Gen.Variant.Application.Bundler.OptimumInstaller.1_074f981136
HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.Application.Bundler.OptimumInstaller.1 (AdAware)
Behaviour: Trojan, Installer
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 074f9811362c8ebac1642eea12719af0
SHA1: 5f92fe2f842d1c510882f7fa9341acf2cfc4fe71
SHA256: 31a04237d242aa27346f3f52ff4efa19ab77205f1b706214fa42e8c7fae686a1
SSDeep: 3072:j8vZJXthnUrezh5qTdYqOKsWiFNXYXYJiwLTEkP7RXBpxvNWV:mTXt5nzhKd58NxJBpxvA
Size: 224544 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: Premium Installer
Created at: 2014-06-26 00:00:36
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:1980
The Trojan injects its code into the following process(es):
%original file name%.exe:424
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:424 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\header_basicinstaller[1].jpg (1326 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\win98_cancel_button[1].jpg (615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\welcome_generic[1].jpg (1802 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp7.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\progress_gears[1].jpg (2313 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\win98_skip_button[1].jpg (567 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp3.tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp4.tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp6.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\win98_accept_button[1].jpg (567 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\muted_flashplayerpro[1].jpg (9874 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\progress_finished[1].jpg (4945 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp1.tmp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp9.tmp (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpA.tmp (6315 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\lock.temp (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp2.tmp (293 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\win99_bottom2[1].jpg (567 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\win99_decline_button_text[1].jpg (1340 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\win98_top_generic[1].jpg (615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp5.tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpC.tmp (342 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpB.tmp (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpD.tmp (3382 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp8.tmp (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\win98_left[1].jpg (3646 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\tmp3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp2.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp4.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp6.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp5.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\header_basicinstaller[1].jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp9.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpC.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpB.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpD.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp7.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpA.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp8.tmp (0 bytes)
The process %original file name%.exe:1980 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
Registry activity
The process %original file name%.exe:424 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A4 D0 A8 C1 AF 74 D8 DD F3 28 E7 1F E6 49 5A 62"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process %original file name%.exe:1980 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D3 94 CC E7 EB 72 02 6E 40 1C 7A 2E 3D DC 93 54"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: Premium Installer
Product Name: Premium Installer
Product Version: 2.4.8.1
Legal Copyright: Copyright (C) 2013 Premium Installer
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 2.4.8.1
File Description: Premium Installer
Comments:
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 155393 | 155648 | 4.49616 | 5fd40fbec820096fd2ca3947c299ae81 |
| .rdata | 159744 | 22610 | 23040 | 3.39348 | e491082b1048d75d4b4732fdb433ad06 |
| .data | 184320 | 6692 | 3584 | 2.04764 | 077561e5c28b2bbb91ac5f7f7f27cc69 |
| .rsrc | 192512 | 35996 | 36352 | 3.40479 | a9c57e8287c0a6e2c03c64fcd3b92162 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://imp.premiuminstaller.com/impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=dotnet_version_4.0&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro | |
| hxxp://imp.premiuminstaller.com/impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=admin_true&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro | |
| hxxp://imp.premiuminstaller.com/impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=guest&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro | |
| hxxp://imp.premiuminstaller.com/impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=setup_run&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro | |
| hxxp://config.premiuminstaller.com/config/FlashPlayerPro/offers.json?pid=installer&ts=2014-06-30T21:29:38.5802377Z&br=CR&ro=1&adprovider=matomy2&version=3.6.3.42 | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/Windows98/win98_top_generic.jpg | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/Windows98/win98_left.jpg | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/Windows99/win99_bottom2.jpg | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/Windows98/win98_accept_button.jpg | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/Windows99/win99_decline_button_text.jpg | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/Windows98/win98_cancel_button.jpg | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/Windows98/win98_skip_button.jpg | |
| hxxp://imp.premiuminstaller.com/impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=win98_linkdecline_theme&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/welcomescreen/welcome_generic.jpg | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/installerpackage/wisedownloads/muted/header_basicinstaller.jpg | |
| hxxp://d1s8azhe8rpvoz.cloudfront.net/bundles/flashplayerpro/muted_flashplayerpro.jpg?v=20130122 | |
| hxxp://config.premiuminstaller.com/installerpackage/wisedownloads/muted/progress_gears.jpg | |
| hxxp://config.premiuminstaller.com/installerpackage/wisedownloads/muted/progress_finished.jpg |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET MALWARE Adware.iBryte.B Install
Traffic
GET /impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=guest&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.153 Safari/537.36
Host: imp.premiuminstaller.com
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: image/png
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 21:29:43 GMT
Connection: close
Content-Length: 109.PNG........IHDR..............wS.....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx.b...?@....... .t.....IEND.B`...
GET /impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=admin_true&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.153 Safari/537.36
Host: imp.premiuminstaller.com
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: image/png
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 21:29:42 GMT
Connection: close
Content-Length: 109.PNG........IHDR..............wS.....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx.b...?@....... .t.....IEND.B`...
GET /impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=dotnet_version_4.0&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.153 Safari/537.36
Host: imp.premiuminstaller.com
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: image/png
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 21:29:42 GMT
Connection: close
Content-Length: 109.PNG........IHDR..............wS.....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx.b...?@....... .t.....IEND.B`...
GET /installerpackage/wisedownloads/muted/progress_finished.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: config.premiuminstaller.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: public
Content-Type: image/jpeg
Last-Modified: Mon, 30 Jun 2014 21:29:46 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 21:29:45 GMT
Connection: close
Content-Length: 36072......Exif..MM.*......................................................
.................................................(...........1........
...2...........i............. ............'.......'.Adobe Photoshop CS
6 (Windows).2012:07:10 13:43:38.............0221......................
.............................................n...........v.(..........
...........~...................H.......H.......FPhotoshop 3.0.8BIM....
......Z...%G........8BIM.%.........}.....pv....N8BIM.:................
....printOutput........PstSbool.....Inteenum....Inte....Clrm....printS
ixteenBitbool.....printerNameTEXT..........printProofSetupObjc.....P.r
.o.o.f. .S.e.t.u.p......proofSetup........Bltnenum....builtinProof....
proofCMYK.8BIM.;.....-..............printOutputOptions........Cptnbool
.....Clbrbool.....RgsMbool.....CrnCbool.....CntCbool.....Lblsbool.....
Ngtvbool.....EmlDbool.....Intrbool.....BckgObjc..........RGBC........R
d [email protected] [email protected] [email protected]#Rl
t............Bld UntF#Rlt............RsltUntF#[email protected]
abool.....PgPsenum....PgPs....PgPC....LeftUntF#Rlt............Top UntF
#Rlt............Scl UntF#[email protected]
ectBottomlong........cropRectLeftlong........cropRectRightlong........
cropRectToplong.....8BIM.........`.......`......8BIM.&................
?...8BIM............8BIM............8BIM..................8BIM'.......
..........8BIM.......H./ff...lff........./ff...............2.....Z....
.......5.....-..........8BIM.......p..............................<<< skipped >>>
GET /bundles/themes/Windows98/win98_top_generic.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 4081
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:47:12 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:47:11 GMT
Age: 6152
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: qrgs-GWovvRmkckOWEOI_sIdFKTT-1t9iMCybefuwjC0qAYrQ4JXXQ==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
............................................................... ......
......................................................................
....................W...1.!.AQa..#.."..2B3s.4%.v7.X...................
..Q...S....!1q.Aa2."..Br..s.4T.....#C$5.............?.....S.?R......5#
.......lxM..,f...E*2V.I%....^.Cu..%..}l.r5Q...W.Q>..wn%.......R5...
......c....m0bj.8e.J?..DC...g.[.fFM.60.......X").N....f.b....... p..I.
....4......"!.gc.{.....X'.w..kq..*DY7.<QVnLtGB..l...y.qV..Q.{U..f..
D8.3Y.p.6J2oj.........k2....FM.W.U.....\.fQ.x.(......rc..k...8o.%.7.\Q
VnLtC.s5.G..d.&...*....q.f.(..l.d..qEY.1..5..e.7......(.7&:!........Q.
{U..f..D8.3Y.p.6J2oj.........k2....FM.W.U.....\.fQ.x.(......rc..k...8o
.%.7.\QVnLtC.s5.G..d.&...*....q.f.(..l.d..qEY.1..5..e.7......(.7&:!...
.....Q.{U..f..D8.3Y.p.6J2oj.........k2....FM.W.U.....\.fQ.x.(......rc.
.k...8o.%.7.\QVnLtC.s5.G..d.&...*....q.f.(..l.d..qEY.1..5..e.7......(.
7&:!........Q.{U..f..D8.3Y.p.6J2oj.........k2....FM.W.U.....\.fQ.x.(..
....rc..k...8o.%.7.\QVnLtC.s5.G..d.&...*....q.f.(..l.d..qEY.1..5..e.7.
.....(.7&:!........Q.{U..f..D8.3Y.p.6J2oj.........k2....FM.W.U.....\.f
Q.x.(......rc..k...8o.%.7.\QVnLtC.s5.G..d.&...*....q.f.(..l.d..qEY.1..
5..e.7......(.7&:!........Q.{U..f..D8.3Y.p.6J2oj.........k2....FM.W.U.
....\.fQ.x.(......rc..k...8o.%.7.\QVnLtC.s5.G..d.&...*....q.f.(..l.d..
qEY.1..5..e.7......(.7&:!........Q.{U..f..D8.3Y.p.6J2oj.........k2<<< skipped >>>
GET /bundles/themes/Windows98/win98_left.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 28240
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:57:08 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:57:07 GMT
Age: 5556
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: eQ_-r4YGoS1455XkBtifnnLN-VnUYcoGecYnAw13uIM0rFXEtVEf4w==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
......................................................................
......................................................................
..................!1Q..Aa...q...".....2r3..5.v7.BR#.Dt...S.Td.VW..bs$.
EUu.&6f'8Cc4.%.(....w......................!1A..Qa"2.q..BR......br#3..
.C4...S.$..c....5...s..............?...47l...9........*..o....G.>..
? [email protected]`."[email protected][.O
)x..dI5....l...)SSC....m...Ms.?j.../.A..r..q(.NqV%..Z.-...}......Z...I
.]V'7$....YJ.r.O-`1..&...w...Y..Q.j.3[..cm...Ms.....6`"....`...q(.9.X.
.......b..[.].....7..5.E...,...L...m6[X..NMs...Sc...P.....k~..m.......
...m...t....m.4MuX..O.6......u.T...D...?j]...Kyyu.r.m.5.b~.6.[.....G.v
...%)Mi.v'7%=...._.Kr..Vj.Y5.b~.=..x.S...6....4MuX..O.6......u.T...D..
.?j]...Kyyu.r.m.5.b~.6.[.....G.v...%)Mi.v'7%=...._.Kr..Vj.Y9.QBsrK{ ..
oQnZ.c..*.d.5....M..v.....7.Z..ot.....}Ox......w$....C......iw..i..AqP
$.. r..Y..|%.....Q.yo.'.>.J....)....36..R.....v.Tdfm!Og......bQ..oe
gv;q.#3h.{y5.}....R...3q.(.....("36....SZ.'..R.......(=..Gj3r..."2B...
"...8f...0%.H.x....o_f-...*8.)..&R1..DH,.{.......)......5vr...=X[...,.
..tO....W._5..z..S................>W..dz..}..-.w~4'.............GF.
[mh.V.I......EB.geC......(..)W.;.*.8-.....=..j../.......=Gt..*.0oZ....
...k.....^...h....g.o.......kY..h..k..g..r36.......~....S.]E.....o....
>........Dn/[email protected]?.......5.Z.`[G.]..8........w.....&...@S.....<<< skipped >>>
GET /bundles/themes/Windows99/win99_bottom2.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 1571
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:47:13 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:47:13 GMT
Age: 6150
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: xJ2df9b0zIG6aG-zQJX4LGwxVv5XsS05pN-gNwTSal18t76hWeI5CQ==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
...............................................................;......
.........c............................................................
..V...q.C...!1A.cF...............................?....'..t...C...W.._.
............_..~|||....Q........<|..'...Ci....&.6.9...o.i....&.6.9.
..o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&
.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i
....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9.
..o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&
.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i
....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9.
..o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&
.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i....&.6.9...o.i
....&.6.9...o.i....&.6.9...o.i....&.6.9...o._.?g..TF...T......z....y._
....o.................................................................
.........^.._`@.......................................................
...............W......................................................
......................................................................
.............../.z..}.................................................
...................^.._`@.............................................
.....................|.].....5|....@..............................<<< skipped >>>
GET /bundles/themes/Windows98/win98_accept_button.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 1961
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:56:01 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:56:00 GMT
Age: 5623
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: Cr_TRm0rxW5unAlbZ9jVbWn1Ck19t34biDUW12Dif8pVeondN_Z4ig==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
......................................................................
.........{............................................................
...........!..1...S....XAQ"u2....#68.q..B3............................
[email protected]/'.. [email protected]...|[email protected].
g./5......z^j....y.......v.=.y..>&..{..P8|[email protected]....
..n.g./5.z.K.m\/.....h.R.n..8d.LE..w...j..&(....h;....A#^........F.9.P
C.. ...=...ld...e..aE..."./...8..E:.Q*..pu. .m0.A6P......"..".k.....eY
(v.........5...A.4........#[...U2.[(.7;.X......._.@....]........go....
.....X.)&.... .0...%)...yG..6W.D.........i..).0w*...]M7.......m..t..0.
. .Mo?.P..^.%is..r.P..T.)\..1...P....9vPk`2.1..&bm..o.I..QI.,.[..T....
T.8.JA(..........o.3C).6..%......F".....w.7A....J...N..41v.....AP...n.
.w...([email protected].#A..()m.. .o2...r......W.....Y~.r$..........P.0n.
..#.8.c.lgry...!.......D.....fI..;i....(..`A....1...4.......n...5#.m.m
..E..Y.....S.G....@z.(k....h?<*... .s|..Q.A..2d....X.B%3.6..3n....u
......Z.^.;.a...h T......q....$x.]^$..p.....)..`...W....Fy.%..-.D./[V.
....E.h.Z5.t.\...$.....J....XSX.......P[.....U..... ...'.....Uk...?..a
.[...o}.}.....L4im....nI.Y*.FA..Ad..u.B(P......vPZ...B....N}.7........
.G.4....e..z..P..5....6......xV.N.....,..........&R.....x..../m.~NR.rF
.=...e.o..l.....}R..c.N..O......vPs.qN1cu-|....[....\.G6#[email protected]
.........^3.......I..(....l..{..@..!. Q............~F..z.P.T[c..XJ<<< skipped >>>
GET /bundles/themes/Windows99/win99_decline_button_text.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 1340
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:56:02 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:56:01 GMT
Age: 5622
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: fSRd4_3gzGzY8GQd72-DwHbFT5Bd6hFpxd1xByLEt5ZFusf5dG4BqA==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
......................................................................
.........k............................................................
..........!1...V.AQ...aq"2#..............................?............
................................*.r8[/..w...-..L.J.b.....0..k...`..E..
.9x>c.W.....c9._.6r....<......$...t.{....ix..-3.....a.V.....W.D.
.......\V...=.[u...?.....&.S.]r....2-d.."..'.....7.....5.G..z...?'.r..
-....AK..ul.W......iq.ol........5'j....e...^.o.Y%-=i.c8.1-..?)..7W5)nB
.BQ...o...S.j..fh9...gx~=...;......}t..vT.....19O....&Z..-~.#.....~.(.
....j$>..lo..Y:<W...Gd.&[R..m...E......u..ZW.....%.v.Ep.M...Z.O.
F@/.........F...\g.w..c...qb.K....DbTY.I?.M!..ih..{........,.#.. _a..u
..y...V.X......T..m..T...}..........~].UaVsX.j.f9.V.ur...TwY[i[.8...{K
E..{...}..Z.q,..{?.....&Q.1..<.Rm&1...ku....[..=z."H....5..6}I.e..X
[email protected].#...mk'.t4ut.......\.<...^...-
...}u"..e.}..i...W.....e"..T.u...r#d.%.J...3...........e.r...u.e'..-..
d...sr8.IuN.-.iq.xZ.B.>......`@..|.p#.)b...e(B.I!...D...$...I.}....
.........{$.1..#02*.....He....\$.$.[RO...i..qw...........l..^p..\].6}D
.8......>.W.....{M.Q ...K........|%...g.J..H.UP) .T..(..Q...F.....j
.3>..S................................<<< skipped >>>
GET /bundles/themes/Windows98/win98_cancel_button.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 2441
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:56:02 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:56:02 GMT
Age: 5622
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: _xQXbY2s9-gla3tHCppnWls1UaSWLyc-yD_Ze07Qfgwv8T0SW2qh7w==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
......................................................................
.........|............................................................
...........!...."..1A.S...XQ#...5u8.a.2BEV'...........................
[email protected]/'.. ..dr&n.@[email protected]...|M..~){(.>&..?......{...^.
.O...../[email protected]:|M..~){(.>&..?......
{...^..O...../e.z.K.m\/.....h.R.n..8d.LE..w.........#.oA..(.....\Q6.=.
n..ec.n..IJ.7..l..8.....=c.. ......!..m0.q..,.[mY.3y......n......S.M..
..S..&......;<..\..e...#..dm.}Y...M..].v..*....J".*.. .....!Am....{
.o.#.....Q.x...t`~_Q..s9|}...5.]h7...7.>'1..WL;.d..^z>&.....$...
.Y w'#....V..H..l...S.~$p....&.[.MJ...-f..e....$.9.......X........PYH.
[email protected][email protected]...&.....;...k7a.r..I..lC...i)..Q.N.QChR(C)..
#.....(:K....#.wE..n.,U.*R/..8.@JU\....d.'....#..("<..#`.%..qT...6.
P<s.-...pp.'Mn.d..AA..2...A1....q...j9..=..,..p..,..QYT[...&C..L. .
.M.2.4.);.....m>..c6%...c.2...H..A..4.J.....;.W..9..7..P[....A..kiK
_~.d-.........Ssm.q.1.H..'....h"<[.q......\.v........r.....&T.5x..(
.dNQ(.....Cz...H....$..B.7.2.K.....H.I.(.L..D....8T.%..D....Al|=.{>
..X.#..........O.k..q.6t.3.....V....z.....ZKz..............3...r...r.d
..Y....9.Q.v0h;..W.....S2..kg.~?..h!A......Q.}......m.m...m..o(.J-....
..y8...)..h0...j.K...R.;.....q...s..m..X...9..'m...-9&... ...^E.Q]..0.
...N".....,{......U...:..9I.. .\.].....h..;..zw..s*.....I.4J..KY.$<<< skipped >>>
GET /bundles/themes/Windows98/win98_skip_button.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 2029
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:56:03 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:56:02 GMT
Age: 5622
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: u8mP8vLjyonWh1zO7996r7Hgq6uO0jpiaAWr_jrkXUQHTnOKxfb5Jw==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
......................................................................
.........}............................................................
...........!.....S....X1AQ.uq.".6a.2$..8..B#..........................
[email protected]/'.. [email protected][email protected]_3......n.g./%...
.|.j^J............u.=.y(.>&..{R.P8|[email protected]_3......n.g./
%....|.j^J....&.._.\.........Vp.H..3H..):U..LP...6.ot....F...O..K/....
..C.4....L.sn..t.........9......l2.x..}.fK.....:....Z....^>l.i.Q]..
D............W..~.....gJ.[...{Z..w..4.G%q...q....$..%9..wm..|_-....- .
.iyY..we.....j.Q:.........u..C..m..J.|{i5l....h.b.7.~.i4.(.X.n..".....
.p...G@.]..e.s...;[...crB<..e.\&.......f1u.xk.v}..f.._...I[......L-
..-.Nf.%e.....R9.)..eT.....B....c.......o.uF$.>..H.....:...R..pO.HL
ML#.b.....c....X.....A..vs4..T.r.@#PYTx.3.....ot.'.....(*.....s....%..
.P(..5..~..Y.x.G4.g.*.........QD.. S*r.D.(....h.AA..c..H.s.1.D...s.YW7
\l-..*F....%%[email protected].~..W..'y.....Y.x...n...YM...2..L..
...8...5........"...rQ.R.a$L.S.N.Y.....:..:..OE.":.w....A.C.....V.>
\S5...........X..o....EP........X.... ..^.....e....L.....b......F?.n..
......(:,....|E.V.9...`H..)....r...:.H.X.~.....0UB...o...........2..
..$..3.......I3..6r...n.'Y.Is{v..P....%.7...a..q.^.s7Z...}V.PT/.?.....
.0J.{@.P(${.@..>._.......u..A...lAuM...q..;>S..0.-...b....:b'.}.
..nO..nPaFJ.6@m.)..E.TU...AM5...z...%)...l...JY.T..G.6.,......v..u<<< skipped >>>
GET /bundles/welcomescreen/welcome_generic.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 11049
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:48:43 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:48:43 GMT
Age: 6062
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: WEUjpVDTt1J5pgo8rv94up7TpNplfakqn8mBlEKY7Ev18GT2Zd_uDA==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
......................................................................
......................................................................
...............1..!AQa.r....q.."2..BR3...#.b....CS....................
.!..B.1.AQ..aq.2..."..R..b...............?....n..y..u..7\9....7.9....7
\9.....y..t.......0c.....0g...X..u.y..t........u.y..u..7\g..._.>..[
...._..B.vg....'`.J.............................................../.t.
...,...r....$......K....,...rH..`r.....,.. rH...,.. rH.....B......J.w.
\...W..d...\............................................y..n..........
........................F9a...9`..................n4...k.{..Ngfz .[.v.
..............................................<.....7.............?
`2.......?|..~....K.w.....W..d...\....................................
........y...47...`.c....b.......u......k. k.L...N..........Og.cX.X.X..
..4.~..../.7..^........V...! .........................................
....?..p....5.A(..H.B........1......gY.Y.b`..w....J....~...._3=.......
.........................................................-.".o1?../..n
.'.A KX.2.M......q:..x..x..x........m............D...0.k. .{.lN.G.~...
._3=...........n......................................................
2,...%.1.....k ....PpgI......k..d......Y......6..dx...w....*....t.....
s.|..._..C.6g....'`.j..............................................o47
..Qi...'...k.1...(...(.~.N8.`....X.k0..4.|.. ..........v..D......,<<< skipped >>>
GET /installerpackage/wisedownloads/muted/header_basicinstaller.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 5341
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:47:15 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:47:15 GMT
Age: 6150
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: _dQuCKRV1xeVATqW162VGbJtCogv0939BM94eVcx-fOKoqGkMYbc8w==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
...............................................................R......
......................................................................
..................1A..V.!.".....U.WQ.R..Ta.2S.q..Bbt.w................
......Q.R..!..1A..aq..."2Br3D.............?....................I.w...-
%*....'V...i...0m.....`..r............................................
......................P.t.'........~,.l....Y.m6.s...eQixYm.n.DVR.....
.........k3.2...2.O-.Wm\.M$.O jifM4..Bbbi$LLV.".K..w.7.......R.H.Jjy`.
j".U......,...8 W..... .-z..d......d....<(.e..&...mi^..z...a[.t]O.X
..9....z.E....2...4..4...M.K..[t]...;.-...L.c.O.m.....3F..jk6fv...r...
*...Q.. V..W.%.,.lOnkW%Pi...onfnf...... .\.7..O6. ....................
................................................. R.s}.......u.......g
.n|..]........oc.)wF..r.Bir.e..n\i-.....Gq..9.p...:.[7n......z.....n..
....m.:n.wq>....>..xm..r4.>w-.......k..q...i.SE/........ub.~.
...u/..M....j..........rv...ylj...Y..*M.6k.#![...].........{;v........
.~..|............_............1'..vK{...9...c_.LX.eB7.....S....6mx.Rz.
}..k.....<...=..Oww.q..[^.......t}..k.M.j..}n.6f.y=be4..i<......
y.....f..e.3.Z..kw|..)7DDL....\K...8........O.l..?......g......?.....i
._...W..v..4h...Wc=.\..,R.j-..Qk..|x..7wM-.....[....m".31.............
........2u.<K3;.y6-..i\%.u.Y..jn...eh....u....e.O......7...)tE\...#
..H....{SL..E.>.....:...b......d\.Y<3(M',....)>g....m.7W.<<< skipped >>>
GET /bundles/flashplayerpro/muted_flashplayerpro.jpg?v=20130122 HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 56471
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:54:52 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:54:52 GMT
Age: 5693
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: -iBW5RrQVD1WHJvKAA3sL0K9bin4h6OXI2KYmYMHSWil3qRU9vR-dA==......JFIF.....x.x......Exif..MM.*..............Ducky.......P.....C...
.................................................................C....
......................................................................
.."............................................................}......
..!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcde
fghijstuvwxyz.........................................................
.....................................................................w
.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
..................................?........|.<........7..7.......Q.
o..o.7.....8...o..g.7...8....8...;.......?..y?.....y..y.........}..=..
O...].j...z<.zo.G.@%a.g..o.7.....8....7..7......Q....P1.o..o.7.....
8.IXw..G..M...(...(..~.....q....p.....N......-]..K.....~..........$}.S
......QEyg..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE
..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..?....`XT....
.....-..QE......-......-..QE......-7.....l..P.l.l..P.l.l..P.l.l..P.l.l
..P....Ce...?.............................~........#....X...0.. .= ..(
...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(..
.(...(...(...(...(...(...(...(...(...(...(.....qS..Wq.....P.......@...
(...~..,........9[4.([email protected]
[email protected]...?...............}.............~{......#....X.
..0.. .= .....(...(...(.4P.E.P.E.P.E.P.E.P.E.P.E.P.E.P.E.P.E.P.E.P<<< skipped >>>
GET /installerpackage/wisedownloads/muted/header_basicinstaller.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d1s8azhe8rpvoz.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/jpeg
Content-Length: 5341
Connection: keep-alive
Cache-Control: public
Last-Modified: Mon, 30 Jun 2014 19:47:15 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 19:47:15 GMT
Age: 6150
X-Cache: Hit from cloudfront
Via: 1.1 ae96545e0552212804f85fcc54706cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: zim6TUInuFwF4Hs1mfkDoWqlWRw00CEkQRrS99nLEv10BM9HMCyhoA==......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
...............................................................R......
......................................................................
..................1A..V.!.".....U.WQ.R..Ta.2S.q..Bbt.w................
......Q.R..!..1A..aq..."2Br3D.............?....................I.w...-
%*....'V...i...0m.....`..r............................................
......................P.t.'........~,.l....Y.m6.s...eQixYm.n.DVR.....
.........k3.2...2.O-.Wm\.M$.O jifM4..Bbbi$LLV.".K..w.7.......R.H.Jjy`.
j".U......,...8 W..... .-z..d......d....<(.e..&...mi^..z...a[.t]O.X
..9....z.E....2...4..4...M.K..[t]...;.-...L.c.O.m.....3F..jk6fv...r...
*...Q.. V..W.%.,.lOnkW%Pi...onfnf...... .\.7..O6. ....................
................................................. R.s}.......u.......g
.n|..]........oc.)wF..r.Bir.e..n\i-.....Gq..9.p...:.[7n......z.....n..
....m.:n.wq>....>..xm..r4.>w-.......k..q...i.SE/........ub.~.
...u/..M....j..........rv...ylj...Y..*M.6k.#![...].........{;v........
.~..|............_............1'..vK{...9...c_.LX.eB7.....S....6mx.Rz.
}..k.....<...=..Oww.q..[^.......t}..k.M.j..}n.6f.y=be4..i<......
y.....f..e.3.Z..kw|..)7DDL....\K...8........O.l..?......g......?.....i
._...W..v..4h...Wc=.\..,R.j-..Qk..|x..7wM-.....[....m".31.............
........2u.<K3;.y6-..i\%.u.Y..jn...eh....u....e.O......7...)tE\...#
..H....{SL..E.>.....:...b......d\.Y<3(M',....)>g....m.7W.<<< skipped >>>
GET /installerpackage/wisedownloads/muted/progress_gears.jpg HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: config.premiuminstaller.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: public
Content-Type: image/jpeg
Last-Modified: Mon, 30 Jun 2014 21:29:46 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 21:29:45 GMT
Connection: close
Content-Length: 16093......Exif..II*.................Ducky.......<.....ohXXp://ns.adobe.
com/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?&g
t; <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-
c061 64.140949, 2010/12/07-10:57:01 "> <rdf:RDF xmlns:rdf
="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description
rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRe
f="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://n
s.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:57C758BEE118E0
119991D3FF3085063B" xmpMM:DocumentID="xmp.did:63081AE24D1D11E19CEAEEC1
614698B7" xmpMM:InstanceID="xmp.iid:63081AE14D1D11E19CEAEEC1614698B7"
xmp:CreatorTool="Adobe Photoshop CS5.1 Windows"> <xmpMM:DerivedF
rom stRef:instanceID="xmp.iid:A0EFED24164DE1119CBFDE150E64FAC5" stRef:
documentID="xmp.did:57C758BEE118E0119991D3FF3085063B"/> </rdf:De
scription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"
?>....Adobe.d......................................................
......................................................................
......................................................................
.......................................!1..AQ.aq"2...B...R#tbr.3..67..
..C5....S4.....$.u.......................1!A............?..R..........
......................................................................
......................................................................
..................................................................<<< skipped >>>
GET /config/FlashPlayerPro/offers.json?pid=installer&ts=2014-06-30T21:29:38.5802377Z&br=CR&ro=1&adprovider=matomy2&version=3.6.3.42 HTTP/1.1
User-Agent: 074f9811362c8ebac1642eea12719af0
Host: config.premiuminstaller.com
HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Length: 64951
Content-Type: application/json
Expires: -1
Server: Microsoft-IIS/7.5
Content-Disposition: attachment; filename=
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 21:29:43 GMT
Connection: close{"headers":[{"1":"hXXp://d1s8azhe8rpvoz.cloudfront.net/installerpackag
e/wisedownloads/muted/header_basicinstaller.jpg","1.25":"hXXp://d1s8az
he8rpvoz.cloudfront.net/installerpackage/wisedownloads/muted/header_ba
sicinstaller.jpg"}],"theme":[{"themeName":"itunes_test_theme","top":"h
ttp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/itunes/itunes_theme
_top_click.jpg","side":"hXXp://d1s8azhe8rpvoz.cloudfront.net/bundles/t
hemes/itunes/itunes_theme_left.jpg","bottom":"hXXp://d1s8azhe8rpvoz.cl
oudfront.net/bundles/themes/itunes/itunes_theme_bottom.jpg","acceptBut
ton":"hXXp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/itunes/itune
s_theme_accept_button2.jpg","declineButton":"hXXp://d1s8azhe8rpvoz.clo
udfront.net/bundles/themes/itunes/itunes_theme_decline_button2.jpg","s
kipButton":"hXXp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/itunes
/itunes_theme_skipall_button2.jpg","quitButton":"hXXp://d1s8azhe8rpvoz
.cloudfront.net/bundles/themes/itunes/itunes_theme_okthanks_button2.jp
g","xButton":"hXXp://d1s8azhe8rpvoz.cloudfront.net/bundles/themes/itun
es/itunes_theme_x_button.jpg","width":"6","headerHeight":"40","borderC
olor":"198,198,198","source_whitelist":"google_itunes-search*","offer_
visibility_threshold":50,"clientWidthOffset":"196"},{"themeName":"win9
8_test_theme","top":"hXXp://d1s8azhe8rpvoz.cloudfront.net/bundles/them
es/Windows98/win98_top_generic.jpg","side":"hXXp://d1s8azhe8rpvoz.clou
dfront.net/bundles/themes/Windows98/win98_left.jpg","bottom":"hXXp://d
1s8azhe8rpvoz.cloudfront.net/bundles/themes/Windows98/win98_bottom<<< skipped >>>
GET /impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=setup_run&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.153 Safari/537.36
Host: imp.premiuminstaller.com
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: image/png
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 21:29:43 GMT
Connection: close
Content-Length: 109.PNG........IHDR..............wS.....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx.b...?@....... .t.....IEND.B`...
GET /impression.do/?user_id=7fa0f3be-1a6f-4e60-8fe5-e3049afabc41&event=win98_linkdecline_theme&spsource=matomy_lightspark-highvolume-US&implementation_id=3.6.3.42&subid=223761&traffic_source=matomy2&offer_id=FlashPlayerPro HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.153 Safari/537.36
Host: imp.premiuminstaller.com
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: image/png
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Mon, 30 Jun 2014 21:29:44 GMT
Connection: close
Content-Length: 109.PNG........IHDR..............wS.....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx.b...?@....... .t.....IEND.B`...
The Trojan connects to the servers at the folowing location(s):
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1980
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\header_basicinstaller[1].jpg (1326 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\win98_cancel_button[1].jpg (615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\welcome_generic[1].jpg (1802 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp7.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\progress_gears[1].jpg (2313 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\win98_skip_button[1].jpg (567 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp3.tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp4.tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp6.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\win98_accept_button[1].jpg (567 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\muted_flashplayerpro[1].jpg (9874 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\progress_finished[1].jpg (4945 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp1.tmp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp9.tmp (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpA.tmp (6315 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\lock.temp (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp2.tmp (293 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\win99_bottom2[1].jpg (567 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\win99_decline_button_text[1].jpg (1340 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\win98_top_generic[1].jpg (615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp5.tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpC.tmp (342 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpB.tmp (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmpD.tmp (3382 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tmp8.tmp (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\win98_left[1].jpg (3646 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.