Default query hit format

Hi,I have a new question.
1. I use the wireshark to capture the packet of the gnutella client such as "Limewire" or "Phex",I can find the request message(0x80),it is a udp message? But I find the number of the udp message is only one!! It indeed contains the keywork i searched.

2. But I can't find the response filelist messages which the type is (Query hit)0x81.Is the response response data of the filelist infomation encrypted or hashed?
Do you know the format of the query hit message?I think it should contains the file contain the keywork i searched,isn't it?

3. Is there some analyzer specified for the gnutella network?
