t.........F..}.&(..k.%#.. u..];N[x.`,...9.9*
;..m.. .].0...t3C...9.N.....][email protected] [email protected]}.,.;...}p...%A..!T.%]/.
.`.9....`.....<b..z.E....!Q&.....po........e.R]Fzk...x%J..#-. ....!
...6Tle..o.......1;7a.....S.w..d4f.,jc.mB.T.......,..z..!..1..~.1.J:..
...csI.J.....~...8:.1.`....{uI ..<?./.j...b..Z.......u.}{.k,.m.;U*.
.....]9...R%..L.&5PXb...Hj....J...ES.>[email protected].......
......G....*[.....~.q..5......k..>.....X.....".....;.\..0.....^..R.
P1...^t..q$k.|.....c7...d.Z..V.:.^j....Gb...`...W........#.....Y?.....
.yX.....6C..Yb..].....l=.f........A..9L...ab.f.....[.eT.....q... .k..4
...t5P.....0*..e.....T..I%.........eR..}.1..eB&...;.......[G.3.......s
.......bL.~0....cXX..m..l...uv)'.q..D...B.....{.].WO...zp....C.U..a...
....{.J2j ..p. .....f....5....w...?V...':?1..../..J..?.........%.N.0av
.sH..K...|{&.i...=.>..qmr........b.;..;(......5...R@ocv...[..)...1.
.p....
....



GET /b?c1=2&c2=9288713&c4=2&ns__t=1464044415657&ns_c=windows-1252&ns_if=1&cv=3.1&c8=_PPLive&c7=http://client-mini.pptv.com/portal/12345.html&c9= HTTP/1.1

Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: b.scorecardresearch.com
Connection: Keep-Alive


HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: hXXp://b.scorecardresearch.com/b2?c1=2&c2=9288713&c4=2&ns__t=1464044415657&ns_c=windows-1252&ns_if=1&cv=3.1&c8=_PPLive&c7=http://client-mini.pptv.com/portal/12345.html&c9=
Date: Mon, 23 May 2016 23:00:13 GMT
Connection: keep-alive
Set-Cookie: UID=13721230a134164502915281464044413; expires=Sun, 13-May-2018 23:00:13 GMT; path=/; domain=.scorecardresearch.com
Set-Cookie: UIDR=1464044413; expires=Sun, 13-May-2018 23:00:13 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
....



GET /b2?c1=2&c2=9288713&c4=2&ns__t=1464044415657&ns_c=windows-1252&ns_if=1&cv=3.1&c8=_PPLive&c7=http://client-mini.pptv.com/portal/12345.html&c9= HTTP/1.1

Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: b.scorecardresearch.com
Connection: Keep-Alive
Cookie: UID=13721230a134164502915281464044413; UIDR=1464044413


HTTP/1.1 204 No Content
Content-Length: 0
Date: Mon, 23 May 2016 23:00:13 GMT
Connection: keep-alive
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
HTTP/1.1 204 No Content..Content-Length: 0..Date: Mon, 23 May 2016 23:
00:13 GMT..Connection: keep-alive..Pragma: no-cache..Expires: Mon, 01
Jan 1990 00:00:00 GMT..Cache-Control: private, no-cache, no-cache=Set-
Cookie, no-store, proxy-revalidate..


GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:40 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /pic/uploadimg/2014-6/4899.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:19 GMT
Content-Length: 159410
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-6/4899.jpg
Last-Modified: Fri, 20 Jun 2014 05:32:07 GMT
Accept-Ranges: bytes
ETag: "70d58fa488ccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..j.....
.{.....n`Nz.t.......M.E...5...U.....}S....%.u.......s.....Z.mR.G...<
;....,..a.......:.9me...^..Wq%...J)....*O...._.*w. .O...z......k.8..&l
t;.l....!.|.Wr..F=G=k._....}'O.|9..$...T..E.!........`|.......M.?..gL.
...i. kmb.r..<..T...7d...j*7)(.}...b.-..|/...U.M..M.x..V...........
...........T...../m. ......O...{.E....x. .........>".....S.%.....|.
._.. .#.... .vc...h_.L?....i....m..........t...\1,....8b...#...w..V..O
..~.v..?...h..j.S...O..........*..U.yf..<..<..........A.@i...$.y
..<{...z....."...=.....|.....=/@."g.~..-c...S.4....?1l..NI......`..
.\[email protected]....<..v..Q...^.Y.Q.K...W.eq%.Q..
.f?#..5...|~...R..~#.n.....5H.$..rI........ .-..~.....G.>.x...`2F..
.......8......?........Sx..u.......c.M....E...h.M.../d.........W.=.m~O
....,..2...{j.'.|.f......s.o......>.....H.%....U..;O.C.<.~.z....
..x[..>..G.<S....#..h^.d........I?.......E.....7...)...\.>

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:26 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /upload/vod/2016-04-6/20164618361516790.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:17 GMT
Content-Type: image/jpeg
Content-Length: 15984
Connection: keep-alive
Set-Cookie: __cfduid=d581b0b8cd547e41a8f83eadd6b2cf3811464044417; expires=Tue, 23-May-17 23:00:17 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 06 Apr 2016 10:36:15 GMT
ETag: "b8955725f08fd11:314"
CF-Cache-Status: HIT
Expires: Tue, 24 May 2016 03:00:17 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f89dc2216dc-ARN
......JFIF.....`.`.....C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......(....".....................................
.........................................am...7b.@.%...)..2.......uy.m
q..v....49u....._.Zb..k.....Ji..!~.}-.yMYp... ..~...S.....c]!......B..
..."...r.@#.....EI|b2i.Uk.4sMRL!.E..D........ ...5.4.....<J.3.Q....
,.HR..}.C.j...;u=.-D...J..?6*.A.m..3?M'y-E._.08h.8...w.N...e1'_.. ...9
......R...:..8..<.l....Q..7.3.....'g.\\..].R..k.F4../Kc.._..4GRF.b.
.V...l nF..=.3.<..;GB..L........z......W;KP..v.....<U.\..b.?....
K.."np......h..w.}uR.. ..V.*a.F.=0\."..|O.X.[J.s'].L...FS.K...<.3.
.t...{H5.V.qK.s...,.'A....g.....|.$.&C..."....7_?0..78..v/..)..$..?..o
.D.. gT.......'.,.z.H..!.k[(....)..B.,G...#......xTS...>c..F..0....
f.N...T.....!.....oZ..z.$h..1........_.6.....?.....[.\....Y='"....j...
PK.iy5a...R........h.....Y...S.5..tVP......}..qXD.-.R.P.!T,....yA.i...
y.....j](...=6.W..,.2..X;K.6v..5o...r.L".O9.S.WA..h.....E...:....1....
$..%..b.....K....'.....2..i,%..$r...g..G...9<.m..To:.}LGL.....(k!.4
{.02).f.]...m..4).y.kK.)......=..xO6...l....1...K.q.Cu..'. y$...W6D.D.
....=.....\=[........Z../.Q$.]sv.9.R\......;I..].. dm9...h,...U\uGM..4
...!R-.rX.t.VZT.7.k...U5 r.\.6.IC.7..9..,IrE.bM$.....*................
............!"1 #$2.AB.0..........|..=.T\..o...rg....dOy.=.TL...%.....
..{|..1......-.,.TWu...l...8.......<.j%*h..fn5.8.q-....QB.*..2*R.x.
Wu...M^_....&..Y..#Xu...............J.i..3... ]..J..S."#*5...cd...

<<< skipped >>>

GET /upload/vod/2016-04-6/20164611133711460.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:18 GMT
Content-Type: image/jpeg
Content-Length: 166052
Connection: keep-alive
Set-Cookie: __cfduid=d581b0b8cd547e41a8f83eadd6b2cf3811464044417; expires=Tue, 23-May-17 23:00:17 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 06 Apr 2016 03:13:37 GMT
ETag: "f0fea64fb28fd11:314"
CF-Cache-Status: REVALIDATED
Expires: Tue, 24 May 2016 03:00:18 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f8a9c2716dc-ARN
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?.....$.y
`..h.............2..E.......*}...Df(.8 [email protected]&0#2n..d.....
.....|....5....B.n.......[..H...|.98...<W..Z..~.|......[O..z'....3.
..x..Lh8...nr.....~...|X...o5 ..i....)-...Oy..?v....8.qP...5.....-x.MV
{Su.}.fo1.m..>...^......U...u?.......z8.<....~K....V........,.W
N.|ec~.W-*.y...2.BT..#=~l.......!x.\........4..R..HW..U..F..g.........
P..~..k.{@&2...fa..w$g....^.._...........R....1.!..6N....p.....T.Y.%..
.Z.p.T...g......| ........c.........q..g..c..... ...7....u.`.w.....F..
.A.c....P....m.S..>..[.5...-...`.w....uA.......qZ...9"...\.Y...n..
.y..k...SN....8...m..#....'..g....u.m..nA..a.K..\...y..\.......|G....T
.}...6..7...Y ...;...Mu..[U.5.z...qp.h..n..7.PG...................q..$
[email protected]*.&..g.x.......]...Qg......X.2....rzr8.^4...}.T
...~,.;.4....I..............M}.xG.^..4.GU.g.R..N..W{....`...'.....`x_.
...[K..:...V.k...S.7?............v.[...;j.....*[i..{.-.........s..

<<< skipped >>>

GET /upload/vod/2016-04-4/2016442312891676.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:18 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=d9646d8eb0cf7a79fa85dcea8c92a92841464044418; expires=Tue, 23-May-17 23:00:18 GMT; path=/; domain=.677dy.com; HttpOnly
CF-Cache-Status: EXPIRED
Server: yunjiasu-nginx
CF-RAY: 2a7c1f8e8c3416dc-ARN
Content-Encoding: gzip
3be............}T]O.Y..'.?..E..r..IK........Nw.%..3[`....i....).7 .S.D
.L...,"vM.d7..f.i..b.6.....{sr.}..9..5.5..1fz.....'..?.t..b..... .1..`
6.I........[ ......A.. s....1........M.z..#ij.>b.)..8...6..n*.t...`
...Q.vf..3.....}[email protected]...).!....a..}n..v....s}O6...
..wl..1..}..n..$M~.j..;.......#...%l.....G.=... zD..$.}.<........%.
........a.BX$M1#.N;..n.[o..`F...d5...x.~. .......{4..h.N..x.Jey.......
.n.e....D.}...n.\....8....K.....j,. T.J!..IX..^.K...f..<..NG.R.....
|z.......R,.u.Uy.N....F........lQ...f2[O.T..g...V;........fN.....$.YM.
... ....Z.T?n&.....=L.y].o.V..E^.G...ii=]......9L.U.I.I)..%n.J|.z.....
G.^. Q.7...... Ag..5......'8...f../f...{i.&..(H.kG.l4.!....r.j........
..D;|..|.../...'...8.S...M.g5^^...=.......D.\k.6~.,..W ..U.."........J
[email protected]... .E..>...&y.H.... ~....`Q8.x.O...b.....C.6N....f.}..h...5.
..._t1yX.....)...}.w.#.Jk.` n.Z...>.y..A..L.... /.s.#...k.L......&g
t;S(..'..{.U....*3..vwZ.".w.?..F.Bt....^7......k..KGS............)....
...0..HTTP/1.1 404 Not Found..Date: Mon, 23 May 2016 23:00:18 GMT..Con
tent-Type: text/html..Transfer-Encoding: chunked..Connection: keep-ali
ve..Set-Cookie: __cfduid=d9646d8eb0cf7a79fa85dcea8c92a92841464044418;
expires=Tue, 23-May-17 23:00:18 GMT; path=/; domain=.677dy.com; HttpOn
ly..CF-Cache-Status: EXPIRED..Server: yunjiasu-nginx..CF-RAY: 2a7c1f8e
8c3416dc-ARN..Content-Encoding: gzip..3be............}T]O.Y..'.?..E..r
..IK........Nw.%..3[`....i....).7 .S.D.L...,"vM.d7..f.i..b.6.....{sr.}
..9..5.5..1fz.....'..?.t..b..... .1..`6.I........[ ......A.. s....

<<< skipped >>>

GET /upload/vod/2016-04-6/20164611265812548.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:21 GMT
Content-Type: image/png
Content-Length: 143221
Connection: keep-alive
Set-Cookie: __cfduid=dfcf9a3a0a9f03a364ad4ccc694b100e61464044420; expires=Tue, 23-May-17 23:00:20 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 06 Apr 2016 03:26:58 GMT
ETag: "bc20112db48fd11:314"
CF-Cache-Status: EXPIRED
Expires: Tue, 24 May 2016 03:00:21 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1f9ebc8516dc-ARN
.PNG........IHDR.......U.....WzUV....bKGD..............pHYs.......... 
.... .IDATx...k.%.u...{W.y.w?n.<{H..!)..%R..H.-[T.8....l.q......b(.
..-;. ... .a'.....G..@1cH.$..0"Erf8.Lsz.{..v..=...{..X{..s..H....A...s
N...........v.8=>.."\...>E..w......\..W~...@...... 7}......:...&
gt;9.....( .......C.T..R...\u...........A5}.....b.v.9.....c..g..E'L...
.............S.A~.btq.....;e.....g..\.4o..E.{....^Y..Y.W....$.m.%,.RU.
u......k..]........u..;4{Q...@.(..(c.....E@..*[email protected]!..w.
..k.P...........w..^...^.._.K?z..!..$...z..O.......o..~./B......bv...S
...L7j...p.p..[h...KO...;5........L)...v.s7BD..1.]?A...#~..?........J.
./|ncs.;?.1Q..o|v:.|.......h4:::B.U}...w._...?("...o...........n.x....
...u|tx......P.?.C?t.......8....... /.....3...?....._......-......l:..
../J.........'..c..S.........D\.X......N.Na;,.^......K/...Ip.......f.q
L.80....~....6~..~...O..M......_|.K_.u.[?....(...~.....O=...k.s...g.I9
.~..~............{[email protected]<w.#.....n..=.hH...go.........}.....~o..9
.{..................7~.c.....&...@U..\...5..*..?.........6w9....eD....
..e9..w..........."...E=..h....g............~.s...].~.... W.X.........
..}.....^~...s....?...........kk....{{.<.,.}.7~.C..Ph.w|.w2........
..nUx.}..O}.........S?......o.o..CfZ__..X.Z[[email protected]...>.TUY...p8(K_.
.`P..rP....Ve.]...,..{..qY..,....A.....;W...1..:.H.=;GD...=.3zG.....w.
......P...9]..H..'"".!.*!..5n....b..-..*.h?.^*Y.6...e.3|....v.p.....(.
.o...J..../.D..."..j_@./.d.....e......./4..y%.d..FN{b....6..,.!.._....
k.../...ono5u=.....wml....._.r%....K.........&9.....~....s.[......

<<< skipped >>>

GET /upload/vod/2016-04-6/20164619445529347.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:22 GMT
Content-Type: image/jpeg
Content-Length: 190804
Connection: keep-alive
Set-Cookie: __cfduid=d8f64d6f060c199bd388714b43a5a7c7b1464044422; expires=Tue, 23-May-17 23:00:22 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Wed, 06 Apr 2016 11:44:55 GMT
ETag: "58d733bdf98fd11:314"
CF-Cache-Status: HIT
Expires: Tue, 24 May 2016 03:00:22 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1fa81ca016dc-ARN
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?....cw.&
gt;\..F=Gjd3:'.2...`..a..Q..dy...H...".......P...9..={..)....r..-.J...
=.8..........E<......K.A.^..V?..c......~#..I.M.......duE.....6.Q..W
........cZ...)M..n#.q.]<:M.`....>.0.;HDA..<.....xa.q.jb.^8|%)
(J....7.ogJ.q....')..4..&..5)B....._.....G...b|..5.....?.<X..h...F.
".......n..w.....$W.|~.O.!..r........1....c.i...Kt...LV.R.9.......TyHQ
.......6...~3^.[E...h.<.".....ZS^............ 0...'$b..V.]...N.u._.
..?.<=..5.......<,[email protected]..%.~..xJ.l$j....#.....W~.....
..2..B...R..g....~Io.U.....6...,.{ZJ...r.g5.........t..i......]'....".
...f\HL."@VT?9)*.r ......}.c......R....m.....T:S.vI.j....k`.f9ae....s.
.......9.w....P..9...4.3^.<....P.a.M5.....]. .d{@........ ...;... .
.1....O..2....Kx.@....?.x..9t..n..cC.R.. F.<..d..8.Tj<...J.|.0..
.(....1.Pu..AJMFU...$...N.I$.d.W..G.v.4.;.c......|[email protected]?..&...@..
..o-X.)...9..T.......X|<O..,....O.G.?.j..E4.G.Z.....%..... .s^.

<<< skipped >>>

GET /upload/vod/2015-05-25/201552512203979861.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.677dy.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:22 GMT
Content-Type: image/jpeg
Content-Length: 110581
Connection: keep-alive
Set-Cookie: __cfduid=d8f64d6f060c199bd388714b43a5a7c7b1464044422; expires=Tue, 23-May-17 23:00:22 GMT; path=/; domain=.677dy.com; HttpOnly
Last-Modified: Mon, 25 May 2015 04:20:39 GMT
ETag: "f0bd028a296d01:314"
CF-Cache-Status: REVALIDATED
Expires: Tue, 24 May 2016 03:00:22 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: yunjiasu-nginx
CF-RAY: 2a7c1fa94ca316dc-ARN
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..E.....
.[.....(| ...|G.C.O...MZ.....]Z...o..Y... ...9...0O.<'.el..4..0{..G
....k../.k?.?.&.0<g...p..]....5..R4....F2.....C.N..f.:i...L.._.....
....~....@'.&.O...7..^....?.%......Lb..WV.z.....z....f./..."......vQ..
2OAS.x\.............&....?.........1..M...J./[email protected]] ....._.
.....n.zq..Z...!.\[email protected]....?fE...c..`..n.t....V`.....f..
>.........G...N@..?l...]FIu.........\..&...`.c. ..8..g*ODS.S.QH....
......V_.c...*..MWI....._P'....3;.?....`q...Ns.....b......J.Nzq.v^..m.
....B.s5.....woLs...Y....sx..pv.[......G....?|7..m........e.m?..f.GM_"
;..,/.Q._(...............?.?.U. S.WJ.......?....._...`[email protected]|2.=N&g
t;.k.tK.4.X..g).6.q... ~X..6u.F.....p.F_Q...{.?v........^A....".......
.....9....._...4...".Hc........... .........Q.;;...n..HRz.z`s.....-uK.
.b._.!....Q.1..sQ..'].Oo#....UO................Yb..O.........t$..v3.,.
.u_..%....T.......t....~....<1...{D..TR......z..QjZ.....j..:...

<<< skipped >>>

GET /portal/12345.html HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: client-mini.pptv.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:08 GMT
Content-Type: text/html
Content-Length: 10183
Connection: keep-alive
Vary: Accept-Encoding
Pragma: public
Expires: Mon, 23 May 2016 23:07:40 GMT
Cache-Control: public, max-age=3600
Last-Modified: Mon, 23 May 2016 22:07:40 GMT
Content-Encoding: gzip
Age: 3148
Via: http/1.1 nb-b-ats-190-63-2 ( [uIcRs f p eN:t cCHi p s ]), http/1.1 sh-c-ats-204-53-1 (ApacheTrafficServer/4.2.3 [uScSsSfUpSeN:t cCSi pSs ])
...........}is.W...I.....5.*.....T.0y.3cf`BHH.Z.-[ .%[email protected]..
..1T.?..wK.........%.[....5...V.Y.s..9}.......m..ML.>.d....._ld"...
vac4..m.b...m...p.,[email protected].>.Y......s..i..E..=.=.....aG.
..N3oF6.......S.t. ..N.4z;...M.....) .3xG...L...l..y ..../cE.........Q
,a.c...9 .5..w..&.Z......c.....D,YY....6...z..b.R................3....
'..|"..6.n..9..Z..o.....n.....!........$..N#.M%..h.....q...R4....\46.H
..=...I..sp..$.....X...y....|........r.h. ?.......w.......V...O.1]....
.O.....$.~..3.....].O>\...u^.QZ..#..c}.6.U..^g....~..6.R.... ..<
..;Z<t..<.aH/.....7`......Zh.j..D...R.?...(.DY1... ..$qR..L..u.f
...^..3..oNR.M..t$.c..6l(.Q...(a..z,............A.j`.Z..o...?.fWn.....
.......[.T.......g.i...v..G6..M...jGa..6..82...........?..0)....q.O..0
.`....P..::@p3z..H....e.Wp..9g....]........<..\......T.S./.....3ht^
.......%u.@.>....l.f.Z{..$..Y...4.T4e..I ....i Z.`.....p..4m"H..3.;
.?........D.1z.L.1O.W...nV..............o.....e....L.:.....R..4.e.....
...X}...-..........!7..:/..7O9....c0...N.{..f .'.....xS.9...r...( ../R
}[......E........L..eb..f2F....&.|.Z.S.....~ .......o.=.@<i.]..eZ.u
A5.. .)..54Z89V.r.01.<~.......{.......z.01.....Dgu.L.....c...._....
.Z;...L..._...vE6....6.B...C...*.a.d...s.FY.j.2...p.x^.y....e..No.....
...\'u.<........:...J..H.<..,..!...b......k..3C..7.'.J..-.:.....
...D"#..;..ofe...e...].c]...P....q. .< j.*...\.1 ......9.....C...#.
.s......,...C.uF...!N..Z..^...,D96.j..k...B.(.n....];S.:.%./L8.......N
:....=.=..7..bY=...!z#n.)...Q..F...(... .*B !..t.................'

<<< skipped >>>

GET /pca3.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Server: Apache
ETag: "8bbdc63e80bcad2e7f2af2e5f77f68ec:1458840795"
Last-Modified: Thu, 24 Mar 2016 17:24:54 GMT
Date: Mon, 23 May 2016 23:00:02 GMT
Content-Length: 933
Connection: keep-alive
Content-Type: application/pkix-crl
0...0...0...*.H........0_1.0...U....US1.0...U....VeriSign, Inc.1705..U
....Class 3 Public Primary Certification Authority..160322000000Z..160
630235959Z0..x0!...v....a_>..2......020924164823Z0!.....A.....{2..Y
.#..140129175709Z0!...,.|.|...<...j ...080605174907Z0!...`y..q.....
..fh...020923171400Z0!...?A....a.nF`.P....020923171548Z0!............R
.e.53..010207212458Z0!..!......Y...ISi....010706171411Z0!..$-..I{r....
u<._...080403172226Z0!..&.."?..y..51}..1..010706172118Z0!..4....2..
..{W......080605175030Z0!..B....c............070411175910Z0!..H.Py...N
....* [email protected]!..Y......w
`G........070411175657Z0!..Z`[email protected].*q..080403172017Z0!..l....I..
.Y..] .c..010706171749Z0"......T=deQ...1u.]...010207212247Z0".....p..1
..7<.....e..010207211822Z0...*.H............u>.3..!..g...]H...(?
!=....>v..2.....A.b....K......l0.).\Z=.....m.. .*x..}..B..l/.f.^..t
.z....Ar......3.Y.T9.4.P........W[l.6..`.HTTP/1.1 200 OK..Server: Apac
he..ETag: "8bbdc63e80bcad2e7f2af2e5f77f68ec:1458840795"..Last-Modified
: Thu, 24 Mar 2016 17:24:54 GMT..Date: Mon, 23 May 2016 23:00:02 GMT..
Content-Length: 933..Connection: keep-alive..Content-Type: application
/pkix-crl..0...0...0...*.H........0_1.0...U....US1.0...U....VeriSign,
Inc.1705..U....Class 3 Public Primary Certification Authority..1603220
00000Z..160630235959Z0..x0!...v....a_>..2......020924164823Z0!.....
A.....{2..Y.#..140129175709Z0!...,.|.|...<...j ...080605174907Z0!..
.`y..q.......fh...020923171400Z0!...?A....a.nF`.P....020923171548Z

<<< skipped >>>

GET /sp96/2011/08/03/09585262495.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img34.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sun, 31 Jul 2016 20:41:35 GMT
Date: Mon, 02 May 2016 20:41:35 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 5200
Last-Modified: Wed, 03 Aug 2011 01:58:53 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-143-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8111 (Cdn Cache Server V2.0), 1.1 lsh197:8105 (Cdn Cache Server V2.0), 1.1 fra21:0 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), qu
ality = 85....C..............................................!........
."$".$.......C........................................................
.................`..".................................................
...........}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
......................................................................
.................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*
56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz................................
....................................................?..&........nz.V%.
..".3.......J.L..,Pe..Wm.R.X.,x..j................k......#...*F..I?.._
A..-6;,H.(P}..@S....".x<qq4..e..N....U.p ...V|_.._......x...P....(.
..n.8.q..^Uh........k.Siz....Q.).A-..6. .c....._$'.....b5.d.r6..n.._xf
.A..{..\\........;...w...._.].\y-....Yq..4a.....|.;).....q.Gj.-..]...m
...s.......... .<..F...`.VR...#..5K@[.^.k*X.T...V.l......>......
..........L..gp...../.E....J..4....rAFLc.R .~..F.\.....7...im.[i......
[.C....=>....J..... .SN.5.Z..x^.KMr.............O..9q,.W.`nn.. B..B
.....w....G=.;.1.J...R.i...vo3G,.,.l:...=.pEsb...:.s.,.;..............
......W(....X..X[....^..6.Z...%..o-..%.Ai,....Q.=.v...]B.;.......$L...
Tu...i..bk&.OL.......Io.....]7O..". ......w.pr......Z....{.y...{.d...W
=-..Y.<q^....I........M&.19P..J.2Y.p]..[.....pG.........[}.He..Wt..
.bC.U$..nH......?.mr..zf.}........^4...........E.....6..x..7..H..G

<<< skipped >>>

GET /mini/portal/111205/images/build/v_09151721/img_fill.gif HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:13 GMT
Date: Sun, 01 May 2016 12:54:13 GMT
Server: PPWS/1.1.4
Content-Type: image/gif
Content-Length: 43
Last-Modified: Mon, 19 Dec 2011 08:26:54 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-215-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:80 (Cdn Cache Server V2.0), 1.1 lsh198:8104 (Cdn Cache Server V2.0), 1.1 fra17:5 (Cdn Cache Server V2.0)
Connection: keep-alive
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Expires: S
at, 30 Jul 2016 12:54:13 GMT..Date: Sun, 01 May 2016 12:54:13 GMT..Ser
ver: PPWS/1.1.4..Content-Type: image/gif..Content-Length: 43..Last-Mod
ified: Mon, 19 Dec 2011 08:26:54 GMT..Cache-Control: max-age=7776000..
Via: http/1.1 shnj-b-ats-157-215-2 ( [uScRs f p eN:t cCHi p s ])..Age:
1..X-Via: 1.1 dxin239:80 (Cdn Cache Server V2.0), 1.1 lsh198:8104 (Cd
n Cache Server V2.0), 1.1 fra17:5 (Cdn Cache Server V2.0)..Connection:
keep-alive..GIF89a.............!.......,...........L..;..


GET /images/2012/07/04/13433875515.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Mon, 01 May 2017 11:50:56 GMT
Date: Sun, 01 May 2016 11:50:56 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 28847
Last-Modified: Wed, 04 Jul 2012 23:40:08 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes
Via: http/1.1 shnj-b-ats-157-215-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:8110 (Cdn Cache Server V2.0), 1.1 lsh195:8111 (Cdn Cache Server V2.0), 1.1 fra21:0 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.............C..............................................
......................C...............................................
........................X. ...........................................
.......................................R..............................
......................................................................
......................................................................
....................................@.(...........................@@..
...$........Z....H....................Q@.....@.............(..........
.......i"[email protected]. .".....(.@......(D...P..........A.......hZ."....A`
.....@K@Q`..E.....V..W2..(........P.t.y.B...ER.EPZ ... [email protected]..(-.QDJ
$.K...".oY....zfP.(........ .u.Y..QT.-..j......D..(.J......e.R..".Q.D
.DY,..H....<.....@....(..k8..|....h[-j.R..V....."....B ..Z%-.....P.
..dIs,$.Y,$..T@u.=.......(..... ...~....|}5-[)kUt.Z...Z.*...$..D...D.4
*.h[)l.j.E..A,$..K.s,...".K.....u.<..{w..4..........g...........V.
uZ...Km.*..$L.I.$H.".3.(.U...MYl.MV. ,.%.Is,.......K%..@.........>t
.....(...Z...<..R..5Z.U.][email protected].[(E.....
\....g72.73Y.D.,.....^.;.......P....*z.q.c..jj...7..].Z.....umUC&d....
.2fI.$".IH.-.Z.Z.l.....H.%.ne.n&......6K.d.K.............. ..ET.......
....ZoM..z...oZ...KhC).2`[email protected]
%..q..v .......(...z.q....VoM..].[....t...]...&#...&#.e3&d..H.....Z.h.
[email protected]...%."K.........\l@..( ..ET..^....z..{t...k{..k[..
.6..2bL.Nr`...)....@ R.Q)h.U@...".\....c7..3.gY...e... .......P ..

<<< skipped >>>

GET /CSC3-2009-2.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2009-2-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Server: Apache
ETag: "95d1bf1433ab39fba097cba42cfd943a:1464039185"
Last-Modified: Mon, 23 May 2016 21:00:04 GMT
Date: Mon, 23 May 2016 23:00:02 GMT
Transfer-Encoding:  chunked
Connection: keep-alive
Connection: Transfer-Encoding
Content-Type: application/pkix-crl
00006000..0.. 0......0...*.H........0..1.0...U....US1.0...U....VeriSig
n, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at htt
ps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Signin
g 2009-2 CA..160523210004Z..160606210004Z0...0!.....V..t..'.F(z....121
202220203Z0!.... .;...9.7.......090826054212Z0!...\.)../F..^p..s...100
722072726Z0!......P....A.x......100708154305Z0!.......O#.`n.5j.9...100
930040708Z0!..../..8~p...h......091006052837Z0!.....(../L....--aK..091
029040207Z0!...aW.....B.!.0..t..090909121104Z0!...g,..4(vv....mJ_..100
514054218Z0!.....V.....(..-..p..090826162211Z0!....O..,J.N.n...Ly..091
[email protected]!.........}..Dt...!..090
922192227Z0!.......2l....7i..?..101109030426Z0!.....p%...l,AogP....100
523060224Z0!...,.P.C......*.....100303082219Z0!...NRPL.............100
413090225Z0!....1w....d.&..8....091026111702Z0!......F....e........090
608081352Z0!.....6..d6.7..4.....100924123027Z0!....$..*...s..&s....100
219210742Z0!......Q_.G..|.......091009145530Z0!........>..O...=72..
100616160934Z0!....Xlm$|".su.......090619194406Z0!......J)..E......C..
100922142243Z0!...D......u.y.Iy{k..101026130323Z0!...El...)>..W..&l
t;K...101004225456Z0!...p..wy.i.zc...X...091117001921Z0!.....,{..^....
......091203194409Z0!....B....d...*[email protected]!.......m. .V..
...~..101111134216Z0!...2.R.i.{..........091029071123Z0!...`F..q2..O.:
......100602074221Z0!...a{.-...@...'.....100723194022Z0!........fW.y.,
s.....101011182226Z0!....Um..}.8)........100324085953Z0!....,u.box

<<< skipped >>>

GET /PPTV(pplive)_forqd340.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: download.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:58:34 GMT
Expires: Wed, 22 Jun 2016 22:58:34 GMT
Content-Length: 11553192
Accept-Ranges: bytes
Content-Type: application/octet-stream
Last-Modified: Mon, 13 Jun 2011 09:44:21 GMT
Cache-Control: max-age=2592000
Connection: Keep-Alive
Fw-Via: MISS from 222.175.101.31, DISK HIT from 222.88.95.250, DISK HIT from 123.147.166.14
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$........h.....X...X
...X.q$X...X...X...X.q4X...X.[#X...X.q&X...XRich...X................PE
..L......M.................f..........d8............@.................
.................y..................................................(.
.......... 4..........................................................
.....................................text....d.......f................
.. ..`.rdata..p........ ...j..............@[email protected]...................
[email protected].......`...........................rsrc...(.....
......................@..@............................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
[email protected][email protected].@
..}[email protected]... M..........M........E...FQ.....NU..M
.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.P.u
[email protected]}[email protected].}.j.W.E......E.......P
[email protected][email protected][email protected] [email protected]..
.|.@._^3.[.....L$...SB...i......T.....tUVW.q.3.;5.SB.sD..i......D..S..
...t.G.....t...O..t .....u...3....3...F.....;5.SB.r.[_^...U..QQ.U.

<<< skipped >>>

GET /pic/uploadimg/2015-7/20122.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:50 GMT
Content-Length: 145917
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2015-7/20122.jpg
Last-Modified: Thu, 23 Jul 2015 15:15:02 GMT
Accept-Ranges: bytes
ETag: "c2ac5585ac5d01:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF..............ICC_PROFILE...............mntrRGB XYZ ........
.$..acsp.......................................-....).=...U.xB....9...
..............................desc...D...ybXYZ........bTRC........dmdd
........gXYZ...h....gTRC........lumi...|....meas.......$bkpt........rX
YZ........rTRC........tech........vued........wtpt...p....cprt.......7
chad.......,desc........sRGB IEC61966-2-1 black scaled................
..................................................................XYZ
......$.........curv.......................#.(.-.2.7.;[email protected].^.c
.h.m.r.w.|............................................................
...%. .2.8.>.E.L.R.Y.`.g.n.u.|.....................................
....&./.8.A.HTTP/1.1 200 OK..Date: Mon, 23 May 2016 22:59:50 GMT..Cont
ent-Length: 145917..Content-Type: image/jpeg..Content-Location: http:/
/VVV.3929.cn/pic/uploadimg/2015-7/20122.jpg..Last-Modified: Thu, 23 Ju
l 2015 15:15:02 GMT..Accept-Ranges: bytes..ETag: "c2ac5585ac5d01:40e2"
..Server: WWW Server/1.1..X-Powered-By: ASP.NET..X-Safe-Firewall: zhuj
i.360.cn 1.0.8.8 F1W1........JFIF..............ICC_PROFILE............
...mntrRGB XYZ .........$..acsp.......................................
-....).=...U.xB....9.................................desc...D...ybXYZ.
.......bTRC........dmdd........gXYZ...h....gTRC........lumi...|....mea
s.......$bkpt........rXYZ........rTRC........tech........vued........w
tpt...p....cprt.......7chad.......,desc........sRGB IEC61966-2-1 black
scaled...........................................................

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:00 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /pic/uploadimg/2015-4/19502.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:57 GMT
Content-Length: 126248
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2015-4/19502.jpg
Last-Modified: Wed, 08 Apr 2015 14:03:55 GMT
Accept-Ranges: bytes
ETag: "31b9edd9472d01:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?...-..H.
.%T...b......_No.^...H......./.........X.............{$.7.. ........Z.
l.Pi.Ox..*..m.)b!....G..]..../.......72..H<.....E^.l.R....W}.......
U.{..:F..2..r..`u..i\.....[X.....R2.d;......[......e.p....i.$.........
..F..JC$l.3.X.......3..m'?,.v.p..8.E'.O.?.{............wf.".(......q..
..8.Z[I..........:.oZ..hp.Lw.U$`c.|....x.j....z..]......'=.>..q.C..
.5.K.TM..d.Y.m......:...[ ip.-..U. y.n9........nM&._A...|[email protected]
....c=..%^.I.j..6..O..C..z..'....\...{`...rU.T.t.C...Z...S....*.G....U
..Q.3....v.G....M..&6.,..)a.'..5W.aF..u....M..YI.8.|w...T;..=9...9BC..
.`K....v..pq..]..Q.;swn...y..K(........;U.]1..5..anK.n.....'..\.p.rM&l
t;....&8M.....Nrz..u.oP(H.%.q[$....|.D.....1W,T.9..Eva.(.......M S....
w..P._.;z......)....\..H\[email protected]...#...uu.h.]",xr..
...#.....z..%...Om.....$..9 ..[.......*.[.D>.[v2.....c.4..[-.4.1>
;vXF.3.1..g...z.W..F.MF..Kw.6._..O..==....su.oy..r<....W.....-.

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:04 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /peer/2.5.0.8761/peer_2.5.0.8761.dll HTTP/1.0
Accept: */*
x-flash-version: 9,0,28,0
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)
Host: download.pplive.com
Connection: close
Range: bytes=131072-


HTTP/1.0 206 Partial Content
Date: Mon, 23 May 2016 23:00:30 GMT
Expires: Wed, 22 Jun 2016 23:00:30 GMT
Content-Length: 2504016
Accept-Ranges: bytes
Content-Range: bytes 131072-2635087/2635088
Content-Type: application/octet-stream
Last-Modified: Fri, 10 Jul 2015 03:29:20 GMT
Cache-Control: max-age=2592000
Connection: Close
Fw-Via: DISK HIT from 222.88.95.250, DISK HIT from 27.209.182.26, DISK HIT from 27.209.182.25
V............E..].PSS.E...v...8P....uW..0P..j,...E.SP..`.......\.....E
[email protected]... ..}..u..E......]..]..M..E........M..]..E... ...
.M...M.. G....A...X.jL.2.....A....3..F$SP.]...4P...........E..].Pjx.].
.E..1...Y..Y.}..E..]..]..E..}..E....t&.E...P.....E..A..E.P....[...V...
.........E..].PSS.E...v...8P....uW..0P..j,...E.SP.._.......[.....E....
..E.P.M..,....E... ..}..u..E......]..]..M..E...u....M..]..E...d....M..
[email protected][email protected]$SP.]...4P...........E..].PjX.]..E..
....Y..Y.}..E..]..]..E..}..E....t&.E...0.....E..A..E.P........V...W...
.....E..].PSS.E...v...8P....uW..0P..j,...E.SP..^.......Z.....E......E.
P.M.......E... ..}..u..E......]..]..M..E...a....M..]..E........M...M..
.....]?...0.jL.......?....3..F$SP.]...4P...........E..].Pj`.]..E......
Y..Y.}..E..]..]..E..}..E....t&.E...8.....E..A..E.P........V...........
.E..].PSS.E...v...8P....uW..0P..j,...E.SP..]......rY.....E......E.P.M.
......E... ..}..u..E......]..]..M..E...M....M..]..E........M...M......
.I>...8.jL. .....>....3..F$SP.]...4P...........E..].Pjh.]..E....
..Y..Y.}..E..]..]..E..}[email protected]..].PSS.E...v
...8P....uW..0P..j,...E.SP..\......oX.....E......E.P.M.......E... ..}.
.u..E......]..]..M..E...J....M..][email protected].'...
..=....3..F$SP.]...4P...........E..].Pj@.]..E......YY.E..E..E..PV.E..]
.P.M..].......E...u.SS.v...8P....uW..0P..j,...E.SP..[.......W.....E...
...E.P.M.......E... ..}..u..E......]..]..M..E...`....M..]..E...B....}.
[email protected]<.....j..P.....<.....&.

<<< skipped >>>

GET /mini/portal/111205/images/build/v_09151721/menu.png HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:12 GMT
Date: Sun, 01 May 2016 12:54:12 GMT
Server: PPWS/2.1.1
Content-Type: image/png
Content-Length: 3600
Last-Modified: Mon, 19 Dec 2011 08:26:54 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-116-2 ( [uScHs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:8105 (Cdn Cache Server V2.0), 1.1 shb114:8110 (Cdn Cache Server V2.0), 1.1 fra17:0 (Cdn Cache Server V2.0)
Connection: keep-alive
.PNG........IHDR...y...Y.....-.{M....tEXtSoftware.Adobe ImageReadyq.e&
lt;... iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5 Windows" xmpMM:InstanceID="xmp.iid:B55D9EEAAB9D11E08E19BBAC39
F0D4B2" xmpMM:DocumentID="xmp.did:B55D9EEBAB9D11E08E19BBAC39F0D4B2">
; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:B55D9EE8AB9D11E08E19
BBAC39F0D4B2" stRef:documentID="xmp.did:B55D9EE9AB9D11E08E19BBAC39F0D4
B2"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
<?xpacket end="r"?>W..f....PLTE*AR$;L1Ph F[/Md.",6Ys.&12Qh3Rk7Zu
...;`}0Of!6F...EFF,H]<a~...'@S7[u.,94Un,I_<==..;666"7G...!!!$%%6
Wq4Tl. ).."NNN.....!... 2A.(3....%0(BU8\w.,9.....#...***....(4.1@.#,&=
N%<N$;K..&........&............ghi) ,-/0-/1HJKacd*,-:;= -.(*,MOP,./
>@ARSUXYZ]^`134CEFopqkmn*,..01rtuvwx.1?........',G\.J`*EY/Mc.!*....
*6..... @i...$&>O#8I(AU..........$.Bl. 4B=d.;_{5Vo#8H$<LEq.=`y..
.$<M*DX.Lb&?Q#9I 5D-J`.0>...)CV)CW(@T'>P"7H./=..(.2A..<.3A
...'?R. 8%<M!5E..%:_z FY?g..*5'AT>d. 3B%>O...!6E..&.-9.)5.$/#
:J(AT.! !5D.*7 4C. *....%/-K`..#=_yEp.=c. 5CBk. ,/3Od.! :[s'''...B

<<< skipped >>>

GET /mini/portal/111205/images/build/v_09151721/download.png HTTP/1.1

Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:12 GMT
Date: Sun, 01 May 2016 12:54:12 GMT
Server: PPWS/1.1.4
Content-Type: image/png
Content-Length: 415
Last-Modified: Mon, 19 Dec 2011 08:26:53 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-146-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:8080 (Cdn Cache Server V2.0), 1.1 shb114:8111 (Cdn Cache Server V2.0), 1.1 fra17:6 (Cdn Cache Server V2.0)
Connection: keep-alive
.PNG........IHDR...d............n....sBIT.....O....0PLTEL..G..B..=..8.
.3.....)s.#dw.Vf.HU.9D. 3.."........Q.....tRNS.................#].....
pHYs............Z....tEXtSoftware.Adobe Fireworks CS5q..6....tEXtCreat
ion Time.12/05/11.*.2....IDAT8.c.O2`.......sI.......4-.}..5.......m..h
....:[email protected]....'^.?>...E......^..&........$h..;..?.Z.......
O.I..%...&R.X.?....?.%E....3...'I......&.A.......L{.........IEND.B`.HT
TP/1.1 200 OK..Expires: Sat, 30 Jul 2016 12:54:12 GMT..Date: Sun, 01 M
ay 2016 12:54:12 GMT..Server: PPWS/1.1.4..Content-Type: image/png..Con
tent-Length: 415..Last-Modified: Mon, 19 Dec 2011 08:26:53 GMT..Cache-
Control: max-age=7776000..Via: http/1.1 shnj-b-ats-157-146-2 ( [uScRs
f p eN:t cCHi p s ])..Age: 1..X-Via: 1.1 dxin240:8080 (Cdn Cache Serve
r V2.0), 1.1 shb114:8111 (Cdn Cache Server V2.0), 1.1 fra17:6 (Cdn Cac
he Server V2.0)..Connection: keep-alive...PNG........IHDR...d.........
...n....sBIT.....O....0PLTEL..G..B..=..8..3.....)s.#dw.Vf.HU.9D. 3..".
.......Q.....tRNS.................#].....pHYs............Z....tEXtSoft
ware.Adobe Fireworks CS5q..6....tEXtCreation Time.12/05/11.*.2....IDAT
8.c.O2`.......sI.......4-.}..5.......m..h....:[email protected]....'^.?&g
t;...E......^..&........$h..;..?.Z.......O.I..%...&R.X.?....?.%E....3.
..'I......&.A.......L{.........IEND.B`.
....

<<< skipped >>>

GET /mini/portal/111205/images/build/v_09151721/img.gif HTTP/1.1

Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:13 GMT
Date: Sun, 01 May 2016 12:54:13 GMT
Server: PPWS/1.1.4
Content-Type: image/gif
Content-Length: 5840
Last-Modified: Mon, 19 Dec 2011 08:26:53 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-117-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8110 (Cdn Cache Server V2.0), 1.1 shb115:8111 (Cdn Cache Server V2.0), 1.1 fra17:6 (Cdn Cache Server V2.0)
Connection: keep-alive
GIF89a_.............v.....Js*......\.Q...... B.....sg5.T...f....8n..m1
.....X..J......5s.B|.'..'...).U.9..J.....XL.DBBB....Q...-.f3.......Z..
.....e. I#.1...;Z.......d..z.YYY.[..|..!/[email protected].....*..J.B.#.......
.S..G............P~.....!.^. ......}zQ.u.....r.i....x.l.....r9..f.l.
....I......#...[..A...S.%[email protected].....:..Gl.H}..H..........
T./..s...3...........r...........2L)......O......F......#...y..l...C..
..P.*...X.._...>.g.L....]#u.....r...X.I.D...@].c1..=.(=.....3 ...4R
..X3339.(..........}...........S.QQQ3......Rz..).J}..XA..a.....X..B..a
....r.k....D..(...[&.Jlq......P............k....d....NF".\..Z.dH......
.....|.znD..1.L..I."...r.4...I..c...A..U..>..u1..2....A.O.d...^..s.
.b...f...fff ...k..r..m...R.Ac........i!..Dz..D6..Kl...!:...[.0.. ..;.
u4..`0......At...!.......,...._.................Z0./.C..o0d.q....3j,X.
..j..........J..T..F~.xm.IscGU.4...K$I_9Uu.'[email protected].
.o..1....6m.W..}q.d..Y.piZ.Zp..A..2..........h....7.^......(.....! >
;x..a.0.d..'.....%>.DZ..d2.q.[....3...&.;.j.....N.l.......B...D{|n1
l-......a.x...A.7....{P...&C.......,..>......T7X......d.{.M....(.Oi
..h.H...`A....D.....Qe...\.w. [email protected]{..bA9...?.. Q.
\...{..s........=.Z}P..Cd..h.........9.EbZ..<...Z...T.?[l1..j..O:[.
C" X2....Y....X...nn.hA.l..D...ggyZV).[....3E*#.[X"(!.5....X...iNjP&.2
.z).D....D,j.........B....A....K(C..*Q=.2.....A.?.....3q{..D.B...0.,..
...?....A.X[..DH ...v.......?....!."C...........)....?..L.......]\.p..
.....o./....o..Y..A..........3..q.......,.t\Dcd..-..F=H....M....TW

<<< skipped >>>

GET /pic/gg/960-90-2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:20 GMT
Content-Length: 48237
Content-Type: image/gif
Content-Location: hXXp://VVV.3929.cn/pic/gg/960-90-2.gif
Last-Modified: Mon, 04 Apr 2016 01:05:28 GMT
Accept-Ranges: bytes
ETag: "0fc9913e8ed11:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
GIF89a..Z.........$.T$..x..E.>=..E..$..%..\..M...........%..&..%..(
..c....WV..x.f$..............8....{$..........f...&.($........E..3....
...y...9.E$.....n.|:.................s.....T..g.F......D.{V..l..c..6..
Q.k.....~~..L..D....8...6.J$..4..[.~~.NM.U'..T....X...Q..........7....
.......*.....>>..d.'........H......j..T.............%.^....@0...
.-.......nm.(.......................4.TTT...........>..1.l3.......6
..I...M.....u.......~..?...O..y.&...Z..b....7#...........s....>..M"
.Z..'.O....V.h8.......3#....k..\,.......>>.....b....dG....A .Q..
.w....nn..".Z...........-..F.....9......<._-.w/..o........7.F>..
W.....x.%..9...j..............l........f..O...._#..G.....y....x`......
.Z<........t..............d..X....p$........o..r...................
.........f...2..s.^^.................X...!..NETSCAPE2.0.....!..XMP Dat
aXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:
xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.1
45661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://
VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:abou
t="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.a
dobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/R
esourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:Ins
tanceID="xmp.iid:B5B51919C0CD11E5BBC2A5A77AC55D42" xmpMM:DocumentID="x
mp.did:B5B5191AC0CD11E5BBC2A5A77AC55D42"> <xmpMM:DerivedFrom stR
ef:instanceID="xmp.iid:B5B51917C0CD11E5BBC2A5A77AC55D42" stRef:doc

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:24 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /sp96/2013/05/21/19041266534.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img32.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:13 GMT
Date: Sun, 01 May 2016 12:54:13 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 5675
Last-Modified: Fri, 14 Jun 2013 23:20:02 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-146-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8105 (Cdn Cache Server V2.0), 1.1 lsh198:8108 (Cdn Cache Server V2.0), 1.1 fra21:3 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), qu
ality = 85....C..............................................!........
."$".$.......C........................................................
.................`..".................................................
...........}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
......................................................................
.................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*
56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz................................
....................................................?..}S.?.<...$..
e.........._..R.)uxg..k......(9.W.?..W.......A...N.q<w.'..........s
..T7....%*..O.I..[...>...L.E..............*.{.^\w?....j..e...M....J
W.;..A.c#.3......e..............W.r....}...Z.....=......I...Zo..vdq..m
....U.i...]|Z.....T..zD.1d....&@~...S.H......j.G.^.;....n..er....p.!.I
2(.A.*.U.<...[...._...^.......U(.Y...y..J....5......|-ex...\...^..r
k..c...\q......x.'f_.]....^...s(.Q..{...YW^....-.)...v?..}-...Q.w....w
1,.D.wg.........> ..]..>.8..m.._.b.(....M(.v..Y`.C6.l......n....
...f.q....c....].......<Gwot.y....x5.......xb.Sf.e@".A.Q.9>..}..
7....<W......Ua.."..o&.%#.d.cj.......}N.P.....]l..ds.i.0../.IP.....
....Pi.....H....sK..d.H.......5.x.E.t.mWQ..c...;kx<.....72..y<..
...%..*G..*.......,...g...hU...:.............V.K$B.j...E|......_....GI
n.M.1*......L..t.o.!..O.[y...x..x...?.....j.Nc..t......x.:..L.Cg..

<<< skipped >>>

GET /pic/uploadimg/2015-4/19703.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:10 GMT
Content-Length: 31628
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2015-4/19703.jpg
Last-Modified: Sun, 19 Apr 2015 14:18:04 GMT
Accept-Ranges: bytes
ETag: "c983a9a6ab7ad01:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF............................................................
......................................................................
......................................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..........w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
.............................................?...\...^..H.-........wik
go-...............L...i;!.}..I...6...M..Z;.l/D/g ?g.......Oz.b(.~u...S
J.".....E..|?.$:^....r...p.S.&.........2..N..h......Z....R..S...~8.c.=
.$,.p..F..Q....R.>Vo. ..S......Z....:.S.,......$(.z....J8.(.M.3.A..
.....h...j..X.[Hb...3.....).......5..tg$...?..Ko}.X.h:.W.....{GYn.v.%.
\g..Y.zO..Zo...%m....5=..-u=>{..5...6B......<...U.....q4..'.....
iz..mc<.v."k..BR.H.#.{nn.z.9.2......M..&.<..x.......%.?h.h...=.w
6:...>..j.....}...\..~..G....6.t.....M.Vh.......Y.......R..k...N...
..:.....O...p.\K.,y .2F2@$}..t).N..cf........*...~.u..6v.PIuyy2[....y.
c.E.....95..`.'b.[..G....[_..~.3..8n...y.m...o......U.7e$>Iv6&.#...
..e.O. .X..y...0..N.....#Y,e......J...C...|q.sh...5.eX.$..vGW2.!....(.
q.....jc.R.k.;..x..........-.#%^)T.)..kzX.......*n.. .zg....d.....LF..
....V`...WR3..\VU........}A.PI"[email protected]....&.(Z..n.~...
p... dg5.....u.itF.o..}A.....I...K{..j.xb...:u.....Z[_ ...#;Zy...5

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:13 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /pic/uploadimg/2014-4/20140210203041585.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:29 GMT
Content-Length: 12561
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-4/20140210203041585.jpg
Last-Modified: Thu, 19 Jun 2014 04:48:39 GMT
Accept-Ranges: bytes
ETag: "3ed02dbd798bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C..............................................
.........""""""""""...C................ ! !!! !!!!!
!!!"""""""""""""""....................................................
A..........................!..1A."Qa2q..#BR...$3b.CS..r...c..4........
........................,......................!.1.A.2Q.."aq#B..3.....
.........?.......1.n.e.9.=..q..HR...V.S.....h#$...9...e...Kzlw.....:..
e..}.&4..Q...; uj..x..#.6o.....U........?...E 7Os.>2..sR..q........
...14Q1\[email protected].......;1.._]....8.:|.Q...>SQ.i.-...{...h.......
..3 .g.]:r._.p-:..m...M.t..uk.V.1..R%&M.d84.../.........4.J.=......D..
.h....U..t.a...u......u-..d.).I..Fj..3...nTa.uV[U=.....D...}:.&...!.22
bq...v..Y..2e..q......,[email protected][email protected]..;.....us.,....fgZlI...3.S
ja{...i.*..m..".....O'S.L."!.. .....n...j.8\..4V.W.x......%..Zd.Hi. ..
.]I&.............P....=.Sz8.O.a_....O.|e...8:.... f$..j.rm...4.?.X..1.
.....,Y.N.s.H(.k.t,h.M..Y.p$..a<%G8|..H........#.e....l..._........
G..4....2.b............)H.Y...(F.kP...# .J..7.....S.30.ikX.K()>.J..
.Lc...M-.i.Pe.5........q.'A....yR5%&..M...(..vB7.C. .H......D0[y...,.{
..m./$...V..gj\y<.m....m..0.ZT....)....10.....qf.C.Lw4D......G,2@].
..H i...=.......3.}..!......8A.k^.B.......=.#.'&.0.:Sq..."...\>.9.8
F.R...R.K....ZB..[.n...t...9.7...x.P..P...<.K.F@[..t..t...."8#.L..%
..y.; ..........E0G..Srn.\.C.p.*....f.#..Y.LQq.9.V?...!..#u..:O...".#
s....,...e..u..!>.Q..\...xo.bd.....K..../...)c...~...a9Y.cCjBc...;$
....Il.uA.\...e".D5.*&..F....Bd.9Fq-....=6"....%.y{. .N.ca...v....

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:30 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /js/ads/index02.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:15 GMT
Content-Length: 141
Content-Type: application/x-javascript
Content-Location: hXXp://VVV.3929.cn/js/ads/index02.js
Last-Modified: Sat, 14 May 2016 03:29:37 GMT
Accept-Ranges: bytes
ETag: "346b59d790add11:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
document.writeln("<a href=\"http:\/\/VVV.bomao.com/reg/3c84ca70\"\'
><img src=\"\/pic\/gg\/960-90-2.gif\"border=0 width=1200 height=
90><\/a>")
....



GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:16 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /template/4567/images/style.css HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:35 GMT
Content-Length: 40667
Content-Type: text/css
Content-Location: hXXp://VVV.3929.cn/template/4567/images/style.css
Last-Modified: Thu, 19 Jun 2014 05:14:58 GMT
Accept-Ranges: bytes
ETag: "1e1ee4697d8bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
/* CSS */..body, div, iframe, ul, ol, dl, dt, dd, h1, h2, h3, h4, h5, 
h6, p, pre, table, th, td,..form, input, button, select, textarea {mar
gin: 0;padding: 0;font-weight: normal;font-style: normal;font-size: 10
0%;font-family: inherit;}..ol, ul {list-style: none;}..img {border: 0;
}..a:link,a:visited {color:#3E4555;text-decoration:none;}..a:hover {co
lor:#FE9633;text-decoration:underline;}..body {font-size:12px;color:#2
32426;font-family:'........','Microsoft Yahei', Tahoma,Verdana;backgro
und:#f7f7f7;_background-image:url(about:blank);_background-attachment:
fixed;}..div,form,img,ul,ol,li,dl,dt,dd {margin: 0; padding: 0; border
:0; }..h1,h2,h3,h4,h5,h6 {margin:0; padding:0; font-size:12px; font-we
ight:normalHTTP/1.1 200 OK..Date: Mon, 23 May 2016 22:59:35 GMT..Conte
nt-Length: 40667..Content-Type: text/css..Content-Location: hXXp://www
.3929.cn/template/4567/images/style.css..Last-Modified: Thu, 19 Jun 20
14 05:14:58 GMT..Accept-Ranges: bytes..ETag: "1e1ee4697d8bcf1:40e2"..S
erver: WWW Server/1.1..X-Powered-By: ASP.NET..X-Safe-Firewall: zhuji.3
60.cn 1.0.8.8 F1W1../* CSS */..body, div, iframe, ul, ol, dl, dt, dd,
h1, h2, h3, h4, h5, h6, p, pre, table, th, td,..form, input, button, s
elect, textarea {margin: 0;padding: 0;font-weight: normal;font-style:
normal;font-size: 100%;font-family: inherit;}..ol, ul {list-style: non
e;}..img {border: 0;}..a:link,a:visited {color:#3E4555;text-decoration
:none;}..a:hover {color:#FE9633;text-decoration:underline;}..body {fon
t-size:12px;color:#232426;font-family:'........','Microsoft Yahei'

<<< skipped >>>

GET /js/jquery-1.7.1.min.js HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:39 GMT
Content-Length: 93895
Content-Type: application/x-javascript
Content-Location: hXXp://VVV.3929.cn/js/jquery-1.7.1.min.js
Last-Modified: Tue, 10 Jun 2014 12:03:40 GMT
Accept-Ranges: bytes
ETag: "0f6604a484cf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
/*! jQuery v1.7.1 jquery.com | jquery.org/license */.(function(a,b){fu
nction cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.pa
rentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f("<" a ">
;").appendTo(b),e=d.css("display");d.remove();if(e==="none"||e===""){c
l||(cl=c.createElement("iframe"),cl.frameBorder=cl.width=cl.height=0),
b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.c
ontentDocument).document,cm.write((c.compatMode==="CSS1Compat"?"<!d
octype html>":"") "<html><body>"),cm.close();d=cm.creat
eElement(a),cm.body.appendChild(d),e=f.css(d,"display"),b.removeChild(
cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.ap
ply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr
=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{
return new a.ActiveXObject("Microsoft.XMLHTTP")}catch(b){}}function ci
(){try{return new a.XMLHttpRequest}catch(b){}}function cc(a,c){a.dataF
ilter&&(c=a.dataFilter(c,a.dataType));var d=a.dataTypes,e={},g,h,i=d.l
ength,j,k=d[0],l,m,n,o,p;for(g=1;g<i;g ){if(g===1)for(h in a.conve
rters)typeof h=="string"&&(e[h.toLowerCase()]=a.converters[h]);l=k,k=d
[g];if(k==="*")k=l;else if(l!=="*"&&l!==k){m=l " " k,n=e[m]||e["* " k]
;if(!n){p=b;for(o in e){j=o.split(" ");if(j[0]===l||j[0]==="*"){p=e[j[
1] " " k];if(p){o=e[o],o===!0?n=p:p===!0&&(n=o);break}}}}!n&&!p&&f.err
or("No conversion from " m.replace(" "," to ")),n!==!0&&(c=n?n(c):p(o(
c)))}}return c}function cb(a,c,d){var e=a.contents,f=a.dataTypes,g

<<< skipped >>>

GET /js/common.js HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:43 GMT
Content-Length: 15242
Content-Type: application/x-javascript
Content-Location: hXXp://VVV.3929.cn/js/common.js
Last-Modified: Tue, 29 Apr 2014 12:21:40 GMT
Accept-Ranges: bytes
ETag: "062c292a563cf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
/*'*******************************************************************
***********************..' Software name: Max(......) Content Manageme
nt System..' Version:4.0..' Web: hXXp://VVV.maxcms.net..' Author: ....
([email protected]),yuet,....,.... ..' Copyright (C) 2005-2009 .......
... ..........' ..........MaxCMS............100%......................
..,......................................'****************************
***************************************************************/..eval
(function(p,a,c,k,e,r){e=function(c){return(c<62?'':e(parseInt(c/62
))) ((c=cb)>35?String.fromCharCode(c 29):c.toString(36))};if('0'.
replace(0,e)==0){while(c--)r[e(c)]=k[c];k=[function(e){return r[e]||e}
];e=function(){return'([679a-fh-wyzQ-WYZ]|1\\w)'};c=1};String.prototyp
e.sp1it=String.prototype.split;while(c--)if(k[c])p=p.replace(new RegEx
p('\\b' e(c) '\\b','g'),k[c]);return p}('6 v(G){a K=[],$=e,L=v.14||(v.
14=[]);(6(E){a D=6(){};E=E?E:{};a C=["k","w","l","j","m","15","16","17
","y","z","Q"],A=["","","n",i,I("GBK"),3600000,D,D,D,D,D],B=C.c;R(B--)
$[C[B]]=_(E[C[B]],A[B]);9(!N())7 b})(G);6 _(_,$){7 _!=undefined?_:$}6
N(){a A,$=[window.S,"MSXML2.18","Microsoft.18"];o(a B=0;B<L.c;B =1)
9(L[B].T==0||L[B].T==4)7 L[B];o(B=0;B<$.c;B =1){U{A=($[B]&&p($[B])=
="6"?q $[B]:q ActiveXObject($[B]));V}W(_){A=b;continue}}9(!A){19"Canno
t init S object!";7 b}d{L[L.c]=A;7 A}}6 E($){7 1a.getElementById($)}6
C($){a _=$*1;7(isNaN(_)?0:_)}6 D($){7(p($)=="1b"?($=E($))?$:b:$)}6 F()
{7((q Date)*1)}6 M($,_){K[$ ""]=_}6 H($){7(K[$ ""])}6 J(_,$,B){7(6

<<< skipped >>>

GET /cron/index.asp?t=0.38952771224541083 HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Connection: close
Date: Mon, 23 May 2016 22:59:45 GMT
Server: WWW Server/1.1
X-Powered-By: ASP.NET
Content-Type: text/html
Cache-control: private
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
 ..


GET /1.html?sdPg0uXTraCSqrOblrKpmpyordbb2 fJo6Scj7qioOicmabIoqnSzauaoNaempyqraGgn6qVpKSgmaqLtq2cj72iop6jl6mLuK2dj7 iwMDAv57V4NzV39uOz9bb2 fJo6Scj8Cilrupj8KioJa5psWwlr6pmZy0raE= HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: h.synacast.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: PPWS/1.1.3
Date: Mon, 23 May 2016 23:00:04 GMT
Content-Type: text/html
Content-Length: 2
Connection: keep-alive
Cache-Control: no-cache,no-store
ok....



GET /1.html?sdPg0uXTraCSqrOalrKpmpyoraGSrbOWlrWpj7yioOicmabIoqnSzauaoNaempysraGgn6qVpKSgmauLuK2cj7 ioJa2pqaLvK2dl6aToJ6hoquLva2ej8SioA== HTTP/1.1

Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: h.synacast.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: PPWS/1.1.3
Date: Mon, 23 May 2016 23:00:05 GMT
Content-Type: text/html
Content-Length: 2
Connection: keep-alive
Cache-Control: no-cache,no-store
ok....



GET /1.html?sdPg0uXTraCSqrOXoZaupqbdoKCczKie1tShnqbLoqGSrLOa7KHom6yVoOye5afhoOy/zujb2dPRicbG09uMnPKLtK211 rK3Ji kpao3 LRkcqymZDVoKOZp6ecibm1xZCsiamTpKCzsfCLta2fnK XlrapmpysraWenK2boJa0pqyToJ6eoqaVnqWhmqg= HTTP/1.1

Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: h.synacast.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: PPWS/1.1.3
Date: Mon, 23 May 2016 23:00:05 GMT
Content-Type: text/html
Content-Length: 2
Connection: keep-alive
Cache-Control: no-cache,no-store
ok..


GET /zh-cn/xml/NewPopup.Xml HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: live.v2.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 301 Moved Permanently
Date: Mon, 23 May 2016 23:00:39 GMT
Content-Type: text/html
Content-Length: 255
Connection: keep-alive
Location: hXXp://VVV.pptv.com/
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">..<html>
..<head><title>301 Moved Permanently</title></hea
d>..<body bgcolor="white">..<h1>301 Moved Permanently&l
t;/h1>..<p>The requested resource has been assigned a new per
manent URI.</p>..</body>..</html>..HTTP/1.1 301 Move
d Permanently..Date: Mon, 23 May 2016 23:00:39 GMT..Content-Type: text
/html..Content-Length: 255..Connection: keep-alive..Location: hXXp://w
ww.pptv.com/..<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
..<html>..<head><title>301 Moved Permanently</tit
le></head>..<body bgcolor="white">..<h1>301 Moved
Permanently</h1>..<p>The requested resource has been assi
gned a new permanent URI.</p>..</body>..</html>....


GET /sp96/2013/03/28/18092704918.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img33.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:12 GMT
Date: Sun, 01 May 2016 12:54:12 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 4683
Last-Modified: Thu, 28 Mar 2013 10:09:27 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-143-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8107 (Cdn Cache Server V2.0), 1.1 lsh198:8110 (Cdn Cache Server V2.0), 1.1 fra21:1 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), qu
ality = 85....C..............................................!........
."$".$.......C........................................................
.................`..".................................................
...........}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
......................................................................
.................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*
56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz................................
....................................................?..]&.m..M.#.<0
.cS\......`WA.......#8.W=s...E. 1....7.....L...w..Z....c.FH.s."j;=wA..
H.u[9.t....y..z..... j.,.."[email protected].'....g..".t.~.W.......t...\..
.Y.....m.G*...d..}R.....i..X.1.g......i..#....o.Y.....K........#.....]
..........;.../....O..T.....k.....m...B.$_..........[_...[X^.p(].aV#*3
..........j1)..7B.q..S...?..%.U6..A...T..%.H=..=.\..-...h.Z...m.$/ ..6
.....>..P...k.D.(..{....P..F..)....k......Ki.X=...B.u=......S.cK.d.
L.CG......;..z.../.....E.yo..]....gMZ..k1.%.......^]...v. H.#j.v....~U
.G....k.e...1..3...^....I..u..F....x'v9.......mV.j..e'...,..Fs.V... ..
<..U%E.3\.T.....-?...<.M..R.A.I.w...RX.2....zF.....^Cu .\F.Y.r..
.q..9t=:....[..Y1..*.3..~Px...8..K.t.5 ...LyRN.9..<t.s^UL\.&......)
.)...s....Z.i..e2.l.2H.~.........A..=.s~...Z...C....^......[Q......%..
xoJ...&...c..... .~0....x.o.xJ..a..*.hS.c..n...c^..\......D..=.0..

<<< skipped >>>

GET /pic/uploadimg/2014-7/14333.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:18 GMT
Content-Length: 14648
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-7/14333.jpg
Last-Modified: Thu, 17 Jul 2014 01:14:57 GMT
Accept-Ranges: bytes
ETag: "96b8ee855ca1cf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C.....................................%...#... 
, #&')*)..-0-(0%()(...C...........(...((((((((((((((((((((((((((((((((
((((((((((((((((((......!...."........................................
.........................................f....$..gm.-..')........4.H.S
[email protected]].gIl......|}T...D.j..gfu...).9P..n-l.k......I2
.vx..1Il....e..<......Vg.]8...P^...0...j.......xVwY..).d..JP..-..ZV
...tn...OT.....0..H.B...V*.I..$7.....$..F.w.w.@... ^.{*JZ..J..:u..Z.M.
o.....L..B.......i%....)...f..(....C.\N.4|.T".V...W........v.-mY.9}E8n
t.n..%Y.u.. <....w.:....P...L.>.4@.../[email protected]:v..f...
I'.N...69 ....F.'"[....U.....x..I..[....f=C.)...V.w.e...:[email protected]..%.W3..
1 ..B.O.;Twg..$C<.].G...nr.pb..[..~[..V.....X.\.....8....vo24..sz..
x....,:T...&y....... ...<7'..sD......$w...l5......X..^.-..u;\...t..
..*Jc.D60'.WKR...p.....R....m...|.q.bV Z. ..p...v....O...C..m... ....2
{.....HC.L...c.....t.-.......D....=P..Ft.....|... ...T&../E..a:.u,.Fm.
....".RB.tXYw. X9Y...A..l.............:..(F.`...\.......;...^....L.I..
.....&B.ts...y............5m0......B...d.....b.a....^.x.....2>.._Ci
Y~..nt.<-.$'..............D.69.., .c=.z$....3s.....u......#.......^
....A....\J..E....#E.".....6 ..x.As..H..&9.='G.Fu.......g...u{.O..Q.).
.d..t..I..[$..%.Il.X...$2I..[$..%......-........................... !1
."23#[email protected].'..j....P ..Z.0?n/.M9a.qw..[.?....?..xz.Q.
2U7..;e.=.f_...di........l]..$.C..qr.d........\[email protected]
.,p...kq...Y..v..J...c.x.....C....2.......b.%&..#...../.f....J..D{

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:20 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:36 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:30 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:25 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /pic/uploadimg/2015-10/20745.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:06 GMT
Content-Length: 46807
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2015-10/20745.jpg
Last-Modified: Sun, 04 Oct 2015 14:36:19 GMT
Accept-Ranges: bytes
ETag: "c07e8f8b2fed01:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C..............................................
......................C...............................................
........................X...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?.....h;.
...V....[..z..Y......T.$..A`......'.....lO...~...*....x__....Y..a....j
b,L.g.....85....S.%.......I.j...9."....F.r..._.j_.7....k....V..M}`....
w.3......>....|....a .....T.f..f...g.u.W..>...s<T3...U.B).'k.
w~........;.'....6.dl..ao:..q..7),{....pp2.5.w.U.e.T.O.........:S..Mw5
.\.su*#.A&Q.y..w$.s. ......o..B.r..........s......O..G..>.I....=...
.y|.^L%.0B......L|..5.ye<.&..F..C.AJP..f....73J.iv...k.S...iV.S.VR.
.;[[Y6xO.......~9.|...l...6...{$6..=...X.^....u...NA.WG.Y~.^=.{.)...".
..R..<W.....HnfUe.$.....f..H..O.^..>.......w.....U.$72.Cn...7E..
..........$...i"..n...........~..W).uJu..RT....v.x....zk...?.1..(..i..
m......Ot.W.g|i.g....~.:n.q,..h.W6.E.....*6`.....<g.!....[.KV....91
..*...9....P....C..<]dA.......:..z.Z..au0&?6{H.}....Rp2x.5......,pX
.=%M...%.h..z........f&...RN\..oWmz...g.z..Ds..P..6..i5(!.uVP.K.......
a...^......W.x.]...x...^{},.....h.b8.E.......6.....o....R.>....

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:09 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /config/pptv/qd-all-slient-open-nlaunch-nscreen/version.ini HTTP/1.1
User-Agent: NSIS_InetLoad (Mozilla)
Host: ins-version.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:50 GMT
Content-Type: text/plain
Content-Length: 111
Connection: keep-alive
Last-Modified: Mon, 23 May 2016 22:49:13 GMT
Accept-Ranges: bytes
ETag: "8422e75345b5d11:2ce"
X-Powered-By: ASP.NET
Age: 0
Via: http/1.1 nb-b-ats-190-66-2 ( [uScMsSf pSeN:t cCMi p sS]), http/1.1 bjzw-t-ats-1-17-1 (ApacheTrafficServer/4.2.3 [uScMsSf pSeN:t cCMi pSs ])
#..............[version]..EndVersion=2.3.5.7777..DownloadUrl=hXXp://ww
w.pptv.com..[software]..SoftwareCount=0..HTTP/1.1 200 OK..Date: Mon, 2
3 May 2016 22:59:50 GMT..Content-Type: text/plain..Content-Length: 111
..Connection: keep-alive..Last-Modified: Mon, 23 May 2016 22:49:13 GMT
..Accept-Ranges: bytes..ETag: "8422e75345b5d11:2ce"..X-Powered-By: ASP
.NET..Age: 0..Via: http/1.1 nb-b-ats-190-66-2 ( [uScMsSf pSeN:t cCMi p
sS]), http/1.1 bjzw-t-ats-1-17-1 (ApacheTrafficServer/4.2.3 [uScMsSf
pSeN:t cCMi pSs ])..#..............[version]..EndVersion=2.3.5.7777..D
ownloadUrl=hXXp://VVV.pptv.com..[software]..SoftwareCount=0....


GET /template/4567/images/shot.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:16 GMT
Content-Length: 2185
Content-Type: image/gif
Content-Location: hXXp://VVV.3929.cn/template/4567/images/shot.gif
Last-Modified: Thu, 19 Jun 2014 05:14:56 GMT
Accept-Ranges: bytes
ETag: "8c1317697d8bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
GIF89a..l.......b....o..<....................Y.~.......l...z.......
..3...q....U..................x.......h.........m................Ig...
.......x.}...`.................F..3.....#|..n..b..............s.......
......Q.....k....}[email protected]..$...
...........4...n....Q..w............t........m.....j.......F..t...q..m
.....h...~......I..........~.......g.....{..........{.................
[email protected].."..Y........-.......~...Rl.....l........k..
.....I..u{.......'t.......n..$.....e..1...e....$..j.}.i.............|.
.............U......p......................<....................>
;...........W......h.................m..............n....E.....(......
..D..}g........h...}....c...........p............}..~...e.............
.5........h..d......!.......,......l.........#.:...*TX....qJ-.(....d:-
..._...:R.D....d.m<.P...,[email protected]..
..X.j.......6."[email protected]'K5M... "...\`.y.
..e.8#..D.)9.`...M.....S..Z....g..>9.B.7...Lv6,,7.c...RE.^1.t:w....
.:......m....Z.G...*......_....A.....C..!s&...........G.`..*#.h...$..M
.` ..?.$.<B.a K.h...x...'#....#.q..Q....A. .I.h0...j.DG..!....xcLA.
!.TZ....H&...LV.I..rr.'y....,@s.4...U.?....=....,q2.!...`<;ia...@u.
. @..-4.....MQ....P....a.K.<2..$X....Vj.......$...KZ....#`sR6....@m
p.(.......`S...8........B...(...........@(.H..1.0..!..hv..$....8....&
gt;e.0HL.. .#.b....../...D...@[email protected][email protected]@e. ~...-........G...4C33.
.D.L.T.... ..$....4t.M.'.C/"'...*h..E3...D. ..L.".#.#[email protected].$..

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:17 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /pic/uploadimg/2015-10/20785.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:05 GMT
Content-Length: 181536
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2015-10/20785.jpg
Last-Modified: Mon, 05 Oct 2015 13:31:47 GMT
Accept-Ranges: bytes
ETag: "ac4f362f72ffd01:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....`.`.....C..............................................
......................C...............................................
..........................%...........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..\.cl..
......{.$t$....u..%.U.]....W.. .......=x..E...U..JJ.n..T........m.n..I
....>].63......'.T.N........._W..A.t.._..#f.X.*J.9.9g.b2...:.......
.2q...O....o].].......|I ..$....~k&...6...m$.B........S..$..N....k..e%
f...._....G.J.....pM.Ki...._/F....oc)\}.,6......'.c..........U..im....
.....m.........]b..F..m......X8.....r.....'$d.....<.u.gt..&..Z=...v
...e..M...M.....{.6....Z..s........73.T...$...8.k.-I]?.T..%..t...u...*
.T.z...^..........rv.#C... d`........ ......}..w.G....^..Q...Ow.YZ...W
......pZ....;...0.N\.8.t..I.8`.......?x....iuv.w9.T.'.}....Ww[.kv.....
g.I ..I...|.v...=1......W.t..2.c...}......Z.rS..s sZ...Z.7....K..^.O..
[5...fR...J..8.$s.....$......n..][]....M...l....^...RZ.D.v....v.....^.
.2...IF.!....`~|.G<.. ..;.....w}9......_......W.4..[h...ov.O..H.?..
.5..p....;...8=J...:.=4.......[........9..d.....m;..y.{4....c.....L..$
0W......;O..[...:.......k.........t..g..~...g.........d_...,......

<<< skipped >>>

GET /pic/uploadimg/2015-12/20884.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:13 GMT
Content-Length: 26589
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2015-12/20884.jpg
Last-Modified: Mon, 14 Dec 2015 12:16:38 GMT
Accept-Ranges: bytes
ETag: "5cf07a486936d11:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF............................................................
......................................................................
......................................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..........w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
.............................................?...k..*>..|..J%w..$U.
.......'-...oo......Qz(......#U.....`C).W.......V.....H..1......ROJ.U.
~#HQ.Y......9....vO .."h...... m..5.i.....qK.RWT.{....C..;..~...R.5.Fd
..nn.R ...N.y....yl.r...*F2T.OZ.}.9I.?.s.....K..Z....u{.E.....;...7L:e
.....y..[JD.....D.#....R.. .|f .... Yt....n|0...|M.//...KY.&G.X.dVV8..
H....U/...4..0....|..Y......z...v.Fc....b...F.Uv.....i.J...t........I.
y....s..L..1-I..*G".|.Be..qI.)-.$...j......M..Z..n.<...?....G.I....
MH..bH~c.5...9J...$..c..IR.....9I.. .x...E(]......b.!2.... .=?...V.;!O
Tsv^/......t....7.d....q..c.f ...<.GZ..Y........J.9.jN.N.-...y...W.
[email protected]"..b\*%Q....jXj.p......m..5..:_.o....R
..i.S]..l ..hw..5.Dp9.......>.$....*..|..k.m8.s.....o...O...|Cm.[..
X...^....[.....v.....yc...`.*\_?.vAC4.......o..g...D.O.k.$.....4:D.}.\
Ce=.{..)....*.r>`.I....X.S..c..`........[..ok.....u/.| .9.4..n....h
6..p....?xo..On;{8Z.n.8..a.....W.....D....u...].w..w*;4a.]@?w.6...

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:14 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /1.html?sdPg0uXTraCSqrOalrKpm5yoraGSrbOWlrWpz XX4dSfnaaLtq2c4aaVoNOeotzJpaWcz6iWlrepmqqbpKCgnaqVqJa0pqaLua2cj8CioZa4pqicoKOcmaaelr2pmZyzraCSuLOXoaikj8aioQ== HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: h.synacast.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: PPWS/1.1.3
Date: Mon, 23 May 2016 23:00:07 GMT
Content-Type: text/html
Content-Length: 2
Connection: keep-alive
Cache-Control: no-cache,no-store
okHTTP/1.1 200 OK..Server: PPWS/1.1.3..Date: Mon, 23 May 2016 23:00:07
GMT..Content-Type: text/html..Content-Length: 2..Connection: keep-ali
ve..Cache-Control: no-cache,no-store..ok..


GET / HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.pptv.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: aduid=4259378207094581bc4ce41514cc1b96; __crt=1464044413526; PUID=9d03cc1eb8c7469496c7fc5fc376c2ca; ad_ts=-oxsYXN0Q2hlY2tUaW1lTDE0NjQwNDQ0MTM1MjiObGFzdFJlcXVlc3RUaW1lTDEzMjUzNzYwMDAwMDD7; recordctrl0=""


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:40 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 139062
Connection: keep-alive
Vary: Accept-Encoding
Pragma: public
Last-Modified: Mon, 23 May 2016 22:56:03 GMT
Cache-Control: public, max-age=300
expires: Mon, 23 May 2016 23:01:03 GMT
Content-Encoding: gzip
Age: 277
Via: http/1.1 nb-b-ats-190-72-2 ( [uIcHs f p eN:t cCHi p s ]), http/1.1 bjzw-t-ats-1-17-1 (ApacheTrafficServer/4.2.3 [uScRs f p eN:t cCHi p s ])
............iw.G.0.9........V..`... .H !..<>....$$..$9...x......
1.7..w.....u..)..........0.....Rw..[...u.............p.....S'k?...m.{"
.V.T..9.b}8.....U.e/|-qb......F).yB.`H.G[k.-....o."Q)[email protected]...#4...
M...!^./.........KMJs...Y..\[email protected]..>..>....#R..)*W1ih&......B!.
"pQ%...O,p..9...~C_..G.......*Q.T........*u.O_.Vo...............[.....
..C..k.D...L...-u..o..........z..~u...u.....f|..>...g.....8..O..-..
J.-.........GR...<..d...7.[.K.d!m..`.M......mxB_|.D.2~kR..I..4A...O
.s.j.s}d.R_]...${T.>..[......7.VjKKZ.P.6..>Uj...........Pel..:;\
.x..V.F...c......3...mq.R....{A...l.Eu....A.5.[....W......g...m.(J.!..
.. .....k...B.D...vo.>......;..k&u..k..U.....Cb..I......5Q.o.U ..}.
..;.%.\.M..0G.Im.*...Y...T18...<HL.....}.Z..S.|..<3...&...k..y..
..gL&...l...F.......Y.......0.0d.A".4...6.i.8.0d.|b.....C..g.......&V.
....h.=..:..zf..p..F..........R..&:....c.wN.8w@}.........s..T.Q.RU..V.
.....G...t...'.&J.\O...."..=h_..).*...[-.h..D..P..(..X..dF"...e...)X&.
...&..U..E)P.%1.F..D$...D`XR..Ad%..1.J..j....=Pu(.......^...K..BTi....
.....5F.j>.E.Z .EL...o.......\SX..H...ZZZ.C.hs..l.E.!.>E.......Z
..i....O...p.. $..`.......s...B.[.....C...fP....:...V.......B: ....ub.
E.....T#[email protected]..~...>.:.,u...../\.....W/......W.&E5.u.p]....
..$F...F.....M...U....,.p.U.t>._.K...#.....7l..H....^. ...s..%.t.SO
CX.k.)..3..<i..#..}J#.Y.'s...I.(..j.....*....K..o...Vh.z.g.....G...
...=.......K..<.:.y]..V....K..............I.zs.6..k.(.&.'..zH9_s...
..3(.....V...nT..B$b2..^.yu}X..P.G<..U(.0U.b..........^....A.?.

<<< skipped >>>

GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:37 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /config/control.xml HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pp.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:35 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 5429
Connection: keep-alive
Vary: Accept-Encoding
Cache-Control: max-age=600
Content-Encoding: gzip
Age: 384
Via: http/1.1 nb-b-ats-190-64-2 ( [uScRs f p eN:t cCHi p s ]), http/1.1 sh-c-ats-204-53-1 (ApacheTrafficServer/4.2.3 [uScRs f p eN:t cCHi p s ])
...........Zko\.y.._. ."i..._.....s.Q# .D.i..gw..#..Y....5p. ..A.4E..E
[.pa.h..I..i......pI..........w..........qV..e59..M..(&.jXNN..........
.......".......w;.$........Nk.9..'.*..^L.N.....jz.,F.b..w....\<X-..
...|2)F.rZ.o.m.......z|.....8,..G..-uZ......t...y.....I..u..Z.........
*..m..X/b.Z@$t.0.......y.hl^.:....E...e...U.;.Y..J.D.....4.z......e...
Q.t....j.......t:*...`.:c-..s...._.8.....vg...gA.....J.,O.....S.H..".O
............T...?...&....*....F...].... uT........>u..1.y.$.N ..G.e
......Y.^..._0nS.Y^.}...v...[_.. ......y.XN.......;qc....Ya.I9.....4s.
[email protected].&F.2H..R.\.^..PB..B..N.e"Q.7...i.O.<.1..=J9.
.n.#.u4.*.!.:%.:.= (a......1..*X..c....h*.}n3.`.......8.........T.T..,
.Q..)B..2.!..IRKC...'..N0.L....s.9c}jC.DJ..*.Q.R.ykz...fJ..U.....N...T
.R.....|F..<.D..:..J.&.I;...v...$_,gE........f.j...&..UkT.Z....b6.Y
..3.dMzM.........Nk..3...=C`...du...z.U.W.5_m>).k..... ...H. q\pju.
.*..5.*uSb.Wr.*.k.!.e.i.x..NH[F..J.TwZqI...C..i..h..M .T.aH......&~...
7)SM.. ...,e.F.X.].Xg0.te..?...'.m.*.Y..y..t...|......{......k.....F..
.u.p!.|18......N......v.m$.g...-I}b.ck0*...uF...Z....@me...&!D...~ ..C
[email protected]/s....e6....TVH8..Rb1..=X.K`Q.!y.....
T.ZR.<L..)......b9.|.V.x.W.u}._..|.P.vZX...6.C.......#.4....>.o.
...Y>.x.o..j...d..Z......9][W......G..Dw|....l...<..Q6..3...N.(.
`U..6f5...k..{.f..f..f..f..f..k...l;.'./....&..I..m..:.....".\.%..H..f
.n..c.i..`h:*.Q....Di.'<....q.s.<9]Dn.2{.Im...&].i.L.& ..f.i..m.
.V....V...|....l.... .K...gi.c@.`.Y4...p...F.. VC..........C.....,

<<< skipped >>>

GET /images/2013/01/09/10110990986.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Tue, 02 May 2017 20:41:35 GMT
Date: Mon, 02 May 2016 20:41:35 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 6288
Last-Modified: Wed, 09 Jan 2013 02:13:03 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes
Via: http/1.1 shnj-b-ats-157-223-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8110 (Cdn Cache Server V2.0), 1.1 lsh197:8109 (Cdn Cache Server V2.0), 1.1 fra21:2 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.....d.d.....C..............................................
......................C...............................................
........................x.Z...........................................
F..........................!.1.."AQa..2Bq.#34CRS...bcrV.....%U........
...............................1.........................!.1A."Q.#.2Ba
.3q..R...............?...9...XK..J..7.c....ng!3.P.OV..$e:..."...c.xK..
..=..3&.."SP.O#f.N.Z.n...|0.........^FK....i..9T\.R...__...).}.M...1.Y
...;s...{._.K.....R......... ...<..L/.....1... .kmh6R.".....X.ok...
../.M.~].../.X.-....]..d$4l...V>.b..............)z...R...u.e......L
...m5fQw>..S..|.PnJ.[..CZ.'k..p.)..q.Q1d.%[email protected].<.
7.N.0-.4.g..3.M.|%.EejJ.}.0.....0..Y)W.....?.Nt].R....r.f.e..tFZ......
m...i./c...E.NwRsqK4U.L...Q.R.R.../....M...c.). ..Prj.:F...s.u.;.s....
.O.M.6V...U-.^...RL.."Ba.t.rQ.....p.{<.......r.*..m....IH.a./.zN..e
...;qS.4<..:....B.kB@mi<.....F>c.uR. Ok.........-W'f.".|..E.C
D)......U.$vS~|.*"[email protected].$..x?;.y.D9....^C/..-.Q...m..}.X...&l
t;........=#.....M-.ks..1G..?.E......J.n...1S...1....cS...".$..O/..&..
.9'.#.....L..}....L..P...7...........=J.c.m...b. T&...j.u.$%)$.{..7...
.o.xE.,...m..%HC..AJAF..o~_..<.v..\.}...?|Pd.T...7.j.....).4d.d....
[email protected]>*[email protected]..<..W....Hs.}.*ii..$........... O..*
..8[..%)Va..J.Q...%[email protected]_.r.,...6.'....R.l..<G. .......M......
@.ODn?#...g..`?i'2.....wAP Q....a..J......%..?gn_...0.. .FV\:.w..$....
.(.'.Q&E....c2...Y..S..Bbl...)..R...@.{s..Vg1..|..b.NGe...mM[yf..S

<<< skipped >>>

GET /pic/uploadimg/2014-4/20140103141146500.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:27 GMT
Content-Length: 11664
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-4/20140103141146500.jpg
Last-Modified: Thu, 19 Jun 2014 04:48:31 GMT
Accept-Ranges: bytes
ETag: "6ffef8b7798bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....,.,.....C..............................................
.........""""""""""...C................ ! !!! !!!!!
!!!"""""""""""""""....................................................
?...........................!1."A.2Qaq.#3B..$CRb.....4r..S............
.....................$......................!.1A.2Qa."q.............?.
..A....m.S..&..A...?.A..t..q...5..#...A.'A..|...@S..:[email protected]..
c@.[..Mp.x.r.I.0....-5F....;.H8.U...~......._0.../...O/.wu....q.8g.j.\
.C5 .@. .....3.......e.......f8_7..g.U.. ...t.....{...i.;' .....3qV..v
ys.....$..*F.%[email protected].'.cAu.g.4.f..f..1).......N..}..a..IWh.......
O.).'%...:..^......g.a.V.A..S.K.4..6.....?.Au...B.s......O*..3.0M.....
..t.%........Z..Wk....\L.."...j......,.V.....'.uk\<...s....! ......
N.k..Ci..h(.U.......s...w.v....jxz...........#..o...6..........-..-H..
v...o.. .4.9da...PY5........EmUH{4.c....1:.... d.-K..._).{4.QCM...3..*
v.2.. ..3.A........Lc..e........4.H<.zd.`v.4.J..H........h4........
..cSP"....... .F.nY...j..6L....O|.t.U[..H.2.....Q......UQ.JR>..'.._
....O;.<....7..#..p.....?.....RT.VI0f......K.. }T..../X...r...q.8..
..19.;.N.rzc...*.v....F....1bI.f...Az..P...=H9....{..S.....6.o...:z..*
F2.)..^.z....J m]l.!L.Y.z.A.N.....#........h.....af..i./|'V......E.\.h
..6U..F..\.`{...VM..v.QI.mZk.Y.E)...s...-[..K\..O..~V.....h.....nk..3&
gt;c=....s....x.d.!...?MD2..D.d...U...e.9...n...T.[l5qK-\-K,..(.......
A..N.....5r..u.."..p.....V7|u!......Ex....S}.N3.9"h........E..E..VC...
......~..k.,..u.B.....lm.|.'@M....T.N.. ..?..z._.\.:.....X.....8.j

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:29 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /sp96/2013/02/27/15264463677.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img32.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:12 GMT
Date: Sun, 01 May 2016 12:54:12 GMT
Server: PPWS/2.1.1
Content-Type: image/jpeg
Content-Length: 3974
Last-Modified: Wed, 27 Feb 2013 07:26:46 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-144-2 ( [uScHs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:80 (Cdn Cache Server V2.0), 1.1 shb113:8108 (Cdn Cache Server V2.0), 1.1 fra21:4 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), qu
ality = 85....C..............................................!........
."$".$.......C........................................................
.................`..".................................................
...........}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
......................................................................
.................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*
56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz................................
....................................................?..........B.G.$0.
..{y..Wh'....*..........?..U..l.fQ.L.._=.]\........NM%.U. [L.&....c...
.=.}j......Ww..O.uMK..P. .....w&..U.GE.|...o......^.....zu.....q...Ey.
B.p.;G#.^.|Q.z....J."5V..BT..Z(..L..(...(... ..-.8.y.Sewy=.. .M.a....Q
. .p~c...Y....)l\ ..X.q.8...8.}A...:6.......<-(.Y@^....H........Zg.
-m5..Y... O..p...].d.........W^..>.............q....=.x..J..!..i.O.
..p.....cs.K.jV......6.;.f.U....{2.....t.5./.O..T].....u.u....*....w._
3..N.j.........xX:.T...........'m..Im|.....<..#.....JX.O...........
./.............2.....6.._Q....^.lOi>.l.J..}...*.......U..N....J..{.
..O#1.Q..?...Gr..}.}.y.........^*. z...#..A..#..G.....=N...6kK.s..Pp.1
..63.......2..G:..@d....[.Wg..b~U....j>!....4.".a.2.*.v].1........Q
hcQE......~...<k..Dj.1$........i.mgpe]. ......"....kF...../.M./.x9.
.QD......y..._<.|&......h7..i....N..z.m.~.5..)....WA.g.h..VC...

<<< skipped >>>

GET /?tn=sun HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive


HTTP/1.1 302 Object moved
Date: Mon, 23 May 2016 22:59:34 GMT
Server: WWW Server/1.1
X-Powered-By: ASP.NET
Location: /index.html
Content-Length: 132
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; path=/
Cache-control: private
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<head><title>Object moved</title></head>.<b
ody><h1>Object Moved</h1>This object may be found <a
HREF="/index.html">here</a>.</body>.
....



GET /index.html HTTP/1.1

Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:35 GMT
Content-Length: 160634
Content-Type: text/html
Content-Location: hXXp://VVV.3929.cn/index.html
Last-Modified: Sat, 14 May 2016 03:29:45 GMT
Accept-Ranges: bytes
ETag: "43231dc90add11:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!doctype html>..<html>..<head>..<meta charset="g
bk" />..<base />..<title>............-........-........
......-................-........</title>..<meta name="keyword
s" content="........,........,..............,........,............,...
.......," />..<meta name="description" content="................
......................................................2015........,...
.......................................,..............................
......................................................................
.." />....<link href="/template/4567/images/style.css" type="tex
t/css" rel="stylesheet">....<meta http-equiv="x-ua-compatible" c
ontent="ie=7" />....<script type="text/javascript" src="/js/jque
ry-1.7.1.min.js"></script>....<script type="text/javascrip
t" src="/js/jquery.SuperSlide.2.1.js"></script>....<script
type="text/javascript" src="/js/common.js"></script>....<
script>var sitePath = ''</script>....<script src="/js/func
tion.js"></script>.. <meta name="baidu-site
-verification" content="yCtQO3Z1vI" />...</head>...<body c
lass="chindex">....<div id="header">...<div class="head"&g
t;..<div class="logo"><a href="hXXp://VVV.jijiyingyuan.cn" ti
tle="............">....</a></div>..<div id="search"&
gt;..<div class="ser">.. .<form name="formsearch".<scri
pt type="text/javascript" src="/js/jquery.SuperSlide.2.1.js">&l

<<< skipped >>>

GET /js/jquery.SuperSlide.2.1.js HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:43 GMT
Content-Length: 11274
Content-Type: application/x-javascript
Content-Location: hXXp://VVV.3929.cn/js/jquery.SuperSlide.2.1.js
Last-Modified: Tue, 10 Jun 2014 12:03:40 GMT
Accept-Ranges: bytes
ETag: "0f6604a484cf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
/*!.. * SuperSlide v2.1 .. * ................................ * ......
............hXXp://VVV.SuperSlide2.com/.. *.. * Copyright 2011-2013, .
......... *.. * .......................... * .........................
................. */..(function(a){a.fn.slide=function(b){return a.fn.
slide.defaults={type:"slide",effect:"fade",autoPlay:!1,delayTime:500,i
nterTime:2500,triggerTime:150,defaultIndex:0,titCell:".hd li",mainCell
:".bd",targetCell:null,trigger:"mouseover",scroll:1,vis:1,titOnClassNa
me:"on",autoPage:!1,prevCell:".prev",nextCell:".next",pageStateCell:".
pageState",opp:!1,pnLoop:!0,easing:"swing",startFun:null,endFun:null,s
witchLoad:null,playStateCell:".playState",mouseOverStop:!0,defaultPlay
:!0,returnDefault:!1},this.each(function(){var c=a.extend({},a.fn.slid
e.defaults,b),d=a(this),e=c.effect,f=a(c.prevCell,d),g=a(c.nextCell,d)
,h=a(c.pageStateCell,d),i=a(c.playStateCell,d),j=a(c.titCell,d),k=j.si
ze(),l=a(c.mainCell,d),m=l.children().size(),n=c.switchLoad,o=a(c.targ
etCell,d),p=parseInt(c.defaultIndex),q=parseInt(c.delayTime),r=parseIn
t(c.interTime);parseInt(c.triggerTime);var P,t=parseInt(c.scroll),u=pa
rseInt(c.vis),v="false"==c.autoPlay||0==c.autoPlay?!1:!0,w="false"==c.
opp||0==c.opp?!1:!0,x="false"==c.autoPage||0==c.autoPage?!1:!0,y="fals
e"==c.pnLoop||0==c.pnLoop?!1:!0,z="false"==c.mouseOverStop||0==c.mouse
OverStop?!1:!0,A="false"==c.defaultPlay||0==c.defaultPlay?!1:!0,B="fal
se"==c.returnDefault||0==c.returnDefault?!1:!0,C=0,D=0,E=0,F=0,G=c.eas
ing,H=null,I=null,J=null,K=c.titOnClassName,L=j.index(d.find("." K

<<< skipped >>>

GET /js/function.js HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:44 GMT
Content-Length: 14758
Content-Type: application/x-javascript
Content-Location: hXXp://VVV.3929.cn/js/function.js
Last-Modified: Sat, 26 Apr 2014 14:53:16 GMT
Accept-Ranges: bytes
ETag: "09628415f61cf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
/*'*******************************************************************
***********************..' Software name: Max(......) Content Manageme
nt System..' Version:4.0..' Web: hXXp://VVV.maxcms.net..' Author: ....
([email protected]),yuet,....,.... ..' Copyright (C) 2005-2009 .......
... ..........' ..........MaxCMS............100%......................
..,......................................'****************************
***************************************************************/..eval
(function(p,a,c,k,e,r){e=function(c){return c.toString(36)};if('0'.rep
lace(0,e)==0){while(c--)r[e(c)]=k[c];k=[function(e){return r[e]||e}];e
=function(){return'[2-8a-gi-s]'};c=1};while(c--)if(k[c])p=p.replace(ne
w RegExp('\\b' e(c) '\\b','g'),k[c]);return p}('function loadSlide(w,h
){c 2=1;document.write(\'<d classid="clsid:D27CDB6E-AE6D-11cf-96B8-
444553540000" codebase="e://a.macromedia.f/pub/b/cabs/g/swflash.cab#ve
rsion=9,0,28,0" i="\' w \'" j="\' h \'"><3 4="movie" 5="/\' 7 \'
8/6/6.k" /><3 4="l" 5="m"><3 4="wmode" 5="transparent"
><3 4="allowscriptaccess" 5="always"><3 4="n" 5="o"><
;3 4="p" 5="2=\' 2 \'&q=/\' 7 \'8/6/"><r src="/\' 7 \'8/6/6.k" p
="2=\' 2 \'&q=/\' 7 \'8/6/" l="m" pluginspage="e://VVV.adobe.f/b/a/a.c
gi?P1_Prod_Version=ShockwaveFlash" 2="application/x-b-g" n="o" i="\' w
\'" j="\' h \'"></r></d>\')}c s=new AJAX();s.setcharse
t("GBK");',[],29,'||type|param|name|value|slide|sitePath|pic||download
|shockwave|var|object|http|com|flash||width|height|swf|quality|hig

<<< skipped >>>

GET /template/4567/images/menu.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:45 GMT
Content-Length: 211
Content-Type: image/png
Content-Location: hXXp://VVV.3929.cn/template/4567/images/menu.png
Last-Modified: Thu, 19 Jun 2014 05:14:55 GMT
Accept-Ranges: bytes
ETag: "ef8021687d8bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
.PNG........IHDR.......,......'.a....sBIT....|.d.....pHYs...........~.
....tEXtSoftware.Adobe Fireworks CS6........tEXtCreation Time.04/23/14
....... IDAT....A.. ......_.......=..O.#...0.......sM...z......IEND.B`
.
....



GET /template/4567/images/serbtn.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:45 GMT
Content-Length: 221
Content-Type: image/png
Content-Location: hXXp://VVV.3929.cn/template/4567/images/serbtn.png
Last-Modified: Thu, 19 Jun 2014 05:14:56 GMT
Accept-Ranges: bytes
ETag: "818bee687d8bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
.PNG........IHDR.......&.............sBIT....|.d.....pHYs...........~.
....tEXtSoftware.Adobe Fireworks CS6........tEXtCreation Time.04/23/14
.......5IDAT.........D.g...&........\.4.>,....|A..kFi..b.h.D.......
......IEND.B`.
....



GET /template/4567/images/logo.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:46 GMT
Content-Length: 12399
Content-Type: image/gif
Content-Location: hXXp://VVV.3929.cn/template/4567/images/logo.gif
Last-Modified: Tue, 29 Sep 2015 13:48:08 GMT
Accept-Ranges: bytes
ETag: "2c887479bdfad01:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
.PNG........IHDR.......B.......\r....pHYs................ cHRM..z%....
..........u0...`..:....o._.F../.IDATx..}y|TU....m...RY ..@*...Q.0.....
.b..j......l..{....L.........%..#..*..E$..aI.%...V*U..........H..~&..|
R.........9.......[Z..#'....]g[..y..}-......&.l...d..RcFd..Y.csR'..'%.
0$Cru.]...W7.........j/.m...!...P......#....&.L<..0{.tg..kG.M....2.
.....wB....J?..`.....|a.%..Rli.qV. .,.1...".*..........|^..V..<0...
.pNn.M.....1..:.].C. ..q.. .Aj.!=...ww.t....~qJ.M... ^Q.K...t.W...o;.F
...?8..^..,[email protected].(... ..pK[.........:.9....s...
A'.-...`...'_..V4..D...7^..T.AEQ........q..7.YWQ-.=..2.M.]:7.oH-......
.'.`.-...zW.0...m.3G\.o....Z..>*.8..a..k....{.....N.}@#.........3fL
R|...X.D.B...L..(.........Xf.Zx..u..n...8...G..Z.u.`.y..#.|x..OO.{..y.
G.M..;iy..O..B. ..Uv.Uv<....I.=...w...&....l.{..d..{-}.........v.K.
.^.[T.......8f....f........T..P.....a@.(..F. . .R.GT.P.a.....aX....t.7
.y...>..o.D........f<p..V.0.fRZ.-.......g..M..g.u.....\.3..m....
..npu.H .SW..;.^R..XK.>..7..1DE..tN.....v?\U......?.Ak[|........N..
d.AW@!@...#[email protected]{[./.....,'.<..f.h..5.Q.....,.q....S..~.......
...1....<.L..W....a...!==8).....jIFN..W}Y-..6vU......B.S....H..,..&
lt;.Y..%9.bYe..Wj.M....$./...>=....;K*!..u..'[email protected]`U5R[{
....Gkj..[Z.rD...*.,CL.N..{.% )9'#s.....$k\....!..2&m..[Rp..5k...w..l.
l=x.....s...3...!.KJM}(...TH.G.........t..V..!.....J./w...]...(9.o.}r.
.*..lx..{..j.......1.Q......yWe....m'...Ny=-.d3P.t...P...0.z.MJ...&...
.v..........A...t.Mc'.I}j......b.....x.RP^R0y.../..m..^...GD:.b.X{

<<< skipped >>>

GET /template/4567/images/i.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:46 GMT
Content-Length: 6020
Content-Type: image/png
Content-Location: hXXp://VVV.3929.cn/template/4567/images/i.png
Last-Modified: Thu, 19 Jun 2014 05:14:53 GMT
Accept-Ranges: bytes
ETag: "ec31677d8bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
.PNG........IHDR..............%.8....sBIT....|.d.....pHYs............Z
....tEXtSoftware.Adobe Fireworks CS6........IDATx...{.$.].?.....}.....
.=0./.6...x....M...!.B.R .A.(..r....!@...(...!..l.3...!.....$....w.{w.
..3;.....q.........n..g5.......o..W..u.X]]u..4.9.s..uq..m..N..s..i.1.l
.{.}.G5d..G5V.2.v.....9...z.v.J..E.&".!p."[email protected].>.A.J...m..`..:F[7
.A..k.u..9.....!...d......2.....:.h........3:.*.x0Xk....'.d..)...l....
B_wM.....e..H).R.l6i.ZdYF..(..V......q...RvD.N}.`....k!.$.2...h4..!...
sk...h.j....bll.);.....j32....p....Y..*...g.~.km.yvv.........2j...{yy.
F.A.Vcrr.j...1.F....2....!......... .....(..Rvg...._!.Z)..K..x.bg..TW.
.r!...h.h4.T*....Z.......fvv.k-KKK.y>.q......Z..M7..t.4.u.".".V...^
.Z...%..LMMm....V..&....h......1(.....^..l6I..z..a.#..y.wg.....*..?.&.
;.@.....~(Y.J.v>..*...j..\7B...1D.j...i....#..R.{.)..........[.....
..Z....Y\\..;P..,..x../R...!...;....|.<...P.(Bk...2....I.\.....!.T*
Xk.....RO..P..sT.U.1]..~...z........`.....n...$I...cee.'6....cvv.;t...
G`.t..o........Z.<GJ.1...U..T*.`...H&]..]k.=z.s.eYO....RJ.(.....iJ.
Z%M...X.m...299I.."I......ho.....f.k-.Z.;...8..;.qU/.J.....{.).W. .<
;.N.|.v..f...T).m#?...?o...wcL.x.h|=fff.t.R7.U...}..)..w.$...R...#.Z.D
.~./.})%...crr.{T./.x.z....;.;.{-R....V.........Am...G.....]}tf..z.5..
.bii.v......8FkM.$dY..."Y.133.~...X..-.jMMM..1..}......b........o.,...
.c..?.0....7..}A/V.2#.....?.....;7....i...YZZ..C...`z...D.E7...8}.t.3.
.~'.1.q......#.......^\...g....Z.E....gy.......S...-..v......3...H....
...B.........`........[{.....{.H.......^. \..z...r)%.N..-oy.......

<<< skipped >>>

GET /pic/uploadimg/2016-5/201651411255697119.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:47 GMT
Content-Length: 44920
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2016-5/201651411255697119.jpg
Last-Modified: Sat, 14 May 2016 03:25:56 GMT
Accept-Ranges: bytes
ETag: "a216195490add11:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
....(0Exif..MM.*.............................b...........j.(..........
.1.........r.2...........i....................'.......'.Adobe Photosho
p CS5 Windows.2016:05:14 11:01:35.....................................
...............................................&.(....................
............&........H.......H..........Adobe_CM......Adobe.d.........
......................................................................
....................................................................{.
."................?...................................................
.......................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5
....&D.TdE..t6..U.e.....u..F'...............Vfv........7GWgw..........
..............5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.
T..dEU6te......u..F...............Vfv........'7GWgw.................?.
...\...bc.......^......7....:......&LSE....c.. .......-.....o..6.....&
X?5.k....8........av....w..Kjw....m.....s..0.e.O....D8..1{y...=...i...
...[n^...;.....pY.X......O[........ .......t.t...o8..=\.WGo.....}?....
.#..e.N..n;.....#.k[G.*...........G/.z.x.|!.L..!..wQ%_.C.g....=>.M.
.....Sw..vW.........f..Q....3P......9.......Is........ ...G.aSg.....k.
>.W`..r..:FG.....~..........;.,..h...2..#.....].<5..6d.$...._tzU
..m.{.....sW..S.-5:;. z...).wx....~...p.. }..~(o.....x..-?..j..._....C
.....K%.X....6k..d./..?G.......Ws|G...O....Y..1....o.=.:.. .....~.....
......g........r...z....T.V^........eu..e4z...l...>..S.]..31.Av.a.|
L9.se....\.oC.%..`...PZe...h..zn.o....F....&,...)..>.,q.'....G.

<<< skipped >>>

GET /template/4567/images/lazyload.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:50 GMT
Content-Length: 1553
Content-Type: image/gif
Content-Location: hXXp://VVV.3929.cn/template/4567/images/lazyload.gif
Last-Modified: Thu, 19 Jun 2014 05:14:54 GMT
Accept-Ranges: bytes
ETag: "cee8a7677d8bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
GIF89a............................wwwfffUUUDDD333"""..................
.......................................!..NETSCAPE2.0.....!.......,...
.......w $B..$..B.#..#..(<L.....3.....D....H$^[email protected]..."U...P#..
a..\;....1.....o.::0.v.@..$|,3......._#.....d..5..3.".s5..e!.!.......,
..........c $.....9*"#......8.3.b.4..k..B.....J....`4...<..q8...B..
[email protected]*.i.".(.)..VY..#!.!.......,..........` $.Pa.
......K*:...u.....#.@tX....!&0<..U#'.....h..m.'.@Y..^h.a-k..(......
...N......|$.C..f)@.f|!.!.......,..........b $.bA...@."&..-..".*6C....
...*... `j..4..2`. 5...X......p......h/H..`......h....R"..]SW.B].~....
(!.!.......,..........I $..q.........B.,.n[.h......*.G...U.....H.)8..G
.tJ.^[email protected]*Dm.....T.....!.......,..........q $..0.(...q.....k......
.7A.G..d....(1....0.....d...X...`U..eR!.P...T..h .(....v!_"PQ.V.e..Y..
i)..Z.`x#..'3y.|)..!.!.......,..........` $.. ..8.E...I....F0C......T@
..F.`.B4........A....b.Z.bq........ ............)/a.zSS...&.V...p$!.!.
......,..........^ $B.8."1.......0.....B...R.0..v..".B....lp....Xb....
F...a....AA&*X....(@.3....,...(.}..Q >..R!.!.......,..........c $.P
...xB. . *.-[.d..... .i@...)`..L..?'I`.JG....b.P....h......X....B.)0..
...X..Q#..}...N.o."tI ZI!.!.......,..........\ $.P`.....8.....*.....1.
....h..0.r.x8..B......Qa......V. ....!.M.D.l!..4.%..B...Be..PDY0..0!.!
.......,..........] $.$.........I>.Q........].. .d".2..8..G.qH9...A
.2.......B..."., D..H('...4...C.\0..`.UL".r(!.!.......,..........d $.d
I..`....k....B...B ...m.....A.72,....(P..X..........8@R%.a..K..*..

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 22:59:50 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /pic/uploadimg/2014-9/16865.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:52 GMT
Content-Length: 35782
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-9/16865.jpg
Last-Modified: Fri, 12 Sep 2014 00:18:35 GMT
Accept-Ranges: bytes
ETag: "166bc5171fcecf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....`.`.....C..............................................
......................C...............................................
........................f...."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..S.....
.......f..Y<q}ua..g..[.<.....m./.^.h....C.?.M..O.t...fY..5.(.{..
... ..F.|.....EG<.m....c.K3z.2k....W|8......V.x.U.84{..:...Vg....#.
....x.R9..`..(.....7.........n....cK s;(2$`......O..g<V..o.........
.5..SO=...LRo.V..S.r6.z..h...7..v.7.2,6..4.......I<..=h....>....
....i>...T.X......4.B)s.N......6...j.(...(...(.3...Ex.......5Sgu{gu
}o.i..H.K(..v,.......G...N..g.V.%.....M...r.[I.-..| [email protected]...
.M ..5..z..I..(...k.k|3..........%...Si=........O_..0.8...T.QE..QH....
..) .| .`|>......i..GW..x.f....S....g...@#.......R....W..._....SF..
.b...>).Bm...;FC....G.u8....P.....W7...G.y55.`.....D....,.M.rG....s
....(...l...0)........W....c....|.K..iwP.._2.@/...c.....<i...X...._
X.@..[R..4{.....l...i....G.H.,......k.h.......0.Bo.jP......l...8..e...
...P.......N...\...a.km.i.:,WV...k.yL.....`d....S....................{
g4...o7..6w7...'$......o.....c.]..B.....o.^!..%..8... |.V2.P_h..'.

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 22:59:55 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /getcitycode HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: iptable.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:03 GMT
Content-Length: 4
Connection: keep-alive
1121HTTP/1.1 200 OK..Date: Mon, 23 May 2016 23:00:03 GMT..Content-Leng
th: 4..Connection: keep-alive..1121..


GET / HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.pptv.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:07 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 139062
Connection: keep-alive
Vary: Accept-Encoding
Pragma: public
Last-Modified: Mon, 23 May 2016 22:56:03 GMT
Cache-Control: public, max-age=300
expires: Mon, 23 May 2016 23:01:03 GMT
Content-Encoding: gzip
Age: 244
Via: http/1.1 nb-b-ats-190-72-2 ( [uIcRs f p eN:t cCHi p s ]), http/1.1 sh-c-ats-204-55-1 (ApacheTrafficServer/4.2.3 [uScRs f p eN:t cCHi p s ])
............iw.G.0.9........V..`... .H !..<>....$$..$9...x......
1.7..w.....u..)..........0.....Rw..[...u.............p.....S'k?...m.{"
.V.T..9.b}8.....U.e/|-qb......F).yB.`H.G[k.-....o."Q)[email protected]...#4...
M...!^./.........KMJs...Y..\[email protected]..>..>....#R..)*W1ih&......B!.
"pQ%...O,p..9...~C_..G.......*Q.T........*u.O_.Vo...............[.....
..C..k.D...L...-u..o..........z..~u...u.....f|..>...g.....8..O..-..
J.-.........GR...<..d...7.[.K.d!m..`.M......mxB_|.D.2~kR..I..4A...O
.s.j.s}d.R_]...${T.>..[......7.VjKKZ.P.6..>Uj...........Pel..:;\
.x..V.F...c......3...mq.R....{A...l.Eu....A.5.[....W......g...m.(J.!..
.. .....k...B.D...vo.>......;..k&u..k..U.....Cb..I......5Q.o.U ..}.
..;.%.\.M..0G.Im.*...Y...T18...<HL.....}.Z..S.|..<3...&...k..y..
..gL&...l...F.......Y.......0.0d.A".4...6.i.8.0d.|b.....C..g.......&V.
....h.=..:..zf..p..F..........R..&:....c.wN.8w@}.........s..T.Q.RU..V.
.....G...t...'.&J.\O...."..=h_..).*...[-.h..D..P..(..X..dF"...e...)X&.
...&..U..E)P.%1.F..D$...D`XR..Ad%..1.J..j....=Pu(.......^...K..BTi....
.....5F.j>.E.Z .EL...o.......\SX..H...ZZZ.C.hs..l.E.!.>E.......Z
..i....O...p.. $..`.......s...B.[.....C...fP....:...V.......B: ....ub.
E.....T#[email protected]..~...>.:.,u...../\.....W/......W.&E5.u.p]....
..$F...F.....M...U....,.p.U.t>._.K...#.....7l..H....^. ...s..%.t.SO
CX.k.)..3..<i..#..}J#.Y.'s...I.(..j.....*....K..o...Vh.z.g.....G...
...=.......K..<.:.y]..V....K..............I.zs.6..k.(.&.'..zH9_s...
..3(.....V...nT..B$b2..^.yu}X..P.G<..U(.0U.b..........^....A.?.

<<< skipped >>>

GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 22:59:51 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /catalog.xml HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: client-list.pptv.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:04 GMT
Content-Type: text/xml;charset=UTF-8
Content-Length: 1395
Connection: keep-alive
Vary: Accept-Encoding
Expires: Mon, 23 May 2016 23:01:56 GMT
Retry-After: Mon, 23 May 2016 23:01:56 GMT
Cache-Control: public
Last-Modified: Mon, 23 May 2016 22:56:56 GMT
Etag: d531941e28cdb4b7797f0e4d663270c0
Content-Encoding: gzip
Age: 188
Via: http/1.1 nb-b-ats-190-64-2 ( [uIcSsSfUpSeN:t cCSi p sS]), http/1.1 bjzw-t-ats-1-15-1 (ApacheTrafficServer/4.2.3 [uScRs f p eN:t cCHi p s ])
...........XQO.V.~.."...}}.}-.*.....ll..7......i.G..T..... .V:...`@..2
.Ll'.bv|..>A.x...~.;...9W.o=..O=.... .z..#UI.....c..=.....J%u.. =U.
WR.I.O..H.G..............I.W...Dj.A.2......*3.Tw4..1.D.F..V<......A
.o..x,k.1S.#}@!......E...8"I.n......!..AD....A@...&..d..f....3..'...39
H&...Xf.dS..p"h..4I:9.T.r..M.3.C....x.J"p.....I.V.R.{d!b..}.e#.A.YK...
.tR.A...SW.q.....MHd.. 5.CF..}...q.P..F...p...h....'....:..1I....`....
9...LZhl.b..x..J....89.T..].{...H...y`-....*..B... .A.e.3...."....Bjs.
.......tY....Mo .(.".2.{..3x.......h..,B [email protected]]......N.
*c......_.U3T..j..GIMO..G}>J.X.xqC5M...[...KLn...4..4........;.....
.zNN.....x.].}..k.....tG.4....74..v.....K...D8..............uw........
..W..|@.7..<.T#.km...=..q...|..E.|.~..[{}.];....=@3:.#h.........#hZ
X<..'@.B..V.....8.......4M....S.u_...c.A.L.L.H.(.......|..=n...BH.-
.*.½......xXqi-#.l/.d)#.....h^...=.!..)..U..}\. ...S.F(J....hD^. .{.
Y..Y.z`....s{[email protected]@;.7..E....UL;
..5i`..U......,...B....d.yh..~......P..M,U..V....X.....d..U#3.....5.&.
..M...M..<...T..v........y......?.P...E.'..l.pf...E.y..k>/]{~...
.....n.4...Nn..F......J...>......G.1:..a...C.,....|...9.{a.......YP
p.......l...u..0Y.......!.h.Q..;..#...McK._....c..F H.8PA....g..w.....
...z$.vR.l..].b...Mk..&.sa^=...b..Y....}..o.;yg&.....b&#...O...k{v..`.
.-....C..;yS...X8k..y..Z......4D...Zp...s.w.n...,.......}m...:'...t7.y
{....?.z...W.........

<<< skipped >>>

GET /v2/logo.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Tue, 26 Jul 2016 19:47:52 GMT
Date: Wed, 27 Apr 2016 19:47:52 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 24027
Last-Modified: Tue, 09 Aug 2011 03:58:26 GMT
Accept-Ranges: bytes
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-144-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:8108 (Cdn Cache Server V2.0), 1.1 lsh198:80 (Cdn Cache Server V2.0), 1.1 fra21:2 (Cdn Cache Server V2.0)
Connection: keep-alive
......Exif..II*.................Ducky.......P......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
0 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpRights="hXXp://ns.adobe.com/xap/1.0/rights/" xmlns
:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.
com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0
/" xmpRights:Marked="False" xmpMM:OriginalDocumentID="uuid:4F87D7FFC2A
9DF119DD2E63169DCD889" xmpMM:DocumentID="xmp.did:7AFDD8FFB99711E0B0549
62737D1D0E1" xmpMM:InstanceID="xmp.iid:7AFDD8FEB99711E0B054962737D1D0E
1" xmp:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:Derived
From stRef:instanceID="xmp.iid:89C2E16C97B9E01183C19DC2FE33F336" stRef
:documentID="uuid:4F87D7FFC2A9DF119DD2E63169DCD889"/> </rdf:Desc
ription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&
gt;....Adobe.d........................................................
......................................................................
.....................,................................................
..............................................!1..AQ.aq.".2#..Bbr....R
..3$....CScs..de.W...t.%v.G.......................!.1AQq..a...."..R..2
Br...b....#3S5...cs$.%&C............?........D.%.(.DJ"Q...D.%.(.DJ"Q..
.D.%.(.DJ"Q..$....:G.4.\....b.....j..H...sz..qDJ"Q...D.%.(.DJ"Q...

<<< skipped >>>

GET /mini/portal/111205/images/build/v_09151721/style.css HTTP/1.1

Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Thu, 26 May 2016 17:26:38 GMT
Date: Mon, 23 May 2016 17:26:38 GMT
Server: PPWS/1.1.4
Content-Type: text/css; charset=utf-8
Content-Length: 3946
Cache-Control: max-age=259200
Content-Encoding: gzip
Via: http/1.1 shnj-b-ats-157-63-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:88 (Cdn Cache Server V2.0), 1.1 shb115:8104 (Cdn Cache Server V2.0), 1.1 fra21:0 (Cdn Cache Server V2.0)
Connection: keep-alive
.................W......!Q....t.I...b...u [..F.TY.K...>.?..E..i...%
)R:$.ey2.b..F#.\xxn<$.....w.CX..j..\...W.CuL.C.....s.o.wIT....M.=..
<...k.u..<........W..._.....j^.....#.... .....G.6/.*..U.g1}.:..q
i...(...ual8Qr.D..UN.9...S'M.....s....9....)....Q.......8..x.4..Y.$Yq.
......a$.2........_.y.;........$[.."..$....*..q..K....%..S...k.p*...h.
'...c.).2>..mX..:...<G........t.........W.i.J.C\&U#..F...c..t.'.
...N..D...,T..(L.}.J...v.j0..:...._M..N.....j..6....T..M...2....pxO:.$
.......4.V.....J..T..gL}sY.}.....s%?Ut8{g..x....q..........?V...z.M...
}..zK.b:.W.W.(9.i....I.....!.v..n)t\..%|_2>.9..).JQ.)..[......`.5V.
8..?$.'G. ..1...vF>....]....I....zK/....\..*/V3*-6.. lm.3t..\.#w4.r
..s..S3.Q;.4.9.I&8....C..D8......$>.k..y.P_tO..cY...?...?0.$.)..r.3
`N. "..#A9H..G.|...i0...."...L...o....t..b..(..e\.a.g...W..%.S8..... .
...t."..(.o......L.m~..w.|.d......pS?9.'...txA D.!l...9k.s.g.;........
Z."...._......hB=....O.(.a... ]6A....\Cr..L...q..s#e*..).....$.{:..P..
.]E<.I..9........n..c...........gT....\....I.hb..k.,.|.....?.)....q
...].l.F..&....3|... .x.u.K.."...>.(......3....p......G.].!....%..Q
W.<.....z....1..Oc.Q..Q#-...g..4N.x...o..n..|WzK.........G%)nB...X
d.......#.[......x....~O....R..::.ri.O.p..........>aQ.]i......{..`Z
.(...7..(l.X.^.!.j...~5.k`..j....H.....z(M.6..U.dt...~.r.]....{.,..{..
..F.V..!..G2I...hB..TCvz..y._4dU~.>.._h..=.J.6.....Vv....9.p..)....
..3#[email protected][..L...c.... ....B...
.V}b...x..s.......P....z;..%..T.r......F5..E.'"..9.n.(..g....tx...

<<< skipped >>>

GET /mini/portal/111205/js/common2.js?v=09151721 HTTP/1.1

Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Thu, 26 May 2016 12:41:55 GMT
Date: Mon, 23 May 2016 12:41:55 GMT
Server: PPWS/1.1.4
Content-Type: application/x-javascript; charset=UTF-8
Content-Length: 3664
File-Path: /home/pplive/staticSer/static1-8/mini/portal/111205/js/common2.js
Cache-Control: max-age=259200
Content-Encoding: gzip
Via: http/1.1 shnj-b-ats-157-215-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8106 (Cdn Cache Server V2.0), 1.1 shb114:8106 (Cdn Cache Server V2.0), 1.1 fra21:2 (Cdn Cache Server V2.0)
Connection: keep-alive
...........Z[o.... .ta. C.v...=Nm9..Hv.n...5..E.%.T..dE....S......}.C.
...............f..A...r.\.sf..Y..(M...w#...Ah..9..>=vy..mF.{.f....!
....>7./..8....NZ.!K.0~..6..k..4[...tq.G..S......j..g.....*.......[
.w.............r..aQ.m....Q.gQk...b.`T_..C.........4.8.i_..`.*...h..3n
T..*NA0h:.,.S2.|.i.....l.&..R.."-I...E.!....?m..b.. .........O.i......
!..$...%T......q......f..a(.s..aY.7.r..}.=%[email protected]?1<.PD=.Z~.|.._.
I.F3NY......._...^..d.......p.A=..B.C.. ..ES...8.*%.|.5bs.F.......43DL
4...7W#g:..F...%v....:[email protected]..(..;b...h.^..nu{...>.4b.e..
u..0p.....*.\.lP..............F..#bv.-.,".8.R..W}Cx.1..6.}...I..Fq`..2
..M......B...ek!Q[....>.d....$.....]..(\..~.....B....H...J....y.Tg.
9.H..U....Z.C.3..Kv....l...kq.E.#.*(...........8.@"~...#...{..}....`Bt
..ndY......t... .w|..6.x.B3....(.f.....WW.?...../F...8....<...-....
va....m.h..%...-O..T.:}DC777........^...ql... .U...ncw.Y.o...C...._}..
.6o.v..a..|v N1F..,}............r..)........f.T ....*#.EL..V...cs..W&g
t;.$..m[. ..... ..u......9)..!k.vXo..%..:.#..p.@T`.H....s....P..Q.(..e
V..n&...'X..T..9!......t.....tmE;M.8.......j.Z_V..=.P...k..-..&.....~.
.on...Po.."...z^.Q..v...kpX1..s..~..t_c`.PU0.-..........GGL$Rm.p......
..E...V....a#..p.4...W...P.,...I....=.ywR.kE.~....o..... .7|.....>.
.I#I..!..04.;[email protected].=i.|.CQ4....wNO..{......yS.|L.L%.R,...c..........
.o.#..M~......_..o.......EU_.!.....Cg....$%.|..?..}.>......E.g....#
hx.........qjB...U.`&......E......9....o.iO.....Z.1...B].. p.e..YT..O.
......7.5..o.0(g.aB......^.a........?.B:..Z..............mX...\1Cc

<<< skipped >>>

GET /mini/portal/111205/images/build/v_09151721/bg_portal.jpg HTTP/1.1

Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:12 GMT
Date: Sun, 01 May 2016 12:54:12 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 6472
Last-Modified: Mon, 19 Dec 2011 08:26:53 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-142-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:8108 (Cdn Cache Server V2.0), 1.1 shb115:8080 (Cdn Cache Server V2.0), 1.1 fra21:6 (Cdn Cache Server V2.0)
Connection: keep-alive
......Exif..II*.................Ducky.......<.....mhXXp://ns.adobe.
com/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?&g
t; <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-
c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf
="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description
rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRe
f="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://n
s.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:05EB9F2DCDA6E0
118E94AC1434D6439D" xmpMM:DocumentID="xmp.did:8884535DAB9911E0A2A1BE45
21E5E5BE" xmpMM:InstanceID="xmp.iid:8884535CAB9911E0A2A1BE4521E5E5BE"
xmp:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:DerivedFro
m stRef:instanceID="xmp.iid:121938CB4EA8E011A378D088D1EDFE24" stRef:do
cumentID="xmp.did:05EB9F2DCDA6E0118E94AC1434D6439D"/> </rdf:Desc
ription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&
gt;....Adobe.d........................................................
......................................................................
...................T..................................................
..................................!1..A.br#Qq."...a..2B.3s.$..d..R4%.C
c.&.....................!1.Aq............?..K...c..V..4.........`X.j%.
."..X...)p"X....`X...X,H. ..`X...`X...`X.*X...-.X ..........6...9.....
..f..O.y.............-..B...B..eD........D[[email protected]...,....,
....,....,[email protected].?.....<..F.e..^.....`X...`X...`..b-.`D.`.....

<<< skipped >>>

GET /v2/logo.swf HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Mon, 23 May 2016 23:45:18 GMT
Date: Mon, 23 May 2016 20:45:18 GMT
Server: PPWS/1.1.4
Content-Type: application/x-shockwave-flash
Content-Length: 42677
ETag: "DQyw7IRBDx4"
Last-Modified: Mon, 14 May 2012 03:20:26 GMT
Accept-Ranges: bytes
Cache-Control: max-age=10800
Via: http/1.1 shnj-b-ats-157-146-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8109 (Cdn Cache Server V2.0), 1.1 lsh195:88 (Cdn Cache Server V2.0), 1.1 fra21:0 (Cdn Cache Server V2.0)
Connection: keep-alive
CWS.....x...y<U]....s..PIH.HdL....#cfe..Y...e..$..B....."...L..y&.y
....{.....}..|^.u.:.^......Z.i..7...1......@[email protected][email protected].....
......G[].=.J.R@=.....>`^.zZ_.....r..X..y......lm./{k.;....psv....;
.{[;.... ....lm<,.Z.....-..j.C..V..tm.<..=|.s...^.....;..V..mN9[
..N..k.....N....ag.. }...._....h..{.8...Z..l.<.g'...9kk...fJ.......
......T.c....?...X`3.>.]i.=,...qd.FSm R...=.. !=.!=.C=1.K.d9.......
...G...V.X...d!.........V...k.6rMv.....k?...`....(i.g....<.N.j.G..P
!.....G...........}.<.].I....ZP5. @.[t6.E........c.-.7.=..1q..9....
.....HR~.K..LG.!.. O*.1..~q.i`.`..lH.=r..)...2j..PW..;..r.a.'....c....
#..{..7...i..ni.s.... ..L0................H:Z.PJ\&..#.]x......o.HH..,.
.Sw..|....9.R....w...I.N.3.p.8...D.%.c..!...|.M.F.!.l.|.LR .W.q2.....E
..:......>i..C...l>.u..H.F.....O.=&`..8.-.~h..".#.G../..7N.P1.;.
9.q'...=. ...'.NH..bK.k...tDb..9. ...\.C..5..g.. ..q....n%...h..93w".i
x....w...........q#.....#....5(......7x....YH...l...g5.m0.A|.....v..K.
..o.6_....N....9..=..C..;...Yj..0..x...~G........o|[email protected]..
=..ip.....<.M_..S....n....-k.&:....N...5.Az. ..g..u.0..X.......c..
.{M4./....0#X4Q..._......n.O.X.>...!............a..(M.c...C#.c.D...
|....b.;H.%H........C.&H;....=.11"'A.y/G..R...#._\..J.....A..d.wz.....
2AIm...=\o.~u.....1....\.#./...2 ..Vk....z...8V.W.....4.f.....ZA.S.. 2
..1..l.....k'.z.....6.....0f...p9..3.:......BC.8.q*0.}5....%....c\.7.7
j8.?....W...*nq..^.c....D...8E..{..OH3.l.G..X~..M.`T.|P.....U-Bf.....
.8.........=...c....b.".3Z).3\.#|.\.K*.9/o[e#..........*3..;.... .

<<< skipped >>>

GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:27 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /location/ HTTP/1.1
User-Agent: AutoIt
Host: api.liqwei.com
Cache-Control: no-cache


HTTP/1.1 200 OK
Content-Length: 91
Content-Type: text/html
Content-Location: hXXp://api.liqwei.com/404.html?404;hXXp://api.liqwei.com:80/location/
Last-Modified: Fri, 25 Feb 2011 05:13:24 GMT
Accept-Ranges: bytes
ETag: "ccf928baaad4cb1:46bfb"
Server: Microsoft-IIS/6.0
Date: Mon, 23 May 2016 22:58:37 GMT
<html><head><meta http-equiv="refresh" content="0;url=h
ttp://VVV.ibicn.com/"></head></html>HTTP/1.1 200 OK..Co
ntent-Length: 91..Content-Type: text/html..Content-Location: hXXp://ap
i.liqwei.com/404.html?404;hXXp://api.liqwei.com:80/location/..Last-Mod
ified: Fri, 25 Feb 2011 05:13:24 GMT..Accept-Ranges: bytes..ETag: "ccf
928baaad4cb1:46bfb"..Server: Microsoft-IIS/6.0..Date: Mon, 23 May 2016
22:58:37 GMT..<html><head><meta http-equiv="refresh" c
ontent="0;url=hXXp://VVV.ibicn.com/"></head></html>..


GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:35 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /sp96/2012/10/26/13470667633.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img32.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:12 GMT
Date: Sun, 01 May 2016 12:54:12 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 5674
Last-Modified: Fri, 26 Oct 2012 05:47:07 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-145-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin240:8105 (Cdn Cache Server V2.0), 1.1 lsh197:8108 (Cdn Cache Server V2.0), 1.1 fra17:6 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), qu
ality = 85....C..............................................!........
."$".$.......C........................................................
.................`..".................................................
...........}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
......................................................................
.................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*
56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz................................
....................................................?..[.:...mr.{D.!..
...0.d.x<t$T...u.gV.uMM....H....!x..R.p.....}j..,...``..Qj.|..J.&I#
r.!..qZ...DFz.u.._..:.j..Y.......#...*.........w.....:.!4..k.....d..y.
...<......w.Q..H.}.k...|9.[.$.....h...`pOA....Y.s..w<.......{.B[
S..q.....^.tP.p...c..J...K...z......{].N...cM.p m?{..A..3......r.E...,
.a6;...9\..k/C./.f.R....... .._JqJL.9%s......7T{.KP...5..Y gi|d...m.u.
.Xz....G................"..^...s.E|.e..I!$..O.g..Y~M.W.eL...Gz..."..l.
./.>".<7%....s".-.F....z...d........f...u(.YQ#v[t.......n..\m..f
.....%|n ...WN.M...Y.X.c.......s..t...<w.......`.B..w.T(.n..W'....Z
....:\...i..>f.....x.N.....G.Fy&..O.>DQ..ZR...8UR.....fP.S ...G.
.^.....54....G.,qc-...\.@\.8n..A. ..t....<.-.`."y"i.*2.$ ......K^.:
....\Os..r!.....;.]=..A..3...q...-5.|]we<i..;'.........~#.......L..
....y..f....... .........;K..u..}...O...R............S.Z>)Y....

<<< skipped >>>

GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:34 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /pv/1.html?plt=clt&adr=hXXp://client-mini.pptv.com/portal/12345.html&radr=&puid=9d03cc1eb8c7469496c7fc5fc376c2ca&uid=&vip=0&o=&src=clt&r=0.5800773738672186 HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: web.data.pplive.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: PPWS/1.1.3
Date: Mon, 23 May 2016 23:00:16 GMT
Content-Type: text/html
Content-Length: 2
Connection: keep-alive
Cache-Control: no-cache,no-store
okHTTP/1.1 200 OK..Server: PPWS/1.1.3..Date: Mon, 23 May 2016 23:00:16
GMT..Content-Type: text/html..Content-Length: 2..Connection: keep-ali
ve..Cache-Control: no-cache,no-store..ok..


GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:35 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /pic/uploadimg/2014-6/6383.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:37 GMT
Content-Length: 14146
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-6/6383.jpg
Last-Modified: Fri, 20 Jun 2014 07:12:04 GMT
Accept-Ranges: bytes
ETag: "c97b18f0568ccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222...........".....................................
...C.........................!.1.AQa"q...2..#BR....3br..$.C....&6T....
..............................0.......................!1.A."Q.2aq..R..
..B................?......*L.VO....#Z...1.z..(G...(6.....P3.J.T.8.....
q..................S".U.'...Y.p.nFr .....s!D.......3..K.$..V.......S.U
..a):H....T.LWU~!.MY.:OP..<..(#.<..6...._.;wg.n.v..e.Wa<SN..&
.s..,.y.E%.FN*9......8 .b.>....K..wM',...J...3u^...M....J..x.qKd7/M
..I..N.s.S..g..g.R.>%......u._.can..N.c.{.......m%xY.Fvc.k..Q....At
....h.>.!...x#¬.Ov...[OEh).......c....Iy..q...........}(..N._e.5.
,..`..3..Y.F.C.A.V{.?c.v.r.....Q..9...9....{...sE.,.FI.....2k[...I!...
9P./..la`N0q.L.T!]..b..u.A0hQ.B....>1C.f.......b.K...8...._.[......
.nS.yS.m..UF.....F..m`.i'.....J8....VRp..B..!.V.r....CfS...'.c.Li...u.
..K..}.N/B.2..'.d..i..........!.....J......0%.b5r.{<v.........V...c
<../......o../I.7.m......p...##...z]..v.qak,pgah.8..[~u.i.=.E.b....
.1s..x...sN..T..H..v....V).ZX.$QL..X...'..\.O!}.A5;E..._..V9.........0
q..r).......Y....... .|7.}............E.q......^..(..4...W.\...bB.s.G.
A......E.K,...Y.~x.....Q.Z..j.q../.`..W...>..!E....;/.7.=...|...|..
..V..............".X...j....?.....qQ...!O....I...jh.....:....n...x..&l
t;..o.c.`.W...)u.O...o....>.?t....(..Q.c....T..QMu...I..... ..G.3.W
...p.}O'J..z.....1S.Q.E.u5...>.O...a..L..P.....N.9.t..B..P.4...

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:39 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:15 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /pic/uploadimg/2014-4/20140210202824891.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:32 GMT
Content-Length: 15515
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-4/20140210202824891.jpg
Last-Modified: Thu, 19 Jun 2014 04:48:39 GMT
Accept-Ranges: bytes
ETag: "64d2efbc798bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C..............................................
.........""""""""""...C................ ! !!! !!!!!
!!!"""""""""""""""....................................................
I..........................!."1..AQa#2q..3BR.....r..$b....LSUc.ETs..
..................................7........................!..1Q."Aa.2
Rq#B.......$.b..3C............?........4.E....#..n.M..-s.......Zu.v}2K
m.L.......WK'.1.x.o..f(.QZ.f2 .[..%r...................[.tCS.....h....
l.._D.x.F).>&.H............%;60..\...g.n..<..9SPR7.`.....c.....n
.N...[...O.xgn.#..*s..d..HO.jsd....Rm.............v..-...L......m.T*fM
.cv.Vg.4....R..aD.<...:.. P)..6u........!..l>. a.LAK..pJuJb..J.]
....2.X..E.S..kRSJ.#.qvH..^.V...(.Y...9.......NH..C..>..q..........
..B./..c............q.....,..:#k.c.C..[.Zu$.}.....9x.....v.....H5.P..P
UB...Z).e....x_..b...V.qq...jZ}Ya<......k.[[a....{.QQ, t4Qz....!...
R.k..6.......[I.e..d.G...GR..K...F.?...........niv.J.\.%....l.%.I.|...
'[email protected]^[email protected]......
/.. ..I%......m..'F.}....(...<.......8.....>@[H.a...fd_...=m.W.I
...'...Y.O.Z..A..........N...fk\?.~..K..f..:....=..A.ht>X.pk.......
... 9Na.i......o.{...k..GYK.*y^.........^C..ci...k..51.......%. j....E
.....m..(......S...t[.C.t.Y>.....*..je.][.C.ZF...........pc.x..t...
.Z^.....m..;&......6hq;.k....9.]5)U..:W........'.T..c....^.......s..*.
{.`.P...-zC(.6...:...........O.An...|..=U...)..z$:j.Si,8.:...)/.....)j
:...{ ......L_..?...y../..Wb....)..P..)...!%...).u..*d...k:..H6.O.

<<< skipped >>>

GET /pic/uploadimg/2014-4/20140210201622899.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:34 GMT
Content-Length: 13756
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-4/20140210201622899.jpg
Last-Modified: Thu, 19 Jun 2014 04:48:37 GMT
Accept-Ranges: bytes
ETag: "9365e2bb798bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....d.d.....C..............................................
.........""""""""""...C................ ! !!! !!!!!
!!!"""""""""""""""....................................................
K...........................!1"AQ..2a.#Bq...3Rbr..$C....4.%5...DScs...
....................................<........................!..1AQ
."2aqBR......#34.S.....Cbc..............?...i...=....}....5.aUJ.]Q.#..
...n./B..|.8...R...&1....\n.`.J{[email protected]=
b.....b*%X.i..*.b...:.n..*....Fr.....X....>z.V9d.F4zH...y.....S....
q,,|sG.y...k.....>..qy.J.. ..*W..x.......5..g....k.2.Vi.r[....4.5V.
IX........"q.@C..#.............&...x.....5..z....`5..*sW&.....fJ.h....
.....jN........kI-.J.O<..n.......&=......T.D..e..v....=....}i......
1}...M...E.zw...........e..%....\....x..?.a....2.-l4-....2G.F.0.y.M...
{...e...... ....c...8. .E.:../....B...M4A..N........>......G?....W.
|.....6../.}./t.l...;...............2.a..R..w...L.y..I...*.3.../....2=
..Q.T.Rt.y[..........U.$...Sq.U2S.G....<...Dj..*...s.;..ujk$..M....
.Y{@.K..OIOn...CD$Y*X$.V..%H....k...xF...7..x...[Up.Y.cS ..(.t>.Q..
~C\....)9.....8...... ...OK.....v.....u...(.......L......$AQh.....!...
6....iQO...h.O....c..7/.............L.......tQ......^...$r.8..'#......
.P.3...t...........&.FJ..'..s.z:..S...p..hxC.,.\.IjH.O..2.).0.c...y.w.
ZPW...&.V...R]a...M.U..$.......T<".h.9.SEG.:Q.<..{uS....S.Te.S&l
t;.G....~\..1.....WS ...1.8.....:.......ov.7......t..x.....h..KIU6J ..
...~4."..S... ..*`!..z.:`;[GS54...I.)?'....8.-.D...J54. .><.

<<< skipped >>>

GET /pic/uploadimg/2014-4/20140210201418264.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:34 GMT
Content-Length: 10248
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-4/20140210201418264.jpg
Last-Modified: Thu, 19 Jun 2014 04:48:37 GMT
Accept-Ranges: bytes
ETag: "35de9abb798bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....,.,.....C..............................................
.........""""""""""...C................ ! !!! !!!!!
!!!"""""""""""""""....................................................
G.........................!..1."AQa.2q..#BR...br...$3C...s...45Dc.....
...............................9.......................!1.A."Qa2q..b..
..#[email protected].^QJ.p5(..y.zSF-.d..'y/`...1....
..Via.."CuyQI.:........i..../Y;.|...7.X..........3.Q..JQ.wr00..~..>
....[...|..........w.....| ....=..>..m....]@......P..]5zS..........
..e)..t..uI4%@..n..ExX...)gdk.. .V|..$IN/..}.~...... 9.......Q~.FK....
`.q..D'...F...e*.>D.S.$..)9..m.1H.L........Q..j.wF/..l.Wt1......7.y
....b)!=..5...n.....>.......u.484.... .VJ.....|[email protected]%.
.w..zvP...:...6..29.9S....R....:.t.........b7)!$$z.......C....T@......
...k.....?e.H..P.H...<z...rF)3ezJt...j6y.R.*`J6.....7..q...[.......
..........J..Vz......Su.j.....R.U...{..n...J.|.9.`...r;.4.... ....%\..
.h.N...A...u1.I*.o.p..%..w.....v...os....?....t.._TRE..5..r....]H. o..
....t.....Wzw..d...!D..clc.t........xKs.5...}.....S.g?.'.g...=.i.p..N(
...h..r.1.....-.P.l.{...>U'.........n...........\...H...IR..%......
xP......XV.ijl.......&.;@....ed|..1!.j..(...-......P.........F.....@..
..........ni. .>...E{.N...L.L...t.P..x.T.. ../S7....|Gp...N.../).?.
Db.F..>._x...ug...,....m..xvCw...:..kS.RB......8......'..fZ....)b4.
.8.....I..I (%..T..%).4F.k..gG...8.e.....-.....P5,h...*..t}.c.......q.
.......g*..?:|p.9..*....:U..R.w...4...8...{o.....Aan..!....... .]*

<<< skipped >>>

GET /pic/uploadimg/2014-4/20130304191422116.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:35 GMT
Content-Length: 18297
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-4/20130304191422116.jpg
Last-Modified: Thu, 19 Jun 2014 04:48:23 GMT
Accept-Ranges: bytes
ETag: "a28961b3798bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF............................................................
......................................................................
......................................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..........w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
.............................................?.."...y.aalG..<X..@.]
8.........^.....k......W.ZN.1...ww.D..0.U...Z...x........$.ay..#.v1..J
...C..v...Q...4...g.4....P...d....iI.o,..E..w~.T..O.....v'.l|}.x....?.
.KG.O$........B.....c..e..^...S:......g[......1............UT..m...lq.
....z...q.. [email protected].....'...X...[a'@........NFq..2.G...Y
3......@e<.9.z..vf...K*zT..%.;P.........F_.........K.0.....<...
.. .... ....Z.2p.2I.O..>N....h.<3o...k.]Ou3..]i....G..a..y ..V..
...n.D..h...)C..^......[...[s.nO$....x>.._.<Kk.hiy.jv.6...Upz.V.
e=.=.9.7d..8 ......^>.....N...}.y.... .......;.b .h.j......."....J.
p...b..ynE.l..-...]?.....f. .^h...N.Y.........H.H..3. x.<....V6V:2-
.<./{.}..fiX3.......,..8..>=d....{.Rt..../... ....6.]YAs.9.3}...
.g*.D7;mF8..:..T...pl.....4....k..i>...........k....FT....<.....
.q.QjIn{..M.C.............n.u9.. .>An. ./..u^z...g.......c.X..w6.I.
.@.~s..C.g...........].........:W..XQ.Z.L....2~&.r..?..W.iwMg..i..

<<< skipped >>>

GET /pic/uploadimg/2014-4/20140410235243256.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:36 GMT
Content-Length: 8106
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-4/20140410235243256.jpg
Last-Modified: Thu, 19 Jun 2014 04:48:43 GMT
Accept-Ranges: bytes
ETag: "8f6d6cbf798bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....H.H.....C............................................##
&&##0///02222222222...C......................$.....$)# #)'($$$(',,)
),,221222222222222..........."........................................
....................................d.S...%}L.Z...!..N.......(....wA@.
...k f*Z!..k....6...L...AZ.Q..s.V.0.-h.or.{./ j...P.y....@Xt... ..' ..
y.<...e.......-.6....:*r.P.8.....VK...q.....g.......p...b...M......
{..~....B...A...m..@......,.....d.m.En!...<.[.]..p.&...z...3M3...\.
$..1...;......q..D...\..;U..D[zi5mq..p..Z...a..:..}....-....2l.FV/.-.k
..&s..........A0.E....Y.N.......;0ku..B.E..5*R...V'. Yk....w.:...f....
.i.Sr.m...'[email protected]~.5$="$.-.4.f.9Rb..49..^jM...3...,i...x.y..J.|.
.....&...]x.[1.. )4K$r...lb....\q..H......;.u.^..]..... N..{.Mn. =....
.(............................!"12#A. 3$...........f.k.....i... ....q
U.......x...6.^=...w/..~=....l{..Uj$C..sj../Kj{9.mCB...QUdT.eWJZ...MTT
..4..=Yu-.ek.r...-.!...g..$.Q)_e.-p .........,5.3...z...{O.~.p"\ .N..]
..jD. ...Z.;lA5.J..T ...o....r..hli.v|.'#2.T..N....yv=..)X..2B'.oK%O..
*./..!..r.x..T..Y.("2..1k..#..v.#..O...}....*...b.,.3...X....5........
[email protected]>E.2.I....K.5N4l....4....j...u.;..!;l..
..........ov.p.....(...9...g#,.....M.pR......!.W...s...V[.E...J>;c_
...fi..&n\.8.}.c.Z..U..:7L}..|/.....B.....nn..~......R.Z.Tib..s.....Q.
.,...fl\.f......}p.M./#.....#.......-0.\[email protected]#.../....`2
-...#...Z.V..f.........bV=F...'.........S&....i..}@.Kn..|Q.6....rV....
.mOinbwXM...Y...E...G ......m...?.........;.Ud.X.}....O~...E5)..3.

<<< skipped >>>

GET /pic/uploadimg/2014-4/20121129171512084.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:36 GMT
Content-Length: 18564
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-4/20121129171512084.jpg
Last-Modified: Thu, 19 Jun 2014 04:48:22 GMT
Accept-Ranges: bytes
ETag: "6a4dcb2798bcf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....`.`.....C..............................................
......................C...............................................
......................................................................
..H............................!."1A.2Q.#a.$3BRq....b...4Cr....Ss....%
5c.................................5........................!.1A."Q2a.
...#Bq...$R...3..............?..[.....z..M...].vt..(...:}..N..."..U.4.
.........u.cP-......#..hc..Fp.i..t...fM..."..e^.W..3..{WsV..r.u.pX7.u.
/2.F#...ZrZ".h..;...?T..n.uS.>....D..aO..v.Nd.Y..[...<#-...}..@.
.).N>..;W.......l...I~..j.&P....h..6...........2=..S.V....U....Z.).
...V]Ji.p).c..\....L....O.J<..E&.B...{.nt.....)].T..v..Y..5.0..e1T@
...TT..|..-4....N._.*....2..b..gR).......<.5...Mye==....._.f.1.....
..idWU...E.HO....,..a[BpG)......X....xhT.....U ..gmn*ER..[.$...#.H....
...8`H.r.X\..V_.....&.m....U(.m.W.=D.............2..[Sq...B...r=.p....
.Z.?...&E.f.5*...~...]1a%....7.S.............N.....~......C.jukr...U.q
..G..f.... ......N..%EM...K..\.z............5.......l.p.....*....S.[..
..Q.. ..K.P.9T...n5&..9.......w%T...9e$....o9.m.t...f.yu?%...q.2.M...e
.'.hT...^..Y..>.*Z\.......5>[email protected]....#A...T......:e
.g._G.........7.Nu2..YpY..8.e.4....b..(<s...]...U..9Ul...F.V.eW.@..
m..ZC{.Ou.......$........=..\^.q.G.N.bO.A......{.I.m..vW.W..S..4.4._..
...`.;.D..b..^..\*2q......|c...3....D.d.Z...5......QrCsE.|..."a{..U.:S
.<....f.s....>.....E....}.%....;p....6...Q......BqH..~.....jM...
..3J;.s..6.....J..n .g<.fM<Q<$...A...~.....\Q.P.M6:|.....

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:37 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /zh-cn/ad/adconfig3.html HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: live.v2.pplive.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 301 Moved Permanently
Date: Mon, 23 May 2016 23:00:05 GMT
Content-Type: text/html
Content-Length: 255
Connection: keep-alive
Location: hXXp://VVV.pptv.com/
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">..<html>
..<head><title>301 Moved Permanently</title></hea
d>..<body bgcolor="white">..<h1>301 Moved Permanently&l
t;/h1>..<p>The requested resource has been assigned a new per
manent URI.</p>..</body>..</html>..HTTP/1.1 301 Move
d Permanently..Date: Mon, 23 May 2016 23:00:05 GMT..Content-Type: text
/html..Content-Length: 255..Connection: keep-alive..Location: hXXp://w
ww.pptv.com/..<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
..<html>..<head><title>301 Moved Permanently</tit
le></head>..<body bgcolor="white">..<h1>301 Moved
Permanently</h1>..<p>The requested resource has been assi
gned a new permanent URI.</p>..</body>..</html>....


GET /tg14.html HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.81830.info
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Wed, 18 May 2016 01:57:34 GMT
Accept-Ranges: bytes
ETag: "0bb4a5a8b0d11:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Mon, 23 May 2016 22:58:29 GMT
Content-Length: 2324
<!DOCTYPE html><!--[if lt IE 7 ]><html class="ie6">&
lt;![endif]--><!--[if IE 7 ]><html class="ie7"><![en
dif]--><!--[if IE 8 ]><html class="ie8"><![endif]--&
gt;<!--[if IE 9 ]><html class="ie9"><![endif]--><
!--[if (gt IE 9)|!(IE)]>--><html><head><meta http
-equiv="Content-Type" content="text/html; charset=utf-8"><title&
gt;</title><meta name="viewport" content="width=device-width,
initial-scale=1"><noscript><meta HTTP-EQUIV="REFRESH" con
tent="0; url=/legacy"></noscript></head><body><
;script type="text/javascript">g_oV=(function(){var.Dv=document,ayG
=location,C_=Dv.createElement('script'),azL=false,LE;C_.defer=true;C_.
async=true;C_.src="//VVV.google.com/adsense/domains/caf.js";C_.onerror
=function(){ayG.href='/legacy';};C_.onload=C_.onreadystatechange=funct
ion(){if(!azL&&LE){if(!window['googleNDT_']){ayG.replace('/legacy');}.
LE(google.ads.domains.Caf);}.azL=true;};Dv.body.appendChild(C_);return
{ayv:function(oo){if(azL).oo(google.ads.domains.Caf);else.LE=oo;},bq:f
unction(){if(!azL){Dv.body.removeChild(C_);}}};})();g_oX=(function(){v
ar.ayG=window.location,nQ={},bH,ayF=ayG.search.substring(1),azD,azF;if
(!ayF).return nQ;azD=ayF.split("&");for(bH=0;bH<azD.length;bH ){az
F=azD[bH].split('=');nQ[azF[0]]=azF[1]?azF[1]:"";}.return nQ;})();(fun
ction(){var azx=screen,QW=window,ayG=QW.location,azK=top.location,Dv=d
ocument,RH=Dv.body||Dv.getElementsByTagName('body')[0],azH=0,azG=0

<<< skipped >>>

GET /images/play-img.png HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:32 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (.
.


GET /webdelivery/webafp?ap=201401&ct=js HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wafp.pptv.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:13 GMT
Content-Type: application/x-javascript;charset=UTF-8
Content-Length: 39
Connection: keep-alive
Set-Cookie: aduid=4259378207094581bc4ce41514cc1b96; Domain=pptv.com; Expires=Sun, 11-Jun-2084 02:14:20 GMT; Path=/
Set-Cookie: __crt=1464044413526; Domain=pptv.com; Expires=Sun, 11-Jun-2084 02:14:20 GMT; Path=/
Set-Cookie: PUID=9d03cc1eb8c7469496c7fc5fc376c2ca; Domain=pptv.com; Expires=Sun, 11-Jun-2084 02:14:20 GMT; Path=/
Set-Cookie: ad_ts=-oxsYXN0Q2hlY2tUaW1lTDE0NjQwNDQ0MTM1MjiObGFzdFJlcXVlc3RUaW1lTDEzMjUzNzYwMDAwMDD7; Domain=pptv.com; Expires=Sun, 21-Aug-2016 23:00:13 GMT; Path=/
Set-Cookie: recordctrl0=""; Domain=pptv.com; Expires=Sun, 21-Aug-2016 23:00:13 GMT; Path=/
Expires: Wed, 31 Dec 1969 23:00:13 GMT
Cache-Control: no-cache
(function(){.var __pas_pic = [];.})();.HTTP/1.1 200 OK..Date: Mon, 23 
May 2016 23:00:13 GMT..Content-Type: application/x-javascript;charset=
UTF-8..Content-Length: 39..Connection: keep-alive..Set-Cookie: aduid=4
259378207094581bc4ce41514cc1b96; Domain=pptv.com; Expires=Sun, 11-Jun-
2084 02:14:20 GMT; Path=/..Set-Cookie: __crt=1464044413526; Domain=ppt
v.com; Expires=Sun, 11-Jun-2084 02:14:20 GMT; Path=/..Set-Cookie: PUID
=9d03cc1eb8c7469496c7fc5fc376c2ca; Domain=pptv.com; Expires=Sun, 11-Ju
n-2084 02:14:20 GMT; Path=/..Set-Cookie: ad_ts=-oxsYXN0Q2hlY2tUaW1lTDE
0NjQwNDQ0MTM1MjiObGFzdFJlcXVlc3RUaW1lTDEzMjUzNzYwMDAwMDD7; Domain=pptv
.com; Expires=Sun, 21-Aug-2016 23:00:13 GMT; Path=/..Set-Cookie: recor
dctrl0=""; Domain=pptv.com; Expires=Sun, 21-Aug-2016 23:00:13 GMT; Pat
h=/..Expires: Wed, 31 Dec 1969 23:00:13 GMT..Cache-Control: no-cache..
(function(){.var __pas_pic = [];.})();...

<<< skipped >>>

GET /images/2013/01/09/10144547146.jpg HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Tue, 02 May 2017 20:41:35 GMT
Date: Mon, 02 May 2016 20:41:35 GMT
Server: PPWS/1.1.4
Content-Type: image/jpeg
Content-Length: 7410
Last-Modified: Wed, 09 Jan 2013 02:16:03 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes
Via: http/1.1 shnj-b-ats-157-143-2 ( [uScMsSfWpSeN:t cCMi p sS])
Age: 1
X-Via: 1.1 dxin240:8108 (Cdn Cache Server V2.0), 1.1 lsh195:8107 (Cdn Cache Server V2.0), 1.1 fra17:2 (Cdn Cache Server V2.0)
Connection: keep-alive
......JFIF.....d.d.....C..............................................
......................C...............................................
........................x.Z...........................................
.C............................!1"AQ..2a.#Rq..$34BSb..TUr.....5d.......
..............................>........................!1.AQa.."q..
..2R.....B..#bcr..3S................?.......sl.....oc......9P.........
........K'.....]BW..J.A#...C:....r...{.C..>]..@...,.n....lt....RO..
.].....5,p........=_X?X....R......: .uC...[.VYl.........T....dg@.`....
.....C...I......vWV........Kzul.<p.........O..E4d..Q......T....w..m
xB.......v.@. ...49XJ......!H.[.{......2g.^m.. 6..w,.p...u.jc.3#..Z..&
lt;....9..e{7..T8....._m)S........6.P.G.L..P...T.......=...<...uV..
.p.T......Hu<.,.F0?.....Z..V.a ...(.....g}.<.....Ge..A!E.0..(..I
...h....T.....z..vM4......D.....Uv.9 nC....O\.*.......S.{3.Q.._M)k../.
....|....U.7..]..}......:.2..V.....8rR.V.Hp'.......z..Q.....J./..<.
..;...vjE.Ji..HTTP/1.1 200 OK..Expires: Tue, 02 May 2017 20:41:35 GMT.
.Date: Mon, 02 May 2016 20:41:35 GMT..Server: PPWS/1.1.4..Content-Type
: image/jpeg..Content-Length: 7410..Last-Modified: Wed, 09 Jan 2013 02
:16:03 GMT..Cache-Control: max-age=31536000..Accept-Ranges: bytes..Via
: http/1.1 shnj-b-ats-157-143-2 ( [uScMsSfWpSeN:t cCMi p sS])..Age: 1.
.X-Via: 1.1 dxin240:8108 (Cdn Cache Server V2.0), 1.1 lsh195:8107 (Cdn
Cache Server V2.0), 1.1 fra17:2 (Cdn Cache Server V2.0)..Connection:
keep-alive........JFIF.....d.d.....C..............................

<<< skipped >>>

GET /hm.js?3767faaa77a89d77b80cba3753456e42 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hm.baidu.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: max-age=0, must-revalidate
Content-Encoding: gzip
Content-Length: 8806
Content-Type: application/javascript
Date: Mon, 23 May 2016 22:59:46 GMT
Etag: c11cd960e40cce10ccdaedc6a7a9250c
P3p: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Server: apache
Set-Cookie: HMACCOUNT=4B645ACB55C07847; Path=/; Domain=hm.baidu.com; Expires=Sun, 18 Jan 2038 00:00:00 GMT
...............(function(){var h={},mt={},c={id:"3767faaa77a89d77b80cb
a3753456e42",dm:["xiguayingyuan.cn"],js:"tongji.baidu.com/hm-web/js/",
etrk:[],icon:'',ctrk:false,align:-1,nv:-1,vdur:1800000,age:31536000000
,rec:0,rp:[],trust:0,vcard:0,qiao:0,lxb:0,conv:0,med:0,cvcc:'',cvcf:[]
,apps:''};.;.{......p..`5........l.]....X..I..l...c..IZ...wF.CN...{...
..3....d.<5R.LB.....wi..E...;.9.....[.....,..a.....~H'.s..V.....Ij/
2.>..8'j........[..e..../6..k1~z;.......%.4.Oc.F.g5.F..../..D..*..x
<^...f.].M.....(...Pv..bvhd.Xa......U......T..^.~>.l..m.........
.GK&DI.D...kN..`2.UlAQ.Uov&r.,b/.......Y/A.|'..m.,`.X.Ox......3a...h.6
L#..dV .m..m.m. ..........eg.4.N..|...)....}....0....v......<...EJ.
..8-..".&vn..#....:.."..S.e....A.6.l..;..b9.{.$......7B.|x6...GZ......
X.j1P.4.......3.eox..d.$..2.6..|..k.... ..[RX.....j.....~{7......9...g
.1....S4..#Kb..F.......`.s.g....9H.....T0..D<.'.{%...&...Yd..@.."O.
.{...8....$.,3.A.R.x.M,....J.....)...Q[. ` .....Z...?]B....[,....UMK.,
Y..L.|...u....p_.&.tE.D....9.&r%...t.Kf.H..d.i....&.....b...Xf..I.N.&`
...&...-.YC...P.......%0.e..%_.....!..!ShaU..D0.........&...K.pJt.....
H..V......)(}.d...Z.d...*.Z~......T;... [email protected]..
r}3...50.TG....#..`K.|....~......,..c......E.4.|gp..a!^..w<Z.......
Fh....(l*..ge.....i..,Y....I..`."5.3i.....F.........n......:*t.`..QL.&
lt;...v....ge..!.9...yt..@....`I......E.k._.'..(A...].0.........n... .
......n!k...>...(x..Fnm....n...7.l...e3.f ..6S.LM.8..on...y#;....f.
....F..#........".E..p......GM..3W....f..8.!. .b.>.c....J......

<<< skipped >>>

GET /hm.gif?cc=0&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1691788267&si=3767faaa77a89d77b80cba3753456e42&st=1&v=1.1.26&lv=1&tt=吉吉影音官网-吉吉电影-吉吉免费电影网-吉吉影音在线观看-吉吉影院 HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hm.baidu.com
Connection: Keep-Alive
Cookie: HMACCOUNT=4B645ACB55C07847


HTTP/1.1 200 OK
Cache-Control: private, max-age=0, no-cache
Content-Length: 43
Content-Type: image/gif
Date: Mon, 23 May 2016 22:59:46 GMT
Pragma: no-cache
Server: apache
X-Content-Type-Options: nosniff
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Cache-Cont
rol: private, max-age=0, no-cache..Content-Length: 43..Content-Type: i
mage/gif..Date: Mon, 23 May 2016 22:59:46 GMT..Pragma: no-cache..Serve
r: apache..X-Content-Type-Options: nosniff..GIF89a.............!......
.,...........L..;..


GET /pic/uploadimg/2014-11/18154.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:14 GMT
Content-Length: 85036
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-11/18154.jpg
Last-Modified: Mon, 10 Nov 2014 12:10:53 GMT
Accept-Ranges: bytes
ETag: "e3a93860dffccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.....`.`.....C..............................................
......................C...............................................
............................."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?......R.
"..{..P>.....6..W..8.Go.|I.?......e.....$q........os1.C!s..)..u.n..
9I...qz.........2......V..5....iU$.y....^./...D[70\.u.z.F....U0...o...
.scQh.{...(...R....q..9.Y4..#.'.O?.y.k.u3".......d..~...WPW*......J.]8
_tt.w.c...7.py..s\.........M.W.5^K...W ..._..\.P.....S.8${t...M....S..
F..D".D1N..gp#..:..x....'P.0..N..4...^O..>....b...C..:.VDR1...|.K..
..s..z....j]..`..D.G.....qv....6.w.....'...H..mo(>\.3J.....G.......
...-`\$..9.A]..G.]..d..1E$nVA..Y.g.r1...aM.......).}e......Il......(..
........./..g. )[email protected]...'8.R.......G.F.....=.u..4.e".......n{W.R.&.
S..[......=.......p..Z.%.V...<....Z.....Q...t.!V .*;.z..j`..OkI..nB
..)..;.:c......$.[byb.vd.P....x...5.9&...G...t.:.S..A....I.R.%U....3..
O.8.....C\\.Z...8....{......wZ]...o.$y..$.O.q.......q...H.UP..r01.g..&
gt;...=Jx.z|.Z.D...|....8 .).9..]..s.....Q4`.F.x..<.sU%.$.2y..7rz.}
*...vz..7.N......z..7.3...".n...]=....C...9..n..ip.U.1...p....R.4.

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:18 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /sta.js/ HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Mon, 23 May 2016 23:06:21 GMT
Date: Mon, 23 May 2016 22:06:21 GMT
Server: PPWS/1.1.4
Content-Type: application/x-javascript; charset=utf-8
Content-Length: 2086
Pragma: public
Last-Modified: Mon, 23 May 2016 20:26:38 GMT
Cache-Control: public, max-age=3600
Content-Encoding: gzip
Via: http/1.1 shnj-b-ats-157-63-2 ( [uIcRs f p eN:t cCHi p s ])
Age: 3233
X-Via: 1.1 dxin239:8108 (Cdn Cache Server V2.0), 1.1 lsh197:8107 (Cdn Cache Server V2.0), 1.1 fra17:3 (Cdn Cache Server V2.0)
Connection: keep-alive
...........Xks.6.. .6..!LII...E...<f.m..?I...A..D2$$....{A.....;..8
.........w.M$T.G...f.cN.*}.oy....).F|....Wo)....I.............W....s..
...&S..*.>.*.Wb...?9Y*./.z/.s.Q..........0S2...y....; C.R..E9jYG...
....f..C.....8.l2s=....{N.SX.K.KR..0.=...p.M....]..'^*.}....".j..&N*.2
.$&T8.8.0rP.........o.......d.4V.d.L..\. ....(..Z..>*..6.U.y...y.T.
.*V@..)..O...3..E..uo..d4W.w.&p..6....L...n.......c"-.e".............?
......A..\.aY.=.8.p...D.<..c.r^.....T.`.J..s.......p.p.x...4y..kL^r
...5...b...2.>}..#.....<3A..f...J/.fq..M..0gb....=.._4..........
..g...u......p5...`5G.<.".,^.\...\.i...u.@..}A}V........9s....j....
x...y.....U..f..&........0.Li....|"f...S<V.xV5.~,6k.h([email protected]
.y.A9|.8.0hU.N.:I.u.R..p......./~.4...M.}1.......U......../w...%..j.DM
................:.#.Op..P;D.}B.....*y....C......?.x.]..g.E......H$ .$.
Y.9E...D.....{.F3.."......!1..u.tt<w.8..I....G..!4<;.X....,..B&g
t;.i...I......1..I~.| .Q.%........[.......eU...;.[3.<E\.l......3..w
[email protected]:.At..gxLv_M..........$$.]>................h.f...*[email protected]
..V.h_.[.t..uW....V.H.f. ...lm.un_., [email protected]\
.\..z..\-f..5....v...o..`m..@...[./..w..F.d..8..^....d.6...j........&.
.y.M....m.@ .V..3{k.l..u.ut_.;....cG..K..........u...&A..l....Cg..$:.&
gt;.k....i-..P...y....E.8..!.'........o~...>.A........R..^.0.H..5&l
t;..y..hnV.t$d.^..%,.A.Mm.....v.H.L...H'F.d....@..........%Uj.X.-7.e..
C..!..3.P............q......f..4..~.#.j...)..yNJ.g.L9..}.6H?i...A...9.
...r.;.....8...DB.j|29p.l.v]..2.d.RW. ]:i..hx.P......U...u..;C?...

<<< skipped >>>

GET /pic/uploadimg/2014-6/6363.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:26 GMT
Content-Length: 9735
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2014-6/6363.jpg
Last-Modified: Fri, 20 Jun 2014 07:00:11 GMT
Accept-Ranges: bytes
ETag: "f8a66a47558ccf1:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............;CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), qu
ality = 90....C.......................................................
.............C........................................................
.................x..".................................................
...........}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:C
DEFGHIJSTUVWXYZcdefghijstuvwxyz.......................................
......................................................................
.................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*
56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz................................
....................................................?.......3G5...v.$c
..U....I.w2_4?)?gf.1=1Yz.........C398..e.....)~.?...0...5.....8.{...K.
.5..v~.Jq.5......kW....o............}m.w..#...o.$....7...u-..z.O..U.$.
......k.........[..mBKk.....[!...)...J...;8[...#ya...........j.....&..
Q%....rA.~......f._$.............]kZ..u.n.V.s$...6....YJ..!...U......{
]3...j.vu...o...3.. ....... .....q:.....U.....'....[.V`1..&../......Hc
..3...W....n..2kif2B..H.C....0e............Emmm..uh.s4.i...........$u.
.5U1r...s..SrQ.&.D.....4$v...;).~.d..H..#.....,J.q!...... .o.,.G....Yf
M'Mk.C /......8......<c....2.....L}Ia...k.I.Xm<..\....pK.-n.=(..
]r.N.G...om,.j.q.o...4.Tr.$..~u..]..o.gM...qZ.3.$..l>[email protected]\
I..|.x.....5GQ.g..h..E.......Nf.[..\(#.x..y.9J.t..?W....2..si.i...1...
be!~..RI...K..t.$.......p7...}#B....9?.%.e.U..[.I..Q...Y....."....#R.d
r....X....S.7..H...J.....4V. <[email protected].)..V%...x.

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:27 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /js/ads/index01.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:46 GMT
Content-Length: 141
Content-Type: application/x-javascript
Content-Location: hXXp://VVV.3929.cn/js/ads/index01.js
Last-Modified: Sat, 14 May 2016 03:28:46 GMT
Accept-Ranges: bytes
ETag: "1e3055b990add11:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
document.writeln("<a href=\"http:\/\/VVV.bomao.com/reg/cde7de70\"\'
><img src=\"\/pic\/gg\/960-90-1.gif\"border=0 width=1200 height=
90><\/a>")
....



GET /pic/gg/960-90-1.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 22:59:46 GMT
Content-Length: 42652
Content-Type: image/gif
Content-Location: hXXp://VVV.3929.cn/pic/gg/960-90-1.gif
Last-Modified: Mon, 04 Apr 2016 01:04:58 GMT
Accept-Ranges: bytes
ETag: "059b81e8ed11:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
GIF89a..Z.................i..-..9..{...2.D4..1...........&.<3.s...%
..6.o(.l..G}.......... V.w...D./a....EH.....W.pq.....e.....A..{..6....
.......s.O...G..C.....'.KR...........>....>r..T..4........:..T..
............2...........Z....\...y..3..,.i........Y...........f.......
.K...........sJ.&M....?B..T..........[...O.t.....'[email protected].
>V..............f.d..YT..J........,.n...K..*..........!?.....A.....
!.......z...........?...Y..?....t..Zw........ ........................
.....(..E.....Z.....#.....7..U.1=.9g..F.V...............e.....G..|....
.I.Pd..g....;\.a-........Y..$.r2.K$.(Y.1I..............N....F^....B...
........C..\.....d..s(.......|.....n.....}...........xL.......i.......
.Ly._q.....4........=....c..u.........E.......~........Dr.......^a....
.H..D..T.......3f......!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket b
egin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="a
dobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-
14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02
/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="ht
tp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/m
m/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:C
reatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:9
A92041DBFE511E58784AC88FB7D7788" xmpMM:DocumentID="xmp.did:9A92041EBFE
511E58784AC88FB7D7788"> <xmpMM:DerivedFrom stRef:instanceID="xmp
.iid:9A92041BBFE511E58784AC88FB7D7788" stRef:documentID="xmp.did:9

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 22:59:49 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /pic/uploadimg/2015-9/20568.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.3929.cn/index.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 200 OK
Date: Mon, 23 May 2016 23:00:00 GMT
Content-Length: 68090
Content-Type: image/jpeg
Content-Location: hXXp://VVV.3929.cn/pic/uploadimg/2015-9/20568.jpg
Last-Modified: Sun, 20 Sep 2015 10:23:16 GMT
Accept-Ranges: bytes
ETag: "1020145d8ef3d01:40e2"
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
......JFIF.............C..............................................
......................C...............................................
..........................*.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?........
.H.....Z.o.7..u.f..............>D5e...<.8...o..P.z.1Tg;.3...E...
.&....#.k;..wS.d$.sU.dS..m....?...[w....w........]...).[[email protected]....
...9%}...`.b/$.c..k..tA.... b.O..`..1..qZv..?.Vyc....Z0.......8.....gW
.........(E.x.1uq.A..F..7..i.6.o...9..x.r;[....4.KrI.V...;......H5.S..
.VG.C.*.F.5.... k.%..=}*..v.E-.3v./'.......m1..\....\.r.....v.F8..y..^
Sw..ieR..U....Xi...\}.K<[email protected]..'...~!....,.H7..y.0O..G...vG.
."...I...\\...Dr..>@@.8 .A.qZ...]6y.....9<....Q]q.....5..Z."...~
c...&..#.....T...'Y.........I..r1..N9..Wap..lQ.c..z4l. g.......!......
Q.ry.M...#........L.I...`.....z..`.....4e7...$..3d..M...J..V<e>.
;...= ....sb..Q.....U.v9...'.~......xh.........&.J.c8.....<....U
..UrG]...3..q......8.M&.:..1.}u5x.O.Cws?..%l...Ic....MW.....7]........
...-6m:t.v....(...6......t/.......:...4O.h.Im.K...l...D`..u.$2.....TU$
.._U.o...t...g..O...]x..........$.Ga....`.RZ...Sw,..pAr0.p....g...

<<< skipped >>>

GET /images/play-img.png HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.3929.cn
Connection: Keep-Alive
Cookie: ASPSESSIONIDSAQQBTQT=MCGICFKBAHJCEJDHFJJKJCDC; Hm_lvt_3767faaa77a89d77b80cba3753456e42=1464044388; Hm_lpvt_3767faaa77a89d77b80cba3753456e42=1464044388


HTTP/1.1 404 Not Found
Date: Mon, 23 May 2016 23:00:05 GMT
Content-Length: 1308
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET
X-Safe-Firewall: zhuji.360.cn 1.0.8.8 F1W1
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "hXXp://VVV.w3.or
g/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>.....
.......</TITLE>..<META HTTP-EQUIV="Content-Type" Content="tex
t/html; charset=GB2312">..<STYLE type="text/css">.. BODY { f
ont: 9pt/12pt .... }.. H1 { font: 12pt/15pt .... }.. H2 { font: 9pt/
12pt .... }.. A:link { color: red }.. A:visited { color: maroon }..&
lt;/STYLE>..</HEAD><BODY><TABLE width=500 border=0 c
ellspacing=10><TR><TD>..<h1>............</h1&g
t;....................................................<hr>..<
p>................</p>..<ul>..<li>...............
.........................................</li>..<li>......
......................................................................
......</li>..<li>....<a href="javascript:history.back(1
)">....</a>....................</li>..</ul>..<
h2>HTTP .... 404 - ..................<br>Internet ........ (I
IS)</h2>..<hr>..<p>..............................<
;/p>..<ul>..<li>.... <a href="hXXp://go.microsoft.co
m/fwlink/?linkid=8180">Microsoft ............</a>..........&l
dquo;HTTP”..“404”........</li>..<li>....
“IIS ....”...... IIS ...... (inetmgr) ....................
....“........”..“............”..“.......
...........”........</li>..</ul>..</TD><

<<< skipped >>>

GET /mini/portal/111205/images/build/v_09151721/bg_bottom.png HTTP/1.1
Accept: */*
Referer: hXXp://client-mini.pptv.com/portal/12345.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static1.pplive.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Expires: Sat, 30 Jul 2016 12:54:12 GMT
Date: Sun, 01 May 2016 12:54:12 GMT
Server: PPWS/1.1.4
Content-Type: image/png
Content-Length: 335
Last-Modified: Mon, 19 Dec 2011 08:26:53 GMT
Cache-Control: max-age=7776000
Via: http/1.1 shnj-b-ats-157-142-2 ( [uScRs f p eN:t cCHi p s ])
Age: 1
X-Via: 1.1 dxin239:8080 (Cdn Cache Server V2.0), 1.1 shb114:8105 (Cdn Cache Server V2.0), 1.1 fra17:4 (Cdn Cache Server V2.0)
Connection: keep-alive
.PNG........IHDR............. L^>....sBIT....|.d.....pHYs.........B
.4.....tEXtSoftware.Adobe Fireworks CS4........tEXtCreation Time.07/29
/10...E....IDATX...M..P...s. .ih'...#[email protected]".t....E.4.< x..
..K..5Lq....}.F-..3...\.B...&""...a....<.....,.d...qO....F""....&|w
.7......{.z.Wc.Z.......|..%""...g....3.....oZ...........IEND.B`.HTTP/1
.1 200 OK..Expires: Sat, 30 Jul 2016 12:54:12 GMT..Date: Sun, 01 May 2
016 12:54:12 GMT..Server: PPWS/1.1.4..Content-Type: image/png..Content
-Length: 335..Last-Modified: Mon, 19 Dec 2011 08:26:53 GMT..Cache-Cont
rol: max-age=7776000..Via: http/1.1 shnj-b-ats-157-142-2 ( [uScRs f p
eN:t cCHi p s ])..Age: 1..X-Via: 1.1 dxin239:8080 (Cdn Cache Server V2
.0), 1.1 shb114:8105 (Cdn Cache Server V2.0), 1.1 fra17:4 (Cdn Cache S
erver V2.0)..Connection: keep-alive...PNG........IHDR............. L^&
gt;....sBIT....|.d.....pHYs.........B.4.....tEXtSoftware.Adobe Firewor
ks CS4........tEXtCreation Time.07/29/10...E....IDATX...M..P...s. .ih'
...#[email protected]".t....E.4.< x....K..5Lq....}.F-..3...\.B...&""..
.a....<.....,.d...qO....F""....&|w.7......{.z.Wc.Z.......|..%""...g
....3.....oZ...........IEND.B`...

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

%original file name%.exe_704:

.text
`.rdata
@.data
.rsrc
s%j.Zf
tGHt.Ht&
tCPh
SSSSh
\$%u#Sj
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
GetProcessWindowStation
USER32.DLL
operator
This is a compiled AutoIt script. AV researchers please email [email protected] for support.
uxtheme.dll
kernel32.dll
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
erroffset passed as NULL
POSIX collating elements are not supported
this version of PCRE is not compiled with PCRE_UTF8 support
PCRE does not support \L, \l, \N, \U, or \u
support for \P, \p, and \X has not been compiled
(*VERB) with an argument is not supported
ICMP.DLL
advapi32.dll
RegDeleteKeyExW
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
MPR.dll
ole32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WININET.dll
WINMM.dll
WSOCK32.dll
GetProcessHeap
CreatePipe
GetWindowsDirectoryW
GetCPInfo
GetConsoleOutputCP
RegDeleteKeyW
RegCreateKeyExW
RegEnumKeyExW
RegCloseKey
RegOpenKeyExW
SetViewportOrgEx
ShellExecuteExW
SHFileOperationW
ShellExecuteW
RegisterHotKey
GetKeyboardLayoutNameW
ExitWindowsEx
EnumThreadWindows
GetAsyncKeyState
SetKeyboardState
GetKeyboardState
GetKeyState
VkKeyScanW
EnumWindows
EnumChildWindows
MapVirtualKeyW
CloseWindowStation
SetProcessWindowStation
OpenWindowStationW
UnregisterHotKey
keybd_event
InternetCrackUrlW
HttpQueryInfoW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
zcÁ
%s[Ck
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"></assemblyIdentity>
mscoree.dll
>>>AUTOIT NO CMDEXECUTE<<<
CMDLINERAW
CMDLINE
/AutoIt3ExecuteLine
/AutoIt3ExecuteScript
%s (%d) : ==> %s.:
Line %d:
Line %d (File "%s"):
%s (%d) : ==> %s:
AutoIt script files (*.au3, *.a3x)
*.au3;*.a3x
All files (*.*)
#NoAutoIt3Execute
APPSKEY
04090000
%u.%u.%u.%u
0.0.0.0
Mddddd
%s (%d) : ==> %s:
UDPSTARTUP
UDPSHUTDOWN
UDPSEND
UDPRECV
UDPOPEN
UDPCLOSESOCKET
UDPBIND
TRAYGETMSG
TCPSTARTUP
TCPSHUTDOWN
TCPSEND
TCPRECV
TCPNAMETOIP
TCPLISTEN
TCPCONNECT
TCPCLOSESOCKET
TCPACCEPT
SHELLEXECUTEWAIT
SHELLEXECUTE
REGENUMKEY
MSGBOX
ISKEYWORD
HTTPSETUSERAGENT
HTTPSETPROXY
HOTKEYSET
GUIREGISTERMSG
GUIGETMSG
GUICTRLSENDMSG
GUICTRLRECVMSG
FTPSETPROXY
\??\%s
GUI_RUNDEFMSG
SendKeyDelay
SendKeyDownDelay
TCPTimeout
AUTOITCALLVARIABLE%d
255.255.255.255
Keyword
AutoIt.Error
Null Object assignment in FOR..IN loop
Incorrect Object type in FOR..IN loop
HOTKEYPRESSED
AUTOITEXE
WINDOWSDIR
3, 3, 6, 1
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_USERS
%d/d/d
c:\%original file name%.exe
:C:\%original file name%.exe
HCan pass constants by reference only to parameters with "Const" keyword.

IEXPLORE.EXE_652:

%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG
;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512

IEXPLORE.EXE_1332:

%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG
;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512

IEXPLORE.EXE_1676:

%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG
;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512

regedit.exe_492:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_1604:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_604:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_264:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_1944:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_1864:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_256:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_1112:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_220:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_1900:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

regedit.exe_1500:

.text
`.data
.rsrc
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
comdlg32.dll
SHELL32.dll
AUTHZ.dll
ACLUI.dll
ole32.dll
ulib.dll
clb.dll
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
regedit.pdb
udPj
WSSSSh
WSSSShA
mSSh\
u=SSSShH
uKSSh
_acmdln
RegCloseKey
RegOpenKeyW
RegCreateKeyW
RegEnumKeyW
RegUnLoadKeyW
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegRestoreKeyW
RegSaveKeyW
RegFlushKey
GetProcessHeap
SetViewportOrgEx
GetKeyState
ntdll.dll
RegOpenKeyExA
version="1.0.0.0"
name="Microsoft.Windows.Regedit" type="win32" />
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites
LastKey
regedit.chm
Software\Microsoft\Windows\CurrentVersion\Policies\System
.classes
Windows Registry Editor Version
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
REGEDIT: CreateFile failed, GetLastError() = %d
x x x x x x x x x - x x x x x x x x %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
riched20.dll
0xx
0xxx
x x x x x x x x x
x x x x x
%#08xx
5.1.2600.5512 (xpsp.080413-2111)
REGEDIT.EXE
Windows
Operating System
5.1.2600.5512
Export range
&Keys
Import Registry File
&Key Name:
Channel;Port
Port:
Port
&Import...
&Export...
&Copy Key Name
&Export
New Key #%%u
New Value #%%u
regedit.hlp
Registration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.#Text Files (*.txt)#*.txt#Win9x/NT4 Registration Files (*.reg)#*.reg#All Files#*.*#
If you still see this message, try restarting Windows.
Export Registry FileMRegistration Files (*.reg)#*.reg#Registry Hive Files (*.*)#*.*#All Files#*.*#
All Files#*.*#
9Registry editing has been disabled by your administrator.(Finished searching through the registry.*Click the computer you want to connect to.ACommand line argument requires a filename and none was specified.
@Are you sure you want to delete this key and all of its subkeys?
Confirm Key Delete-Are you sure you want to delete these values?
Confirm Value Delete Are you sure you want to delete this value?GAre you sure you want to unload the current key and all of its subkeys?
The key will be restored on top of key: %1.
All value entries and subkeys of this key will be deleted.
Do you want to continue the operation?
Confirm Restore Key
Error Renaming Key
?The Registry Editor cannot rename %1. Error while renaming key.lThe Registry Editor cannot rename %1. The specified key name is too long. Type a shorter name and try again.mThe Registry Editor cannot rename %1. The specified key name already exists. Type another name and try again.QThe Registry Editor cannot rename %1. Specify a key name without a backslash (\).gThe Registry Editor cannot rename %1. The specified key name is empty. Type another name and try again.
Error Renaming ValueAThe Registry Editor cannot rename %1. Error while renaming value.oThe Registry Editor cannot rename %1. The specified value name already exists. Type another name and try again.iThe Registry Editor cannot rename %1. The specified value name is empty. Type another name and try again.
Error Deleting Key
,Cannot delete %1: Error while deleting key.
Error Opening Key)Cannot open %1: Error while opening key.
4Cannot edit %1: Error reading the value's contents.8Cannot edit %1: Error writing the value's new contents.lData of type REG_MULTI_SZ cannot contain empty strings.
Registry Editor will remove the empty string found.mData of type REG_MULTI_SZ cannot contain empty strings.
If you still see this message, try restarting Windows.|The decimal value entered is greater than the maximum value of a DWORD.
Cannot import %1: The specified file is not a registry script.
You can only import binary registry files from within the registry editor.
.Cannot import %1: The key selected is invalid.*Cannot import %1: Insufficient privileges.
HInformation in %1 has been successfully entered into the registry on %2.SCannot import %1: Error opening the file. There may be a disk or file system error._Cannot import %1: Error reading the file. There may be a disk error or the file may be corrupt.5Cannot import %1: Error accessing the registry on %2.~Cannot import %1: Not all data was successfully written to the registry. Some keys are open by the system or other processes.`Cannot import %1: The specified file is not a registry file. You can import only registry files.ZCannot import %1: The specified file is not intended for use with this version of Windows.:Cannot import %1: The file specified does not exist on %2.
SCannot export %1: Error opening the file. There may be a disk or file system error.
SCannot export %1: Error writing the file. There may be a disk or file system error.*Cannot export %1: Insufficient privileges..Cannot export %1: The key selected is invalid.
/Cannot import %1: Error accessing the registry.
4Cannot import %1: The file specified does not exist.
Cannot print: Insufficient memory to begin job. Try closing down some applications, and try again. If you still see this message, try restarting Windows.|Cannot print: An error occurred during printing. Check your printer and your printer's settings for problems, and try again.9Cannot print: Error reading a registry value's contents.
Unable to connect to all of the roots of the computer's registry. Disconnect from the remote registry and then reconnect before trying again.TUnable to connect to %1. Make sure you have permission to administer this computer.
Cannot save subtree: Insufficient memory. Try closing down some applications, and try again. If you still see this message, try restarting Windows.@Cannot save subtree: Error reading a registry value's contents.\Cannot save subtree to %1: Error writing the file. There may be a disk or file system error.\Cannot save subtree to %1: Error opening the file. There may be a disk or file system error.
Error Creating Key2Cannot create key: Error while opening the key %1.1Cannot create key: Error writing to the registry.4Cannot create key: Unable to generate a unique name.
Adds a new DWORD value.5Copies the name of the selected key to the Clipboard.
Adds a new multi-string value.#Adds a new expandable string value.#Displays the permissions for a key.'Displays a value's data as binary data."Loads a hive file to the registry.!Unloads a hive from the registry.
)Connects to a remote computer's registry.!Imports a file into the registry..Exports all or part of the registry to a file.#Prints all or part of the registry.
Quits the Registry Editor.-Finds a text string in a key, value, or data.
Adds a new key.
.Disconnects from a remote computer's registry.
%Removes keys from the Favorites list. Adds keys to the Favorites list.
6Contains commands for working with the whole registry.-Contains commands for editing values or keys.6Contains commands for customizing the registry window.PContains commands for displaying Help for and information about Registry Editor.2Contains commands for creating new keys or values.5Contains commands for accessing frequently used keys.
Enumerate Subkeys
Create Subkey
Registry &Key'R&eplace Permission on Existing Subkeys$Audit Permission on Existing SubkeysHDo you want to replace the permission on all existing subkeys within %1?4Do you want to audit all existing subkeys within %1?
This key only
This key and subkeys
Subkeys only
The key currently selected does not give you access to retrieve such information.pRegistry Editor could not retrieve the security information.
The key currently selected is marked for deletion.kRegistry Editor could not retrieve the security information.
The key currently selected is not accessible.
The key currently selected does not give you access to save such information.lRegistry Editor could not save the security information.
The key currently selected is marked for deletion.
^Registry Editor could not set security in the key currently selected, or some of its subkeys. [Registry Editor could not set owner on the key currently selected, or some of its subkeys.
Registry Editor could not set security in the key currently selected, or some of its subkeys.
These keys do not give you access to change security information.
Registry Editor could not set security in all subkeys.
The key currently selected contains one or more subkeys marked for deletion.}Registry Editor could not set security in all subkeys.
The key currently selected contains one or more inaccessible subkeys.
Key Name:
Port:

PPLive.exe_3560:

.text
`.rdata
@.data
.rsrc
PSSh 
KERNEL32.dll
USER32.dll
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegDeleteKeyW
ADVAPI32.dll
SHELL32.dll
ole32.dll
MSVCP60.dll
MSVCRT.dll
_wcmdln
VERSION.dll
SHLWAPI.dll
xxxxxxxxxxx%x
x%x
\StringFileInfo\xx\%s
PPVA\PPVA.ini
PPLiveNetwork\product.ini
%d.%d.%d.%d
crashreporter.exe
ExceptionInfo: Code = 0x%p, Flags = 0x%p, Address = 0x%p, Args =[ %d, 0x%p ]
Dbghelp.dll
Crash-ddd-ddd-%ld-%ld.dmp
dbghelp.dll
Time : d-d-d d:d:d.d
Crash: %s %s %s
logGuid: {XXXXXXXX-X-X-X}
NOISREV.DAT
crash.log.temp
crash.log-ddd-ddd-%ld-%ld.txt
PPAP.EXE
PPLIVEU.EXE
PPLIVE.EXE
CSymbolEngine::SymInitialize FAILED %d(%#lx)
Module 0x%p 4s   %-18s %s
0x%p 0x%p 0xx - %-16s %s
Advapi32.dll
#((((%9X~
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
dMngModule.dll
ProductUpdate.dll
XUI.DLL
Update{69ED52F5-A388-4589-8338-6B5AFB106EE5}
Kernel32.DLL
PPLive\PPTV\PPTV.ini
/LoadModule ProductUpdate.dll /P1 1 /C
PPLiveU.exe
_ppautostarttagtmp_.ini
3, 0, 0, 5551
PPLive.exe

PPAP.exe_3776:

.text
`.rdata
@.data
.rsrc
PSSh 
KERNEL32.dll
USER32.dll
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegDeleteKeyW
ADVAPI32.dll
SHELL32.dll
ole32.dll
MSVCP60.dll
MSVCRT.dll
_wcmdln
VERSION.dll
SHLWAPI.dll
xxxxxxxxxxx%x
x%x
\StringFileInfo\xx\%s
PPVA\PPVA.ini
PPLiveNetwork\product.ini
%d.%d.%d.%d
crashreporter.exe
ExceptionInfo: Code = 0x%p, Flags = 0x%p, Address = 0x%p, Args =[ %d, 0x%p ]
Dbghelp.dll
Crash-ddd-ddd-%ld-%ld.dmp
dbghelp.dll
Time : d-d-d d:d:d.d
Crash: %s %s %s
logGuid: {XXXXXXXX-X-X-X}
NOISREV.DAT
crash.log.temp
crash.log-ddd-ddd-%ld-%ld.txt
PPAP.EXE
PPLIVEU.EXE
PPLIVE.EXE
CSymbolEngine::SymInitialize FAILED %d(%#lx)
Module 0x%p 4s   %-18s %s
0x%p 0x%p 0xx - %-16s %s
Advapi32.dll
#((((%9X~
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
dMngModule.dll
ProductUpdate.dll
XUI.DLL
Update{69ED52F5-A388-4589-8338-6B5AFB106EE5}
Kernel32.DLL
PPLive\PPTV\PPTV.ini
/LoadModule ProductUpdate.dll /P1 1 /C
PPLiveU.exe
_ppautostarttagtmp_.ini
3, 0, 0, 5551
PPLive.exe

PPLiveU.exe_2540:

.text
`.rdata
@.data
.rsrc
PSSh 
KERNEL32.dll
USER32.dll
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegDeleteKeyW
ADVAPI32.dll
SHELL32.dll
ole32.dll
MSVCP60.dll
MSVCRT.dll
_wcmdln
VERSION.dll
SHLWAPI.dll
xxxxxxxxxxx%x
x%x
\StringFileInfo\xx\%s
PPVA\PPVA.ini
PPLiveNetwork\product.ini
%d.%d.%d.%d
crashreporter.exe
ExceptionInfo: Code = 0x%p, Flags = 0x%p, Address = 0x%p, Args =[ %d, 0x%p ]
Dbghelp.dll
Crash-ddd-ddd-%ld-%ld.dmp
dbghelp.dll
Time : d-d-d d:d:d.d
Crash: %s %s %s
logGuid: {XXXXXXXX-X-X-X}
NOISREV.DAT
crash.log.temp
crash.log-ddd-ddd-%ld-%ld.txt
PPAP.EXE
PPLIVEU.EXE
PPLIVE.EXE
CSymbolEngine::SymInitialize FAILED %d(%#lx)
Module 0x%p 4s   %-18s %s
0x%p 0x%p 0xx - %-16s %s
Advapi32.dll
#((((%9X~
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
dMngModule.dll
ProductUpdate.dll
XUI.DLL
Update{69ED52F5-A388-4589-8338-6B5AFB106EE5}
Kernel32.DLL
PPLive\PPTV\PPTV.ini
/LoadModule ProductUpdate.dll /P1 1 /C
PPLiveU.exe
_ppautostarttagtmp_.ini
3, 0, 0, 5551
PPLive.exe


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    IconBubble.exe:3608
    attrib.exe:2136
    attrib.exe:2144
    %original file name%.exe:704
    tasklist.exe:2168
    PPTV(pplive)_forqd340.exe:2912
    PPLiveU.exe:2540
    regedit.exe:604
    regedit.exe:1368
    regedit.exe:1604
    regedit.exe:1944
    regedit.exe:1900
    regedit.exe:1112
    regedit.exe:1864
    regedit.exe:264
    regedit.exe:1500
    regedit.exe:256
    regedit.exe:492
    regedit.exe:220
    PPAP.exe:3584
    PPAP.exe:3520
    regsvr32.exe:3920
    find.exe:2192
    forqd340.exe:1076

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    %Documents and Settings%\All Users\Application Data\vcry\kswebshield.dll (4025 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\pi3603.exe (254330 bytes)
    %Documents and Settings%\Administrator\Application Data\Tencent\AXSEF\AXSEF.exe (1477492 bytes)
    %Documents and Settings%\All Users\Application Data\vcry\kwssp.dll (3641 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\location[1].htm (91 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\d.tmp (91 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\gou3603.exe (320269 bytes)
    %Documents and Settings%\All Users\Desktop\forqd340.exe (1137 bytes)
    %Program Files%\Microsoft Cdobe Emulator\Internat Explorer\Desktop.ini (75 bytes)
    %Documents and Settings%\%current user%\Desktop\Internat Explorer.HIE (37 bytes)
    %Documents and Settings%\%current user%\Desktop\okregreg.reg (229 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\aut4.tmp (2897 bytes)
    %Documents and Settings%\All Users\Application Data\vcry\kswbc.dll (5873 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\aut3.tmp (3089 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (1176 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\aut5.tmp (3185 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (3185 bytes)
    %Documents and Settings%\%current user%\Application Data\360se\360se.ini (39 bytes)
    %System%\tasklist.txt (157100 bytes)
    %Program Files%\PPLive\PPTV\skins\default\loading_list.gif (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_top_bg_bar.png (244 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_checked_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\PlayProgressThumb_down.png (312 bytes)
    %Program Files%\PPLive\PPTV\ckdll.dll (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\miniclose.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\checkstart.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\common\btn_close_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titletab_on_hover.png (844 bytes)
    %Program Files%\PPLive\PPTV\skins\default\button_down.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\s_close_hover.png (607 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_min_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_on_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\close_down.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\previous_down.png (775 bytes)
    %Program Files%\Common Files\PPLiveNetwork\Converter.dll (4992 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_progress_r.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\muteplus_hover.png (680 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumbgripper_hover.bmp (67 bytes)
    %Program Files%\PPLive\PPTV\skins\default\contrast.png (362 bytes)
    %Program Files%\PPLive\PPTV\skins\default\play_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_expand.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\min_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\exbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_HD.png (544 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_update.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\common.js (1552 bytes)
    %Program Files%\PPLive\PPTV\data\face\em26-±ã±ã.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\dt_tab_check.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\restore_hover.png (662 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\checkstop.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch2_disabled.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_close_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumb_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\notop_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\color_thumb.png (191 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\unmute_normal.png (378 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\checkstart.png (4 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\PPAPIsForbidden.xml (3 bytes)
    %Program Files%\PPLive\PPTV\tab\3\1\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\restore_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mode.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\tab\tab2.xml (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\unfullscreen_hover.png (720 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\VAProxyD.dll (3616 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_pagedown_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_top.bmp (918 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute3_normal.png (579 bytes)
    %Program Files%\PPLive\PPTV\tab\7\2\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_HD.png (1088 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute2_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\NewDownloadTask.xml.js (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_hot4.png (784 bytes)
    %Program Files%\PPLive\PPTV\tab\5\2\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ad_close.bmp (568 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\PPLive32by32.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_down.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\default\top_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pageup.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mode_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize2002.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumbgripper_hover.bmp (67 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute3_down.png (670 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small\frame_r.png (995 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\checkstart_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\tab\7\0\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mini_bottom_m.bmp (888 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\max_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_top1.bmp (694 bytes)
    %Program Files%\PPLive\PPTV\skins\common\download\volume_check.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\data\pplive_schedule_main.gif (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_pageup.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_checked_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\user_vip.gif (169 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_min_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute4_down.png (668 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\stream_spot.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\arrow-default.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\exbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizetop2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\fullscreen_normal.png (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\speed4.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch2_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\vol_bar2.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\components\PPFrame.dll (19096 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_collapsed_treebox1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\saturation.png (366 bytes)
    %Program Files%\PPLive\PPTV\skins\default\unfullscreen_normal.png (338 bytes)
    %Program Files%\PPLive\PPTV\data\face\em29-½ûÖ¹.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\stop_down.png (667 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\button.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\PlayProgressThumb_hover.png (312 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\checkbox_checked_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\in_bg_bot.bmp (150 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_on_down.png (771 bytes)
    %Program Files%\PPLive\PPTV\skins\default\dt_tab_check.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\common\btn_min_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hot_5.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hot_0.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hot_3.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\ico-exit.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_upright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_up_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\downloadbtn_disable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_expanded_treebox2.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\control_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\newsbg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_bg_bottom.bmp (476 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\download_pause.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\check_ok.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\adselector_title.jpg (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mini_bottom_l.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resizemini2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_hot4.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dtconfig_3.xml (7 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize0501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_pageup_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\unfullscreen_normal.png (331 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mini_title_l.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mini_title_m.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\tab\6\2\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_left_top.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\fullscreen_disabled.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_info_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ex_button.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\exbg_left_top.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\close_down.png (766 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\set_bg_right_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrolcommon.js (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_cate_hot.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\unmute_normal.png (502 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\HDSwitch.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\menu_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_close_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\icons\2_3.ico (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumb_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\downloading.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\exbg_left.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\ppopt.dll (3616 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_uparrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\max_down.png (555 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_sch.png (890 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_bot.bmp (728 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_downleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgressThumb_down.png (297 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute4_normal.png (614 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\Controlbar.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_sch.png (890 bytes)
    %Program Files%\PPLive\PPTV\data\UrlCache.List (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_close_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_table_vod.png (784 bytes)
    %Program Files%\PPLive\PPTV\data\local\images\nolink.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\close_numTip_hover.png (320 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\menu.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\blue.xml (278 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\exbg_left.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_pageup_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\ex_button.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\close_numTip_hover.png (320 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\next_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\signin.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumbgripper.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\data\buffer.swf (3616 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mini_main_r.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mode.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\dt_tab_check.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\asc.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_downright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_so_bot1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mini_main_r.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\download_pause.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resizeback.bmp (146 bytes)
    %Program Files%\PPLive\PPTV\chrome\BatchDownload.xml (4 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.3GP.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small\frame_title.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_epg_close.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resizetop2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\downloadbtn_hover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\infobtn.bmp (918 bytes)
    %Program Files%\PPLive\PPTV\tab\5\3\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\shift2new.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\download_fail.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_right.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pause_close.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\exbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\default\Controlbar.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hot_3.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\avatar_bg.png (1552 bytes)
    %Program Files%\PPLive\PPTV\omng.dll (16944 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\contrast.png (362 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\play_disabled.png (997 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\checkbox.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\chrome\DeleteFileFailTip.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\close_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_close_down.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mini_main_r.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\playerinfo.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute2_hover.png (663 bytes)
    %Program Files%\PPLive\PPTV\chrome\signin.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mode_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\local\icon2.gif (732 bytes)
    %Program Files%\PPLive\PPTV\chrome\Balloons.js (784 bytes)
    %Program Files%\PPLive\PPTV\PPLive.url (46 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_close_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ico-exit.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_on.png (793 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\menu_down.png (279 bytes)
    %Program Files%\PPLive\PPTV\tab\6\0\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize_gripper.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small_title_m.png (1 bytes)
    %Program Files%\PPLive\PPTV\uninst.exe (3179 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\PPLive\PPTV Website.lnk (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\close_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\restore_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\updatetipclose.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small_title_r.png (3 bytes)
    %Program Files%\PPLive\PPTV\data\face\em48-˼¿¼.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\SliderThumb_normal.png (267 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ico-setting.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\button_hover.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ad_close.bmp (568 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\checkstart_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\radio_checked.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\login_bg.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\button_down.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hot_5.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\PPP.dll (50224 bytes)
    %Program Files%\PPLive\PPTV\skins\default\menu.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_epg_back.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_expand.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_fav.png (885 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\pause_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_thumb_hover.png (287 bytes)
    %Program Files%\PPLive\PPTV\data\local\images\err_3.jpg (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\dt_header_normal_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_expanded_treebox1.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\expanding.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute_down.png (648 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\check_ok.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\chrome\videoshot.xml (6 bytes)
    %Program Files%\PPLive\PPTV\chrome\CodecFail.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\play_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\Troubleshooter.xml (11 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\user_normal.gif (98 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_close.png (12088 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\stop_disabled.png (510 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\downloadbtn_hover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\loading.gif (3 bytes)
    %Program Files%\Common Files\PPLiveNetwork\resource\PPTV.url (86 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\exbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_table.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_search.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\download_fail.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizemini1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\unfullscreen_down.png (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\EROTSER.dat (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_menu.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute2_hover.png (948 bytes)
    %Program Files%\Common Files\PPLiveNetwork\uilib.dll (24832 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_play.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\blue_b.bmp (3312 bytes)
    %Program Files%\PPLive\PPTV\data\local\errorPage.htm (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ico-exit.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\VIPChannelTip.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\notop_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_downarrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\chrome\main.js (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgress3.bmp (716 bytes)
    %Program Files%\PPLive\PPTV\chrome\NoAds.xml (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\checkbox_checked_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\speed3.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\downloadbtn_normal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\shift2new.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\dt_tab_uncheck.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\radio_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_table_down.png (535 bytes)
    %Program Files%\PPLive\PPTV\skins\default\capture_default.png (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\radio_check_sel.gif (46 bytes)
    %Program Files%\Common Files\PPLiveNetwork\admodule.dll (27704 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_collapsed_treebox2.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titlebar_bg_m.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_hover.png (7 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\shift2old_hover.png (628 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\set_bg_left_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_up_triangle.bmp (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\player\audioswitcher.ax (11048 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch2_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_bot.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_left_top.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\data\face\em14-ʧÍû.png (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\PPAP.exe (15168 bytes)
    %Program Files%\PPLive\PPTV\data\portalbg.jpg (1552 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\version.ini (111 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\avatar_bg.png (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\unmute_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.RA.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hj_expand.png (284 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\stream_spot.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\play_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizetop1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pause_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_right_top.bmp (702 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\playhj.png (478 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pageup_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\Pause2Buffer.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\2.png (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\GetCommentsInfoDll.dll (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute_disabled.png (307 bytes)
    %Program Files%\PPLive\PPTV\skins\default\PPLive32by32.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_uparrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\unmute_normal.png (502 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\previous_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute3_hover.png (669 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_up.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\previous_disabled.png (489 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute_normal.png (533 bytes)
    %Program Files%\PPLive\PPTV\skins\default\exbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\previous_normal.png (614 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hj_unexpand.png (295 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\min.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_downarrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_close_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\checkbox_checked_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\data\face\em11-Ôã¸â.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\min_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_left_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\stop_normal.png (337 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_epg_back2.bmp (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\list\catalog-1-0.xml (3 bytes)
    %Program Files%\PPLive\PPTV\data\audio.swf (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\miniclose.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\s_close_hover.png (607 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_screenhover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\Troubleshooter.dll (9320 bytes)
    %Program Files%\PPLive\PPTV\UPDATE\ICON.ico (4992 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_downarrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\components\PPChLocalManager.dll (9608 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_numTip.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_min_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\tomain.png (449 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_uparrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_uparrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\chrome\SkipAdsBalloon.xml (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\exbg_left_top.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pop_close.png (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsn7.tmp (843408 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\SliderThumb_hover.png (247 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute4_disabled.png (614 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pageup_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\downloadbtn_disable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\tab\3\0\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_collapsed_treebox2.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\miniclose.bmp (6 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\cknsis.dll (1856 bytes)
    %Program Files%\PPLive\PPTV\PlugOut\client_ap.dll (19096 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumbgripper_down.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_progress_in.png (947 bytes)
    %Program Files%\PPLive\PPTV\skins\black.xml (280 bytes)
    %Program Files%\Common Files\PPLiveNetwork\crashreporter.exe (7192 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\unfullscreen_normal.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\muteplus_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_downleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch2_hover.png (989 bytes)
    %Program Files%\PPLive\PPTV\skins\default\checkstop.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_search.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_updata_3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\speed1.png (1 bytes)
    %Program Files%\PPLive\PPTV\icons\game.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\notop_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_screenhover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\dt_tab_uncheck.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize1001.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mode_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\firewall.swf (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\capture_default.png (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\login_ing.gif (2 bytes)
    %Program Files%\Common Files\PPLiveNetwork\MngModule.dll (32824 bytes)
    %Program Files%\PPLive\PPTV\skins\default\next_hover.png (772 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\CommonFuncDll.dll (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch_hover.png (797 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_menu.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\default\play_disabled.png (997 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\des.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_so_bot1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\check_alarm.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\data\local\images\bg_x_channel.png (355 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\restore.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\playhj.png (478 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hj_expand_new.png (299 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\top.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize1501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\stop_disabled.png (333 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_on.png (843 bytes)
    %Program Files%\PPLive\PPTV\chrome\DownloadCodec.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute3_hover.png (957 bytes)
    %Program Files%\PPLive\PPTV\skins\default\infobtn.bmp (918 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\vol_bar1.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\speed4.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\restore_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\PPLive32by32.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_top.bmp (4 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\live\Live.dll (7192 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\restore_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\updatetipclose.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\playhj.png (478 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\muteplus_down.png (682 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\exbg_left.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\radio_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_epg_back3.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em54-ËÄÒ¶²Ý.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\speed3.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_downarrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\unfullscreen_disabled.png (336 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_top1.bmp (694 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\expanding.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\button.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small\frame_bottom.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_triangle.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\frame_r.png (995 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mini_bottom_l.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\chrome\VIPDownloadHD.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\shift_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\tab\5\0\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\ex_button_hover.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_pageup_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\SliderThumb_down.png (267 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch_disabled.png (475 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\RegVip.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pdot.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mini_main_l.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute3_disabled.png (579 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\checkbox_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_top_bg_bar.png (229 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\SliderThumb_hover.png (344 bytes)
    %Program Files%\PPLive\PPTV\chrome\userpopup.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\shift_disabled.png (286 bytes)
    %Program Files%\PPLive\PPTV\data\Postpone.List (283 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_left.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\adselector_title.jpg (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute4_disabled.png (338 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mini_title_l.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ie.png (895 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\downloadbtn_disable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_pageup_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute2_disabled.png (663 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ie.png (895 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\menu_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\restore.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrol2mini.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mini_bottom_r.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\unfullscreen_hover.png (923 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_close.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\downloadbtn_normal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mode.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_left_top.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\previous_normal.png (467 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_right_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\AutoSeek.xml (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute4_disabled.png (671 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch_normal.png (672 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\max_hover.png (564 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_epg_close.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\adselector_title.jpg (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\stop_normal.png (505 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize_gripper.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\fullscreen_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumbgripper.bmp (67 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ad_close.bmp (568 bytes)
    %Program Files%\PPLive\PPTV\skins\default\muteplus_normal.png (376 bytes)
    %Program Files%\PPLive\PPTV\data\face\em34-Ììʹ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_close_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\frame_bottom_m.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_close.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\restore.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute_hover.png (2 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\FWUpnp.dll (5064 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\speed1.png (1 bytes)
    %Program Files%\PPLive\PPTV\ProductUpdate.dll (23424 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_updata_3.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mini_main_l.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\top.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ex_button_down.bmp (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\bind_en-us.ini (80 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_uparrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pop_hot_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_uparrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute2_hover.png (948 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_top.bmp (162 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_downarrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\menu_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\sort_list_btn.png (667 bytes)
    %Program Files%\PPLive\PPTV\skins\default\next_down.png (777 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\speed0.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_cate_hot.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\notop_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pause_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\close_numTip_normal.png (204 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_downarrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\exbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\button.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\newsbg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\expanding.png (353 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\previous_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\stream_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_close_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\unfullscreen_disabled.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch2_disabled.png (761 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\exbg_left_bot.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\speed3.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_bot.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\unmute_normal.png (656 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_bot_bg_down.png (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\SliderThumb_down.png (267 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_hover.gif (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_livebtn.png (890 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute_disabled.png (533 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_expanded_treebox1.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\vol_bar1.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\PlayProgress3.bmp (296 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\PlayProgressThumb_normal.png (301 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_pagedown_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_menu_down.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\next_down.png (777 bytes)
    %Program Files%\PPLive\PPTV\skins\default\button.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize2002.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.WAV.ico (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\BindDLL.dll (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pushplay.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hot_4.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\SliderThumb_down.png (357 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resizenotop1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_expand.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_uparrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\avatar_bg_s.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\download_pause.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\checkstop_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resizetop2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\checkstart.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\checkbox_checked.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute2_down.png (2 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\live\tpi.dll (30464 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\top.bmp (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\gtapi_signed.dll (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_menu.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_bot_down.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\shift_hover.png (641 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\muteplus_disabled.png (556 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize2002.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrolfullscreen.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_hot3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\exbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute2_normal.png (556 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_epg_bk.bmp (214 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_expanded_treebox1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\icons\2_1.ico (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_bg_m.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_close.bmp (822 bytes)
    %Documents and Settings%\All Users\Application Data\Jlcm\profiles.ini (81 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute4_normal.png (374 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_pagedown.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\speed1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_updata_2.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_min_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\strengthenbtn02.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_pagedown_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\TestChannel.txt (451 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\dtconfig_3.xml (8 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\SliderThumb.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\config.xml (10 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\checkstart_down.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\downloading.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\updatetipclose.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\UPDATE\upgrade_bg1.bmp (5064 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize0501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\data\pptvpopo1.swf (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default\close_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_so_bar.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resizetop2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\menu.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\autoshutdown.xml (5 bytes)
    %Program Files%\PPLive\PPTV\Plugin\mframe.dll (21216 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_down_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\downloading.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_bot_hover.gif (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\muteplus_normal.png (556 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_bot_bg_hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mini_bottom_l.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_delete.png (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_top_bg_right.png (456 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pageup.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\checkstart_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_so_bot1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\chrome\BatchDownload.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\components\condisp.dll (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_expanded_treebox2.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_epg_bk.bmp (214 bytes)
    %Program Files%\PPLive\PPTV\components\PPFlvCom.dll (2392 bytes)
    %Program Files%\PPLive\PPTV\player\VSFilter.dll (33633 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\unmute_disabled.png (653 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\tab\6\3\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\menu_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\restore_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\radio_checked_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\unmute_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\PlayProgressThumb_normal.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\default\stream_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\fullscreen_normal.png (761 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\stop_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\button_disable.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_down.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hot_1.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\common\user_normal.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\unmute_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute4_normal.png (614 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\muteplus_disabled.png (680 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\default\min.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumb_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\notop_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pushplay.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\common\button_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_collapse.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumb_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\VolumePopDlg.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\shift_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\DownloadPPGame.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\min_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\notop_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\stop_normal.png (280 bytes)
    %Program Files%\PPLive\PPTV\tab\6\2\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute2_disabled.png (663 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_top_bg_left.png (511 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\des.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\expanding.png (353 bytes)
    %Program Files%\PPLive\PPTV\skins\default\top_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\avatar_bg.png (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bright.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_uparrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\play_normal.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em15-Öí.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_right_top.bmp (702 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\checkstop.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\set_bg_bot.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\default\PlayProgressThumb_normal.png (297 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\unfullscreen_normal.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\user_normal.gif (98 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumbgripper_down.bmp (67 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_update.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\PlayProgress1.bmp (13 bytes)
    %Program Files%\Common Files\PPLiveNetwork\restore.dll (5064 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_upleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\tab\8\2\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\capture_default.png (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\common\download\dt_header_normal_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_downarrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\radio.png (3 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.AVI.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\min_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\playerinfo.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bdclose.png (198 bytes)
    %Program Files%\PPLive\PPTV\data\face\em50-¶³ÝЦ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_on_hover.png (843 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_del_record.png (2 bytes)
    %Program Files%\PPLive\PPTV\tab\4\3\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\speed3.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_left.bmp (134 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\radio.png (3 bytes)
    %Program Files%\PPLive\PPTV\data\face\em16-Õð¾ª.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\checkstart.png (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\InetLoad.dll (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\infobtn.bmp (918 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mini_main_l.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_collapsed_treebox2.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\fullscreen_normal.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\shift_normal.png (416 bytes)
    %Program Files%\PPLive\PPTV\UPDATE\CH.INI (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\play_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\2\1\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\min_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\color_thumb.png (191 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_search.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\stream_spot.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\muteplus_disabled.png (326 bytes)
    %Program Files%\PPLive\PPTV\skins\default\dt_tab_uncheck.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small_frame_r.png (995 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\groupbox.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\checkstart_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize0502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_up.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\default\PlayProgress3.bmp (716 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\unmute_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\radio_checked_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute3_disabled.png (669 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\top_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\exbg_left_bot.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute4_disabled.png (671 bytes)
    %System%\kindling.dll (23936 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resizenotop2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\expanding.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\unmute_down.png (793 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumbgripper.bmp (67 bytes)
    %Program Files%\PPLive\PPTV\chrome\VIPLogin.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\muteplus_hover.png (947 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_bot_down.png (1552 bytes)
    %Program Files%\PPLive\PPTV\chrome\mainframe2.xml (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_close.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\default\avatar_bg_s.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\downloadbtn_hover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute3_hover.png (669 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\checkstart.png (4 bytes)
    %Program Files%\PPLive\PPTV\data\face\em53-»ð.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_downright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_min_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\dt_titlebar_m.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_top_bg_left.png (683 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_so_left.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\stop_down.png (667 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\user_vip.gif (169 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bright.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\default\set_bg_right.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch2_disabled.png (761 bytes)
    %Program Files%\PPLive\PPTV\InstallLog.txt (18517 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch2_disabled.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hj_unexpand_new.png (267 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\checkbox_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\muteplus_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\radio_checked_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\muteplus_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_top_bg_right.png (456 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pop_hot_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\dt_titlebar_m.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\download_wait.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumb_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute3_hover.png (957 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\min.png (233 bytes)
    %Program Files%\PPLive\PPTV\player\CoreAAC.ax (11344 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumb_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_checked_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\next_disabled.png (449 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\default_pic.png (1 bytes)
    %Program Files%\Internet Explorer\PPLite\plugin\1.0.0.595\ppp.dll (8560 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\alert.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\SliderThumb_normal.png (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\max_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em51-Ñ©ÈË.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\next_hover.png (998 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_livebtn_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\checkbox_checked_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resizeback.bmp (146 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resizeratebg.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_new3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_left.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_updata_3.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_close_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\unfullscreen_normal.png (338 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\pause.png (449 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\play_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resizetop1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\in_bg_left_bot.bmp (670 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_pagedown_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\next_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resizemini1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\max_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em38-ÌôüÍÂÉà.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hot_5.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_left.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\shift2new_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\timingshutdown.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize_gripper.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\button_down.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\dtconfig_3.xml (8 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\regvip.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\default\set_bg_left_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\skins\default\restore_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_uparrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\strengthenbtn02.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\default\muteplus_disabled.png (680 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumbgripper.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mini_bottom_r.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_uparrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_down_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hot_3.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\downloadbtn_hover.bmp (2 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\Hookkernel.dll (10136 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\shift_disabled.png (397 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_collapsed_treebox1.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\radio_checked_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\common\btn_min_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumb.bmp (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\version[1].ini (111 bytes)
    %Program Files%\PPLive\PPTV\tab\1\1\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_downarrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\download_wait.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\checkstop_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\data\face\em39-²»·þ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\dt_titlebar_r.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\close_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\exbg_left_top.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv.png (674 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_bg.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\dt_tab_check.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\close_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pushplay.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pop_close.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_downarrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\stream_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\PPTVLicense.txt (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\set_bg_left.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\components\chctrl.dll (38495 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pause_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_pagedown_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\capture_default.png (12 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_pagedown_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\loading.gif (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\color_thumb.png (191 bytes)
    %Program Files%\PPLive\PPTV\player\audioswitcher.ax (11048 bytes)
    %Program Files%\PPLive\PPTV\chrome\PPPlayer.js (784 bytes)
    %Program Files%\PPLive\PPTV\chrome\CodecFail.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\chrome\timingservice.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hot_1.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch_vip.png (443 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_down.png (7 bytes)
    %Program Files%\PPLive\PPTV\tab\2\2\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\tab\4\0\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.MP4.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bright.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\sqlite3.dll (16288 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumbgripper_hover.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\close_numTip_hover.png (320 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\Controlbar.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_close_down.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\data\face\em23-Ç×Ç×.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\restore.png (329 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\strengthenbtn01.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\play_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\config.xml (10 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_downright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pop_close.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\logo.jpg (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mini_title_l.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_titlebar_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hot_1.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_updata_2.gif (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\default\tab_background.png (153 bytes)
    %Program Files%\PPLive\PPTV\chrome\coveredfile.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\check_alarm.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\play_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\sort_list_btn.png (667 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\stop_disabled.png (280 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_downarrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\tab\1\3\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_min_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\speed1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\close_numTip_hover.png (320 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_uparrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute3_disabled.png (669 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resizeback.bmp (146 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\arrow-default.png (1552 bytes)
    %Program Files%\PPLive\PPTV\components\IEBrowser.dll (8184 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute2_normal.png (362 bytes)
    %Program Files%\PPLive\PPTV\icons\2_2.ico (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute3_disabled.png (579 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\PlayProgressThumb_down.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\fullscreen_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize1501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\components\Gallop.dll (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pause_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\player\MP4Splitter.ax (17848 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\set_bg_right.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\data\face\em19-ÈÈ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\radio_checked_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\strengthenbtn01.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\chrome\mainframe2.js (6584 bytes)
    %Program Files%\PPLive\PPTV\skins\default\max.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pdot.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bdclose.png (198 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_left_bot.bmp (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\TipsClient.dll (8560 bytes)
    %Program Files%\PPLive\PPTV\skins\default\previous_disabled.png (444 bytes)
    %Program Files%\PPLive\PPTV\skins\default\updatetipclose.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hot_1.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_epg_back2.bmp (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\sop.dll (16424 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ico-setting.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\PlayProgressThumb_hover.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_numTip.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hj_unexpand_new.png (267 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_disabled.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_pageup_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_top_bg_left.png (511 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\speed4.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\restore_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\stop_hover.png (664 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\fullscreen_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize1002.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em55-²ö.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\contrast.png (362 bytes)
    %Program Files%\PPLive\PPTV\NOISREV.DAT (31 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mini_main_l.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mini_bottom_r.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_close.png (12088 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\radio_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mini_main_r.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\tab\2\3\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_close_hover.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\default\config.xml (10 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\What's new.txt (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ex_button_down.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\avatar_bg_s.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\color_thumb.png (191 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\restore_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute4_hover.png (671 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\checkstop_down.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize1001.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrol2.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute4_normal.png (339 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\unmute_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_right.bmp (134 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\stream_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hot_0.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resizenotop1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\mini_title_r.bmp (696 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_menu_hover.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_triangle.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\miniSite.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\speed2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\data\face\em18-¹ÄÁ³.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hj_expand.png (284 bytes)
    %Program Files%\PPLive\PPTV\skins\default\next_normal.png (470 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_checked.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_hot3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hj_expand_new.png (299 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mini_title_r.bmp (696 bytes)
    %Program Files%\PPLive\PPTV\skins\default\expanding.png (353 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\unmute_hover.png (792 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small\control_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\top_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mini_title_m.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\ieloading.swf (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_top_bg_left.png (683 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mini_title_m.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_update.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_upright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\exbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\stream_spot.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\checkbox.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_collapsed_treebox2.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\brightness.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_menu_hover.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_uparrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\exbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_close_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_HD.png (1088 bytes)
    %Program Files%\PPLive\PPTV\skins\default\vol_bar1.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_upleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\tab\4\1\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\download_fail.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_close_down.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hot_4.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch_normal.png (672 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute_hover.png (929 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_menu_hover.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\asc.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hot_0.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\menu_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute4_down.png (2 bytes)
    %Program Files%\Internet Explorer\PPLite\plugin\1.0.0.595\mframe.dll (16944 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_downarrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_epg_back3.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\menu.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_cate_new.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\expanding.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\exbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_sch_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_right_top.bmp (702 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\checkstop.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\max_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small_title_l.png (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_left.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\shift2new_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\tab\4\2\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\stop_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\radio_check.gif (46 bytes)
    %Program Files%\PPLive\PPTV\data\face\em46-ÓêÉ¡.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resizenotop2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2.ppui (302 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\in_bg_left_top.bmp (670 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\fullscreen_normal.png (761 bytes)
    %Program Files%\PPLive\PPTV\skins\default\dt_titlebar_l.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\stream_bg.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_table_down.png (535 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\frame_title.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\radio.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\top_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hj_unexpand.png (295 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_thumb_normal.png (274 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titlebar_m.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\info_arrow.bmp (138 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mini_bottom_r.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_top_bg_right.png (456 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\dt_selitem_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\below_title.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_expanded_treebox2.png (784 bytes)
    %Program Files%\Common Files\PPLiveNetwork\IEBrowser.dll (16424 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\pnsis.dll (2392 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pause_disabled.png (525 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pdot.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\restore_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_downarrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize2002.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_bar_1.png (995 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\volume.png (462 bytes)
    %Program Files%\PPLive\PPTV\skins\default\restore.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pause_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\chrome\PPGameIsSetup.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch_disabled.png (672 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizenotop1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_cate_hot.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\unfullscreen_down.png (987 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_so_bar.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\PlayProgress2.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\tab\7\3\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_pagedown_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\set_bg_right.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\close.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hot_1.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_uparrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\loading_list.gif (520 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_collapse.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\asc.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_downarrow_down.bmp (938 bytes)
    %Program Files%\Common Files\PPLiveNetwork\player\CoreAAC.ax (11344 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\min.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\RegUser.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\frame_bottom.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\Controlbar.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\parsing.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\7\2\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small\frame_l.png (165 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close_hover.bmp (822 bytes)
    %Program Files%\Common Files\PPLiveNetwork\GdiPlus.dll (51840 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resizeratebg.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\white_dot.png (130 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\exbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\downloading.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\shift_down.png (462 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\arrow_right_sel.gif (59 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_bot.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize1001.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\set_bg_left.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\SliderThumb.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_close.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\arrow_right.gif (59 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_upright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\tomain_down.png (454 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_down.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\exbg_left_bot.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute2_disabled.png (556 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\loading_list.gif (520 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize1002.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch_normal.png (475 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\FindChannelTip.xml (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\arrow-hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_bot.bmp (728 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\volume_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\blue.bmp (3312 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch_hover.png (797 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize1502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\checkbox_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\unmute_disabled.png (792 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute3_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\menu_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\checkbox_checked_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\downloadbtn_normal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_up.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\tab_background.png (153 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute_hover.png (647 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\dt_titlebar_l.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\strengthenbtn02.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\groupbox.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resizetop2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute3_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\play_disabled.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_downright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titletab_down.png (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default\set_bg_bot.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_expand.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_triangle.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\PlayProgress2.bmp (13 bytes)
    %Program Files%\PPLive\PPTV\chrome\SkipAds.xml (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumbgripper_hover.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_close_hover.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_left_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_uparrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_bg_hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_close_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_right_top.bmp (702 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\stop_hover.png (960 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\infobtn.bmp (918 bytes)
    %Program Files%\PPLive\PPTV\data\face\em04-ºÇºÇ.png (1 bytes)
    %Program Files%\PPLive\PPTV\GdiPlus.dll (51840 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hot_0.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\unmute_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\shift_normal.png (307 bytes)
    %Program Files%\PPLive\PPTV\chrome\BalloonCommon.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\set_bg_left_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pause_close.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_collapsed_treebox1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\speed2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\arrow-default.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_sch_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_collapse.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_top_bg_bar.png (229 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\frame_r.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\muteplus_down.png (682 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_min_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_screendisable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_close.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\notop.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute_normal.png (335 bytes)
    %Program Files%\PPLive\PPTV\data\face\em03-´ô.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\check_alarm.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\MyPPTVTip.xml (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_collapsed_treebox1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\notop.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\tab\7\1\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumb.bmp (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bind_en-us[1].ini (80 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_right.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_left.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\max_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\player\OPlayer.ocx (34186 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_downleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\checkbox_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\radio_checked.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\checkstart_down.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\checkstop.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\max_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_hot3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\checkstop_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resizemini2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch_disabled.png (672 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumbgripper_hover.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumb_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\icons\PPLive.ico (4992 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\exbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_bot_bg.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\common\shift2new_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mode_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_new3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\unfullscreen_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_left.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_bot_bg_down.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\loading_list.gif (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mini_bottom_m.bmp (888 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\unmute_normal.png (656 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\contrast.png (362 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_close_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\crashreporter.exe (7192 bytes)
    %Program Files%\PPLive\PPTV\chrome\coloradjust.xml (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_cate_new.png (784 bytes)
    %Program Files%\PPLive\PPTV\data\face\em37-¾À½á.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_bot.bmp (728 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\dt_titlebar_m.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\local\page2.html (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\PPBindDAC.dll (1552 bytes)
    %Program Files%\PPLive\PPTV\UPDATE\progress.gif (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\playerinfo.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\exbg_left.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_pagedown.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_Classic2New.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_checked.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\frame_bottom_r.png (929 bytes)
    %Program Files%\PPLive\PPTV\data\face\em17-Àä.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\miniclose.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\set_bg_bot.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute3_disabled.png (333 bytes)
    %Program Files%\PPLive\PPTV\data\face\em43-ßÖ×ìɵЦ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\skin.ini (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\exbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mini_title_l.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hot_3.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\common\mini_bottom_r.bmp (140 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pageup_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\uilib.dll (24832 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_right.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\icons\3.ico (2 bytes)
    %Program Files%\PPLive\PPTV\chrome\Troubleshooter.xml.js (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_top.bmp (918 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\white_dot.png (130 bytes)
    %Program Files%\PPLive\PPTV\skins\default\saturation.png (366 bytes)
    %Program Files%\PPLive\PPTV\skins\default\brightness.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mini_bottom_l.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\set_bg_left.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\tab\5\0\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pagedown_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\stop_disabled.png (510 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch_normal.png (475 bytes)
    %Program Files%\PPLive\PPTV\chrome\VIPDownloadLogin.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_tab_check.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\ch_vip.png (443 bytes)
    %Program Files%\PPLive\PPTV\skins\default\play_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\PPLive32by32.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\common\mini_title_l.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_expanded_treebox1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_downarrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\muteplus_hover.png (947 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\unmute_disabled.png (378 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\shift2new.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_bot_hover.gif (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\capture_default.png (12 bytes)
    %Program Files%\PPLive\PPTV\skins\default\checkstart_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\data\face\em40-ÎÞÄÎ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize0501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\speed1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute_hover.png (929 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_progress_l.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pop_hot_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\tab_background.png (153 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumb.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\close_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_menu_down.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\radio_checked_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\min.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizeback.bmp (760 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hj_unexpand.png (295 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resizenotop1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\min_hover.png (456 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_close.png (12088 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mode.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_info_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\SliderThumb_normal.png (267 bytes)
    %Program Files%\PPLive\PPTV\data\PPLiveFlv.swf (14 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\nav_status_m.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_screendisable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\muteplus_disabled.png (556 bytes)
    %Program Files%\PPLive\PPTV\skins\default\top.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\speed4.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\fullscreen_hover.png (657 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ex_button_hover.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\avatar_bg.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pop_hot_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mini_title_l.bmp (6 bytes)
    %Program Files%\Common Files\PPLiveNetwork\sqlite3.dll (17848 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\exbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\tab\7\1\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\chrome\Options.xml (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hj_expand_new.png (299 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\speed0.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute2_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_bot.png (1552 bytes)
    %Program Files%\PPLive\PPTV\tab\5\1\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pause_normal.png (525 bytes)
    %Program Files%\PPLive\PPTV\PPLive.exe (15168 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hot_2.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumb_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\pptvpopo.swf (784 bytes)
    %Program Files%\PPLive\PPTV\skins\common\close.png (311 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\shift2new_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\ex_button_down.bmp (730 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute4_hover.png (961 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\OldJumpAdTip.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\info_arrow.bmp (138 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_epg_back3.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_left_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_triangle.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hot_3.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_fav_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pause_normal.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\next_normal.png (624 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\icons\default.ico (4992 bytes)
    %Program Files%\PPLive\PPTV\tab\3\2\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\arrow-default.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute2_hover.png (663 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pop_hot_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\6\1\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\min.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_search.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_top_bg_right.png (463 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_pageup_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\UPDATE\upgrade_title.bmp (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\SliderThumb_hover.png (247 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\loading-2.gif (2 bytes)
    %Program Files%\PPLive\PPTV\UPDATE\upgrade_bg2.bmp (5064 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\System.dll (11 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_screendisable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\FirewallForbidden.xml (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_so_bar.png (784 bytes)
    %Program Files%\PPLive\PPTV\chrome\VIPDownload.xml (6 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\NewJumpAdTip.xml (3 bytes)
    %Program Files%\PPLive\PPTV\admodule.dll (31856 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\speed0.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_pagedown_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_HD.png (544 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\exbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_hot3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_close_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_fav.png (885 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_uparrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_bot_down.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_close_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\checkstop_down.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute3_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_left.bmp (134 bytes)
    %Program Files%\PPLive\PPTV\skins\default\downloadbtn_normal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ie.png (895 bytes)
    %Program Files%\PPLive\PPTV\skins\default\check_ok.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\stop_hover.png (960 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\next_disabled.png (449 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\next_hover.png (998 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\max_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_bot_bg.png (1552 bytes)
    %Program Files%\PPLive\PPTV\data\local\images\err_1.png (9 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute3_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_expanded_treebox1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_pagedown_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_livebtn.png (890 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_on_down.png (843 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_downleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\brightness.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\volume1_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bdclose.png (198 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\unfullscreen_hover.png (720 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch2_normal.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em12-²»Êæ·þ.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em36-IloveUÊÖÊÆ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch2_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_new3.png (784 bytes)
    %Program Files%\PPLive\PPTV\data\face\em24-Õ£ÑÛ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize2001.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\muteplus_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\notop.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pause_disabled.png (813 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_new3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pause_normal.png (525 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_upleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\shift2old.png (314 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\s_close_down.png (473 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\strengthenbtn02.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\chrome\OffLine.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\min_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pageup_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.RM.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_left.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize0501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_close_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\close.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumbgripper_hover.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize_gripper.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_sch_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch2_hover.png (989 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute_normal.png (335 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pagedown_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\frame_l.png (3 bytes)
    %Program Files%\PPLive\PPTV\data\local\images\404.png (7 bytes)
    %Program Files%\PPLive\PPTV\IconBubble.exe (5064 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\downloadbtn_hover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mini_title_r.bmp (696 bytes)
    %Program Files%\PPLive\PPTV\data\vip.swf (4992 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_uparrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_collapsed_treebox2.png (784 bytes)
    %Program Files%\Common Files\PPLiveNetwork\player\CoreAVC.2.0.0.0.ax (9608 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\speed0.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize2001.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\local\images\menu.png (7 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_HD.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\5\2\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\fullscreen_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\chrome\push_pop.xml (10 bytes)
    %Program Files%\PPLive\PPTV\data\face\em45-¿§·È.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em28-¶ñħ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\white_dot.png (130 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_class_bg.png (140 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_pagedown_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch2_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_del_record.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\mini_main_l.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\download_fail.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\close.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_left_top.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mini_bottom_m.bmp (888 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_uparrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_table.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_left.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_down.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\radio_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_new3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\next_hover.png (772 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot.png (1552 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.AMR.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizenotop2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\data\face\em06-Á³ºì.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\stop_hover.png (664 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_bk.bmp (214 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_screenhover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute2_normal.png (556 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hj_expand.png (284 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\muteplus_normal.png (556 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\dt_selitem_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\hoverinfo.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hj_unexpand.png (295 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_left_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_min_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_down_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ico-setting.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\local\nolink.htm (944 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_downarrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\data\face\em27-Æ¡¾Æ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute2_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_updata_3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_bot_bg.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\chrome\downloadTipDlg.xml (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\vol_bar1.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\max_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_min_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_min_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.WMA.ico (784 bytes)
    %Program Files%\Common Files\PPLiveNetwork\player\CoreAVC.ax (6584 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_min_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\newsbg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\user_normal.gif (98 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\FindProcDLL.dll (784 bytes)
    %Program Files%\PPLive\PPTV\tab\3\0\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\check_alarm.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\tab\8\3\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\pprepair.dll (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_close_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\loading_list.gif (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\infobtn.bmp (918 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\exbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute4_disabled.png (614 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ico-setting.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\shift_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_bot_bg_hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_so_bot1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pause_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\data\face\em21-ÍÂÉà.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_info_normal.png (480 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\tab\7\0\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\data\face\em31-Ç®.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute4_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hot_4.bmp (344 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\Loader.exe (2392 bytes)
    %Program Files%\PPLive\PPTV\tab\5\3\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_top_bg_left.png (511 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\download_pause.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\muteplus_hover.png (680 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_update.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hot_2.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\play_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\ETADPU.DAT (498 bytes)
    %Program Files%\PPLive\PPTV\skins\default\color_thumb.png (191 bytes)
    %Program Files%\PPLive\PPTV\tab\1\2\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ex_button_down.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_begin.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\previous_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute4_normal.png (374 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titlebar_r.png (9 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_close_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_checked_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize2001.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumb.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\avatar_bg_s.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_downarrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\data\face\em02-Ìôü.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\play_normal.png (1 bytes)
    %Program Files%\PPLive\PPTV\PPLiveU.exe (15168 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\pause_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\cntvppl.html (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default\dt_header_normal_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\downloadbtn_disable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\ad_close.bmp (568 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\white_dot.png (130 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_info_disabled.png (458 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\chrome\DownloadTaskConflict.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_menu.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\sort_list_btn.png (817 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\info_arrow.bmp (138 bytes)
    %Program Files%\PPLive\PPTV\skins\common\close_down.png (766 bytes)
    %Program Files%\PPLive\PPTV\data\face\em30-ÉÁµç.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ico-exit.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hot_4.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\adselector_title.jpg (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_epg_bk.bmp (214 bytes)
    %Program Files%\PPLive\PPTV\player\CoreAVC.ax (6584 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumb_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_epg_bk.bmp (214 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_hot4.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_Classic2New.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_close_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\data\face\em56-ÖíÍ·.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute4_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\previous_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch2_normal.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizewz1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\radio_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\radio_checked_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\data\local\icon.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\top_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_close_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pause_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\sch_list_class_bg.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mini_bottom_m.bmp (888 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pagedown.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\skin.ini (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_screendisable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_checked_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mini_title_r.bmp (696 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_update.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\des.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\sch_list_class_bg.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.video.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_up.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\fullscreen_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\Controlbar.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ex_button_hover.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_so_bar.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\radio_check_dis.gif (46 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titlebar_bg_r.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\contrast.png (362 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\dt_titlebar_l.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_downarrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\play_disabled.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\previous_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\chrome\PPGameFail.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\stop_normal.png (505 bytes)
    %Program Files%\PPLive\PPTV\skins\default\close_numTip_normal.png (204 bytes)
    %Program Files%\PPLive\PPTV\chrome\DownloadTaskConflict2.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default\shift_hover.png (463 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\SliderThumb_down.png (357 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\stop_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hj_expand_new.png (299 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\in_bg_right_top.bmp (670 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\s_close.png (607 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\GetVersion.dll (5 bytes)
    %Program Files%\PPLive\PPTV\tab\2\1\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\dt_selitem_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch2_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize1002.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_pagedown.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_left_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_pageup_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\data\face\em44-ã¶×¡.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\4\0\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize1502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_triangle.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pause_disabled.png (525 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_bg_down.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mini_bottom_m.bmp (888 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.SWF.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\common\shift2new_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\notop_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\icons\Offline.ico (894 bytes)
    %Program Files%\PPLive\PPTV\data\pplive_schedule.html (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_menu.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resizenotop1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\mainframe.xml.js (8184 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_table_vod_down.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumbgripper_down.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mode_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_screenhover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resizeratebg.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_top_bg_right.png (463 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\fullscreen_normal.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pagedown_down.bmp (938 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\PPLive\Uninstall PPTV.lnk (565 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_hot3.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\set_bg_right.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\PlayProgress3.bmp (716 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\play_normal.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\asc.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_header_separator.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\avatar_bg.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizeratebg.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\parsing.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\stop_down.png (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\product.ini (367 bytes)
    %Program Files%\PPLive\PPTV\skins\default\des.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\set_bg_left_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_right.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\check_ok.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\default\dt_titlebar_m.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_close.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute3_down.png (670 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_header_asc.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\exbg_left_top.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\common\btn_close_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\play_disabled.png (522 bytes)
    %Program Files%\PPLive\PPTV\skins\common\user_vip.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\volume1.png (494 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\cbox_check_dis.gif (60 bytes)
    %Program Files%\PPLive\PPTV\tab\6\0\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_expand.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\previous_normal.png (467 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ad_close.bmp (568 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize0502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_so_left.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\3\1\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_numTip.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\shift_hover.png (463 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\notop_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pause_close.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\exbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_class_bg.png (173 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mini_main_r.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\data\face\em52-ÊÜÉË.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\radio_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute_disabled.png (533 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\P2PDetail.xml (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_numTip.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\logo.jpg (784 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\Classic2NewTip.xml (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\alert.png (2 bytes)
    %Program Files%\PPLive\PPTV\tab\6\3\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_right_top.bmp (702 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\expanding.png (353 bytes)
    %Program Files%\PPLive\PPTV\skins\black.bmp (3312 bytes)
    %Program Files%\PPLive\PPTV\skins\default\max_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\min_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_pageup.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_close.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\s_close.png (607 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mini_bottom_l.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\tab\8\0\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\ui.dll (30464 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\menu_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\checkbox_checked_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\unfullscreen_down.png (987 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_right.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\exbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\logo.jpg (784 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_downarrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\chrome\NavigateStatus.xml (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pageup_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\sort_list_btn.png (817 bytes)
    %Program Files%\PPLive\PPTV\skins\default\notop_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\unmute_down.png (793 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\muteplus_normal.png (376 bytes)
    %Program Files%\PPLive\PPTV\components\IEProxy.dll (8560 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\time.dll (10 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\PlayProgress2.bmp (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\previous_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titlebar_front_l.png (784 bytes)
    %Program Files%\PPLive\PPTV\data\face\em25-ÆøÌå.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumb.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_left_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_class_bg.png (140 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_screennormal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pdot.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\checkbox_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\dtconfig_3.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\regvip.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mode_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\tab\1\0\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\mini_bottom_l.bmp (140 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize2001.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute_normal.png (307 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_menu_hover.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\radio_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_checked.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pause_normal.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\radio_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\checkstop_down.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\saturation.png (366 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\parsing.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\PlayProgress3.bmp (716 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving.xml (294 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute_normal.png (533 bytes)
    %Program Files%\PPLive\PPTV\skins\common\button_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_so_bot1.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\notop_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\sch_list_class_bg.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\dt_titlebar_l.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\set_bg_bot.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\default\strengthenbtn01.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resizemini1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_pageup.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\expanding.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bdclose.png (198 bytes)
    %Program Files%\PPLive\PPTV\chrome\tabs.js (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\next_disabled.png (490 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_screendisable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ex_button_down.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\common\btn_close_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\menu_hover.png (369 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mute3_normal.png (579 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_close.png (12088 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\hoverinfo.xml.js (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\parsing.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\fullscreen_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_uparrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\max.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\restore.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\dt_titlebar_r.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\1\2\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\8\2\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\previous_down.png (775 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\close.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\menu.png (268 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\unfullscreen_disabled.png (336 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\button_down.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\info_arrow.bmp (138 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_class_bg.png (140 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\skin.ini (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\dtconfig_3.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\close_down.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\stream_spot.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\chrome\ChannelNumTip.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\unmute_hover.png (792 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\in_bg_right.bmp (174 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\playerinfo.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\shift2old_down.png (618 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_back2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute_hover.png (647 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\alert.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\next_normal.png (432 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\saturation.png (366 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize1501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute4_down.png (668 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\shift_normal.png (510 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\loading.gif (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\next_disabled.png (405 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgressThumb_hover.png (288 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_close_down.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hot_4.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\data\face\em09-Ë®µÎ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_close_hover.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\cbox_check.gif (62 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_download_playing.png (2 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.FLV.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_vthumb.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\radio_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\fullscreen_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\top_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\player\HTTP_ASF_SOURCE.ax (17848 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\top_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\tab\8\1\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_header_des.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_checked_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\hot_2.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_right.bmp (134 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\data\face\em47-ºÚÈË.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\menu.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\next_normal.png (470 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\menu_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\attemptclose.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\frame_bottom_l.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_downarrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\shift2new_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\alert.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_epg_close.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_vthumb_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_close_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\close_hover.png (769 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize_gripper.png (2 bytes)
    %Program Files%\PPLive\PPTV\components\filepick.dll (3312 bytes)
    %Program Files%\PPLive\PPTV\tab\4\2\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_up.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_left.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_bot.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pageup_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pause_close.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\tab\3\3\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\checkbox_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_VIP.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_sch.png (890 bytes)
    %Program Files%\PPLive\PPTV\IP (7 bytes)
    %Program Files%\Common Files\PPLiveNetwork\player\VSFilter.dll (33633 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_left.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch_vip.png (443 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\arrow-hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\playerinfo.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\tab\4\1\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch_vip.png (443 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_top.bmp (162 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\close_numTip_normal.png (204 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mode.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_thumb_down.png (287 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\radio_checked_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\data\face\em10-µ¹Á¢.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\fullscreen_disabled.png (344 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\dt_titlebar_r.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\nav_status_l.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\stop_disabled.png (333 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_updata_2.gif (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_cate_hot.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_back3.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_tab_uncheck.png (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumb_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pause_hover.png (943 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\stream_bg.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute2_normal.png (322 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\brightness.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\shift_disabled.png (471 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\shift_hover.png (641 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\checkbox_checked.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\previous_normal.png (443 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_left.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hot_0.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pushplay.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\check_ok.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\ico-setting.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgress2.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mypptv_arrow.png (660 bytes)
    %Program Files%\PPLive\PPTV\skins\default\min_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\next_disabled.png (490 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hj_unexpand_new.png (267 bytes)
    %Program Files%\PPLive\PPTV\data\face\em33-Ì¾Æø.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\newsbg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\dt_header_normal_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\config.xml (10 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titletab_on_down.png (844 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_screennormal.bmp (2 bytes)
    %Documents and Settings%\All Users\Desktop\PPTV Online Video.lnk (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\player\HTTP_ASF_SOURCE.ax (17848 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\exbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_menu_down.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\exbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute4_hover.png (671 bytes)
    %Program Files%\PPLive\PPTV\chrome\push_pop2.xml (13 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_livebtn_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\menu_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_livebtn_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pushplay.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_pagedown_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resizemini1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_hot4.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_bot.bmp (728 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\exbg_left.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\tab\7\3\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pause_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\EROTSER.dat (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\unfullscreen_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\downloading.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\downloadbtn_normal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\checkbox_checked_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_expanded_treebox2.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_close_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_top1.bmp (694 bytes)
    %Program Files%\PPLive\PPTV\tab\4\3\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\tab\2\3\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ex_button_hover.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch2_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resize0502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\arrow-hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\tab\2\2\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\close_hover.png (769 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\play.png (543 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\gbg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\exbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titlebar_bg_l.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_menu_down.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_epg_close.bmp (886 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_top1.bmp (694 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_right_top.bmp (7 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\arrow-hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\PlayProgress1.bmp (440 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\white_dot.png (130 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_vthumbgripper_down.bmp (67 bytes)
    %Program Files%\PPLive\PPTV\tab\8\0\2.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hj_expand_new.png (299 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ex_button.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrol.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\exbg_right_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\exbg_left_bot.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resizemini2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\frame_l.png (165 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_menu_down.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\notop.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\passport_menu_hover.gif (13 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_pagedown_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\tab\8\3\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resizeratebg.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\PlayProgressThumb_hover.png (288 bytes)
    %Program Files%\PPLive\PPTV\data\face\em08-ÐÄ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_downright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_pageup.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_right.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize1501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_top.bmp (918 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp\PPInstallLog.dll (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\fullscreen_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\exbg_left_bot.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\min_down.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\PlayProgressThumb_normal.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\download_fail.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pdot.png (784 bytes)
    %Program Files%\PPLive\PPTV\tab\8\1\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\tab\1\3\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\face\em13-¾Æ±­.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\max.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_top_bg_bar.png (244 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\top.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute2_disabled.png (556 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\asc.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\button_down.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\checkstop_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_class_bg.png (173 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\logo.jpg (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\exbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\speed2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mini_title_r.bmp (696 bytes)
    %Program Files%\PPLive\PPTV\skins\common\mini_title_m.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resizemini2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\shift_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\arrow-default.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\icons\2_4.ico (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize1502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_checked_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\icons\ikan-p.ico (4992 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\check_alarm.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_pagedown.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_expanded_treebox2.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\play_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\2\0\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\data\local\cjs\err.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\play_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\restore_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_search.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\pause_disabled.png (813 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\checkbox_checked.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\New2ClassicTip.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\download_wait.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_so_bar.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\unmute_disabled.png (792 bytes)
    %Program Files%\PPLive\PPTV\data\face\em01-΢Ц.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resizenotop2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\skin.ini (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_Classic2New.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\groupbox.png (784 bytes)
    %Program Files%\PPLive\PPTV\chrome\signin2.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hot_2.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_uparrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close_down.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_upleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\exbg_left_top.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\unfullscreen_hover.png (923 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\max.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_upright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\default\shift_normal.png (307 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_close.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hj_unexpand.png (295 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_updata_2.gif (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small_frame_bottom.png (1 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.WMV.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\user_normal.gif (98 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_pause.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\dt_tab_uncheck.png (2 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.MPG.ico (784 bytes)
    %Program Files%\PPLive\PPTV\data\face\em32-Æà²Ò.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumb_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\play_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\set_bg_left.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\cbox_check_sel.gif (832 bytes)
    %Program Files%\PPLive\PPTV\skins\default\passport_bot_bg_down.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumbgripper.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\SliderThumb.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\DataRateChangeWnd.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pagedown_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titlebar_front_r.png (9 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bg_right.bmp (134 bytes)
    %Program Files%\PPLive\PPTV\chrome\DownloadPPGame.xml.js (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\groupbox.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_updata_3.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_table_vod_down.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_close_1.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_vthumbgripper_down.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\groupbox.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\checkbox.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\data\face\em20-ÞÏÞÎ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hot_2.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\arrow-hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\set_bg_right_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_downarrow_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\SliderThumb_hover.png (344 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\checkbox_checked_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute_down.png (648 bytes)
    %Program Files%\PPLive\PPTV\skins\default\info_arrow.bmp (138 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\task_noplay.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\loading.gif (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hot_5.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_item_gap.png (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\live\mir.dll (33747 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\radio_checked_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\alert.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_checked_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pause_normal.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\PPLive32by32.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_bot_hover.gif (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute3_normal.png (372 bytes)
    %Program Files%\PPLive\PPTV\components\PPOptions.dll (19096 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\bdclose.png (198 bytes)
    %Program Files%\PPLive\PPTV\skins\default\previous_hover.png (771 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\hj_expand.png (284 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\speed3.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\ie.png (895 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\BDSwitch.xml (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_cate_hot.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_close_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\chrome\openurl.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\radio_checked.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\tomain_hover.png (475 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\speed2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\pause_disabled.png (376 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_downarrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pagedown_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\data\face\em49-·ßÅ­.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\close.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\PPVodDownload.dll (33263 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\gbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_cate_new.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hot_5.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\dt_titlebar_r.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_pageup_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bright.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_fav_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\checkbox_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\radio_checked_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\strengthenbtn02.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgress1.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\hj_unexpand_new.png (267 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\restore_down.png (660 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_top1.bmp (694 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\exbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\set_bg_left.bmp (62 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\close_numTip_hover.png (320 bytes)
    %Program Files%\PPLive\PPTV\data\NoCache.List (683 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\PPLive\PPTV .lnk (753 bytes)
    %Program Files%\PPLive\PPTV\chrome\UserSkipAds.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\button.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\checkstop_down.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\fullscreen_disabled.png (761 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_upright.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\brightness.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\sch_list_class_bg.bmp (2 bytes)
    %Program Files%\Common Files\PPLiveNetwork\player\OPlayer.ocx (34186 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\min_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\in_bg_right_bot.bmp (670 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute_disabled.png (647 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\PlayProgressThumb_down.png (278 bytes)
    %Program Files%\PPLive\PPTV\data\face\em41-ϲÔÃ.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mode_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\local\images\err.css (4 bytes)
    %Program Files%\PPLive\PPTV\icons\PPTV.MKV.ico (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\close_numTip_normal.png (204 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\edu2_up_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_left_bot.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\logo.swf (1552 bytes)
    %Program Files%\PPLive\PPTV\player\CoreAVC.2.0.0.0.ax (9608 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\previous_hover.png (771 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_top_bg_bar.png (229 bytes)
    %Program Files%\PPLive\PPTV\skins\default\fullscreen_hover.png (657 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_down.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\chrome\miniplayer.xml (8 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\shift_normal.png (510 bytes)
    %Program Files%\PPLive\PPTV\chrome\adselector.xml (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizemini2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\previous_normal.png (614 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_downarrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_min_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\stream_bg.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_screennormal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\unmute_disabled.png (653 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize1002.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\pop_close.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\PlayProgressThumb_hover.png (278 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\previous_disabled.png (489 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\previous_disabled.png (444 bytes)
    %Program Files%\PPLive\PPTV\data\face\em23-ÉúÆø.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\3\3\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\user_vip.gif (169 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\radio_checked_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\radio.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\top_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mode_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\miniclose.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\unfullscreen_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\PlayProgress1.bmp (13 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\radio_checked.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ex_button.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\task_play.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute3_normal.png (333 bytes)
    %Program Files%\PPLive\PPTV\data\face\em22-ÐÄËé.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_bg_top.bmp (476 bytes)
    %Program Files%\PPLive\PPTV\greprefs\all.js (9 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\max.png (288 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\2.png (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\VIPDownloadHDLogin.xml (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_bg_hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\common\small_frame_l.png (995 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\nav_status_r.bmp (344 bytes)
    %Program Files%\PPLive\PPTV\tab\1\1\2.png (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\InstallLog.txt (14482 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\in_bg_top.bmp (150 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_fav_down.png (757 bytes)
    %Program Files%\PPLive\PPTV\ipcfg.ini (343 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pop_close.png (784 bytes)
    %Program Files%\PPLive\PPTV\components\cmdline.dll (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch2_normal.png (761 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ex_button.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\muteplus_normal.png (326 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_left.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_bot.bmp (728 bytes)
    %Program Files%\PPLive\PPTV\tab\3\2\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\next_normal.png (624 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\min_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\speed0.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\5\1\1.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titletab.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\SpecifyPath.List (25 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\stream_bg.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_upleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\radio_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\close_hover.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\previous_disabled.png (418 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_down_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\download_pause.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\local\page.html (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\SliderThumb_normal.png (344 bytes)
    %Program Files%\PPLive\PPTV\skins\default\stream_bg.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize1001.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\vol_bar2.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\in_bg_left.bmp (174 bytes)
    %Program Files%\PPLive\PPTV\data\local\images\err_2.jpg (9 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\top_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_min_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\close_numTip_normal.png (204 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mini_title_m.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute3_normal.png (372 bytes)
    %Program Files%\PPLive\PPTV\skins\common\mini_main_r.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\strengthenbtn01.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\des.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\speed4.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_uparrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_Classic2New.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\resizewz2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\scrollbar_vthumbgripper.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_cate_new.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\mini_bottom_r.bmp (368 bytes)
    %Program Files%\PPLive\PPTV\tab\1\0\2.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize2001.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize1501.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\button.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\next_hover.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_close_hover.bmp (822 bytes)
    %Program Files%\PPLive\PPTV\chrome\playcontrol\playcontrolmini.xml (6 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize1002.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_min_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_epg_back3.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\exbg_bot.bmp (726 bytes)
    %Program Files%\PPLive\PPTV\components\NCList.dll (29256 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titletab_hover.png (6 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_bot_bg_hover.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\shift_down.png (462 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\Startup\PPTV.lnk (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\btn_min_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_uparrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\radio_checked_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\edu2_up_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\button_hover.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize2002.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\common\menu\arrow_right_disabled.gif (59 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize1502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\tab_background.png (133 bytes)
    %Program Files%\PPLive\PPTV\data\face\em42-Ť¶¯.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\common\checkbox_checked_hover.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\PlayProgressThumb_down.png (297 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\button_hover.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_collapse.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_hover.gif (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mini_main_l.bmp (176 bytes)
    %Program Files%\PPLive\PPTV\data\face\em07-´óÊå.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\checkbox_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\speed2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\fullscreen_disabled.png (761 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_down_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bg_left_top.bmp (6 bytes)
    %Program Files%\PPLive\PPTV\skins\default\regvip.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\button_hover.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_right.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\avatar_bg_s.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\checkbox_down.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute2_down.png (661 bytes)
    %Program Files%\PPLive\PPTV\data\face\em35-»Ò.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\play_normal.png (1 bytes)
    %Program Files%\PPLive\PPTV\tab\2\0\1.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\checkstop_hover.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\unfullscreen_disabled.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\sort_list_btn.png (667 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute4_hover.png (2 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\peer.dll (51087 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ie.png (895 bytes)
    %Program Files%\PPLive\PPTV\skins\default\checkstop_down.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_hot4.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute_disabled.png (647 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\saturation.png (366 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mode_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_pagedown.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\btn_screenhover.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\gbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resizeback.bmp (146 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\btn_close_2.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\sch_list_class_bg.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\PlayProgress1.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_pageup_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize0502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\ch_down.png (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\Send_Log_Kernel_Module.dll (8560 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\common\radio_hover.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ch_vip.png (443 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mode_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_check.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\list_table_vod.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\play_normal.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\mute2_down.png (661 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_pageup_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\vol_bar1.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\max.bmp (1 bytes)
    %Program Files%\Common Files\PPLiveNetwork\resource\ikan-p.ico (4992 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\next_down.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_selitem_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_epg_back.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\unfullscreen_disabled.png (331 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_updata_2.gif (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\radio_down.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\volume_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\close.png (311 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_bg_down.png (1856 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\scrollbar_downarrow_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_epg_back.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mute4_hover.png (961 bytes)
    %Documents and Settings%\All Users\Desktop\PPTV .lnk (741 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_livebtn.png (890 bytes)
    %Program Files%\PPLive\PPTV\skins\default\edu2_right.bmp (116 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\scrollbar_vthumbgripper_down.bmp (488 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_up_triangle.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\list_HD.png (544 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\expanding.png (353 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b.xml (293 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\close_hover.bmp (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_uparrow_down.bmp (938 bytes)
    %Program Files%\Common Files\PPLiveNetwork\player\MP4Splitter.ax (17848 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\small\volume1_hover.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resizetop1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\UPDATE\upgrade_title2.bmp (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\resize0501.bmp (2 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\Internet Explorer\Quick Launch\PPTV .lnk (759 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\passport_bot_bg.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\default\pause_close.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\dt_selitem_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\gbg_right.bmp (654 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\bg_numTip.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\titletab_on.png (844 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_uparrow_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\skin.ini (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\download_wait.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_header_select_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\bg_Classic2New.png (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resizetop1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\crossdomain.xml (121 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\strengthenbtn01.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\gbg_top.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\menu_down.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\vol_bar2.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_pagedown_disabled.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\common\scrollbar_uparrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\default\button_hover.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_cate_new.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\stream_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\data\pushvideo.swf (15 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_down.bmp (120 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\newsbg.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\dt_header_normal_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\UPDATE\upgrade_bg3.bmp (5064 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\radio_disabled.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\bg_left.bmp (134 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\hj_unexpand_new.png (267 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\adselector_title.jpg (6 bytes)
    %Program Files%\Common Files\PPLiveNetwork\kernel\PPHookShell.dll (9320 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mini_title_m.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\updatetipclose.bmp (3 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resize1001.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_del_record.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\notop.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\scrollbar_downarrow.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\edu2_downleft.bmp (104 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\ch2_normal.png (761 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\set_bg_right_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\data\face\em05-Ë§Æø.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\fullscreen_disabled.png (459 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resize1502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\edu2_close_down.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_pageup_down.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\bright.bmp (15 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\passport_bot_down.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\ex_button_hover.bmp (4 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\mini_title_r.bmp (696 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resizenotop2.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\s_close_down.png (473 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\set_bg_right_bot.bmp (70 bytes)
    %Program Files%\PPLive\PPTV\skins\default\common\radio.png (3 bytes)
    %Program Files%\PPLive\PPTV\chrome\About.xml (5 bytes)
    %Program Files%\PPLive\PPTV\skins\common\common\checkbox_checked_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\common\mini_bottom_m.bmp (280 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ico-exit.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\vol_bar2.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_progress_m.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\PlayProgress2.bmp (440 bytes)
    %Program Files%\PPLive\PPTV\skins\default\stop_normal.png (337 bytes)
    %Program Files%\PPLive\PPTV\skins\default\ch_disabled.png (475 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\hj_expand.png (284 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\list_del_record.png (2 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\PlayProgressThumb_normal.png (297 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\loading.gif (3 bytes)
    %Program Files%\PPLive\PPTV\tab\6\1\1.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default\shift_disabled.png (286 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\passport_collapse.png (1552 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\downloadbtn_disable.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\dt_header_normal_bg.png (1 bytes)
    %Program Files%\PPLive\PPTV\data\pplive_schedule_buttons.gif (2 bytes)
    %Program Files%\PPLive\PPTV\skins\common\btn_min_3.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_close.png (12088 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\resizetop1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\common\checkbox_disabled.bmp (576 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\volume_bar_2.png (1 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\tab_background.png (133 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\user_vip.gif (169 bytes)
    %Program Files%\PPLive\PPTV\restore.dll (5064 bytes)
    %Program Files%\PPLive\PPTV\skins\default\logo.jpg (784 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\mute2_normal.png (362 bytes)
    %Program Files%\PPLive\PPTV\skins\default\btn_screennormal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\resize0502.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\classic_b\vol_bar2.bmp (5 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\list_collapsed_treebox1.png (784 bytes)
    %Program Files%\PPLive\PPTV\skins\default\list_fav.png (885 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving.bmp (3312 bytes)
    %Program Files%\PPLive\PPTV\skins\3xgiving\regvip.bmp (8 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\pause_hover.png (943 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\btn_screennormal.bmp (2 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\scrollbar_pageup_hover.bmp (938 bytes)
    %Program Files%\PPLive\PPTV\skins\classic\shift_disabled.png (471 bytes)
    %Program Files%\PPLive\PPTV\skins\default\resizemini1.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\skins\default\max_hover.bmp (1 bytes)
    %Program Files%\PPLive\PPTV\chrome\education\NewDownload.xml (2 bytes)
    %Program Files%\Internet Explorer\PPLite\plugin\pplugin2.dll (9320 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\download_wait.png (3 bytes)
    %Program Files%\PPLive\PPTV\skins\default2\mute2_disabled.png (321 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\PPTV_Update.ini (2202 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\peer.dll (717377 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\UPDB.tmp (380 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\Core\resconfig\ResourceInfo.dat.tmp (2508 bytes)
    %Documents and Settings%\%current user%\Application Data\PPLive\PPTV\xml\control.xml (11 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\Core\resconfig\ppvaconfig.ini (1600 bytes)
    %Documents and Settings%\All Users\APPLICATION DATA (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\index.dat (2900 bytes)
    %Documents and Settings%\%current user%\Local Settings\History\History.IE5\MSHist012016052420160525\index.dat (388 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\Core\resconfig\pptl (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\webcache (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\wireshark.txt (533 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\Core\Config.ini (68 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\getcitycode[1] (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN (4 bytes)
    C:\FavoriteVideo\InvisibleFolder\peer_2.5.0.8761.dll.tpp (97 bytes)
    %Documents and Settings%\All Users\Documents\My Music (4 bytes)
    C:\$Directory (576 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content (4 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\Core\MngConfig.s3db (295 bytes)
    C:\FavoriteVideo\InvisibleFolder\externtab(3.2.1.1).zip.tpp (536 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\TrustUpload\2016052402000637762.dat (263 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\Core\Converter.ini (66 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pptv[1] (14780 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[1].xml (1716 bytes)
    %Documents and Settings%\%current user%\My Documents (4 bytes)
    %Documents and Settings%\%current user%\APPLICATION DATA (4 bytes)
    %System%\config (100 bytes)
    C:\FavoriteVideo\readme.txt (543 bytes)
    C:\FavoriteVideo\InvisibleFolder\pplss2.swf.tpp (1074 bytes)
    %WinDir%\Prefetch (672 bytes)
    %Documents and Settings%\%current user%\Local Settings\History\History.IE5\index.dat (484 bytes)
    %WinDir%\Temp\Perflib_Perfdata_668.dat (4 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\pluginad\AdConfig.ini (8281 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\Core\MngConfig.s3db-journal (4998 bytes)
    %Documents and Settings%\%current user%\Cookies (384 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\Cache\TrustUpload\2016052402000537761.dat (195 bytes)
    %Documents and Settings%\%current user%\Cookies\index.dat (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pptv[1].htm (19245 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\control[2].xml (2645 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data (4 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites (4 bytes)
    %Documents and Settings%\%current user%\LOCAL SETTINGS (4 bytes)
    %System%\find.txt (27 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\3\1.png (3 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5 (164 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\catalog[1].xml (2590 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\1\2.png (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\UPD9.tmp (380 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\3\1.png (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\17072340777[1].jpg (1080 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\getcitycode[1] (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\15264463677[1].jpg (50 bytes)
    %Documents and Settings%\%current user%\Cookies\Current_User@pptv[1].txt (1648 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\1\1.png (4 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\1\1.png (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\pptv[1] (17386 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\3\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\2\2.png (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\imgLogo[1].gif (295 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bg_bottom[1].png (335 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\0\1.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\0\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\3\1.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\13433875515[1].jpg (2857 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\2\1.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bg_portal[1].jpg (98 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\1\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\2\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\1\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\0\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\0\1.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\0\1.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\2\1.png (1 bytes)
    %Documents and Settings%\%current user%\Application Data\PPLive\PPTV\prefs.js (202 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\0\1.png (3 bytes)
    %Documents and Settings%\%current user%\Application Data\PPLive\PPTV\2.7.3.0009\compreg.dat.tmp (41776 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\0\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\3\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\screensaver\pplss1.swf (37 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\beacon[1].js (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\logo[1].swf (6844 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\312369caa76e476ecc8f28afeaabe1be (2531 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites\watchlog.s3db-journal (4760 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\0\1.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\0\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\3\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\1\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\2\2.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\common2[1].js (11 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\1\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\2\2.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\webcache\3\312369caa76e476ecc8f28afeaabe1be (21913 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\Favorites\Common.s3db-journal (512 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\3\1.png (3 bytes)
    %Documents and Settings%\%current user%\Application Data\PPLive\PPTV\2.7.3.0009\xpti.dat.tmp (1119 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\1\2.png (2 bytes)
    %Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[1].txt (207 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\3\1.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\3\1.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\3\2.png (3 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4 (37 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\2\1.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\2\1.png (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\09585262495[1].jpg (1076 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\12345[1].htm (526 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\2\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\3\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\2\1.png (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\10110990986[1].jpg (98 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\1\1.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\3\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\0\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\2\2.png (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\19041266534[1].jpg (1076 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\1\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\3\2.png (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[3].css (22 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\1\2.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\1\1.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\0\2.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\catalog[2].xml (196 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\2\2.png (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5 (933 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ppvadownloadbyurl_35601[1] (16777 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\3\1.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\2\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\tab2.xml (879 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\UPDA.tmp (380 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\2\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\0\1.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\2\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\2\1.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\1\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\1\1.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\logo[1].jpg (4302 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\tab.xml (516 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\webcache\3\312369caa76e476ecc8f28afeaabe1be.type (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4 (240 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\11\3\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\2\1.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\1\2.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\img_fill[1].gif (43 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\0\2.png (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\common2[1].js (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\6\3\2.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sta[1] (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\download[1].png (415 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\2\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\3\2.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\0\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\3\2.png (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[2].css (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\tab.ini (38 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\1\2.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\0\2.png (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\img[1].gif (1036 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\13470667633[1].jpg (98 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\5\1\1.png (1 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\2\3\1.png (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sta[2] (5 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\1\1.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\webcache\index.dat (76 bytes)
    %Documents and Settings%\%current user%\Application Data\PPLive\PPTV\xml\pop.xml (8281 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\0\1.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ppvadownloadbyurl[1] (33537 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\13\0\1.png (4 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\1\1.png (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\10144547146[1].jpg (1925 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\2\2.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\8\2\2.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\NewPopup[1].Xml (146068 bytes)
    %Documents and Settings%\%current user%\Cookies\Current_User@pptv[2].txt (1138 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\18092704918[1].jpg (98 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\menu[1].png (50 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\3\0\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\3\1.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\tab3.2.1.1.zip (1281 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\7\1\2.png (2 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\4\0\2.png (3 bytes)
    %Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[2].txt (370 bytes)
    %Documents and Settings%\All Users\Application Data\PPLive\PPTV\tab\3.2.1.1\1\0\2.png (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\PPTV(pplive)_forqd340[1].exe (2596152 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\PPTV(pplive)_forqd340.exe (86230 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "PPAP" = "%Program Files%\Common Files\PPLiveNetwork\PPAP.exe -background"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Atfmon.exe" = "D:\Stion\tmp....................................\a.{D71C5380-D2A0-CD69-E3EE-E1002B3A309E}.. hh.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now