Trojan.Win32.IEDummy_20e36ad04f
HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.Win32.IEDummy.FD (Lavasoft MAS)
Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 20e36ad04ff6515d68b61362b2a06512
SHA1: 4f0152fe37f0d5dffa275d3d786b90c9582ac834
SHA256: 1c4994fb9ea24c0037e8d905211e66ab0a005631c39ff05cc43127c8c7f92886
SSDeep: 98304:BmRAsB9AM0rOOXF7rW12QyUf9axezFFoE1PK7BdUCAqNpDg8zA:Bm7B9AM0jXQmUfIezFfY/Ju8E
Size: 4868347 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2007-09-20 15:34:46
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
msisetup.exe:592
msisetup.exe:1564
%original file name%.exe:348
The Trojan injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process msisetup.exe:1564 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\BYBRWJVG\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3I2TUWDI\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TFZ1DZO2\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\B55C40TD\desktop.ini (67 bytes)
The process %original file name%.exe:348 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (169540 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\__tmp_rar_sfx_access_check_276359 (0 bytes)
Registry activity
The process msisetup.exe:592 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "57 C2 E6 CE AF AC 73 5A 48 55 74 E7 61 0A DD 3F"
The process msisetup.exe:1564 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryCount" = "16"
[HKLM\SOFTWARE\Microsoft\ESENT\Process\msisetup\DEBUG]
"Trace Level" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"TypesSupported" = "7"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CB CA 54 A3 1E 27 84 CB 97 9B 4D AF 74 DA 5D 15"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Internet Explorer]
"iexplore.exe" = "Internet Explorer"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\ESENT\Process\msisetup\DEBUG]
"Trace Level"
The process %original file name%.exe:348 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A7 7E D6 77 38 55 F4 D6 3C 61 DA E3 FF 1D F3 C3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\RarSFX0]
"msisetup.exe" = "msisetup"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Dropped PE files
| MD5 | File path |
|---|---|
| 52801f1610d2b3121b1a374b49b68eb8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\RarSFX0\msisetup.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 81920 | 79872 | 4.48153 | 8c499086717691066d921075ed5bdb09 |
| .data | 86016 | 28672 | 2560 | 3.40313 | 0cb811e47f78b5404a658fb36b591857 |
| .idata | 114688 | 4096 | 4096 | 3.55201 | 8bf175092a70a21f11fd06cc4087c7d0 |
| .rsrc | 118784 | 16822 | 16896 | 2.98979 | e56287babd73f9c7a9cd2d4d38334457 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://presentaci.ru/downloads/752_55394.ppt | |
| hxxp://presentaci.ru/style.css | |
| hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/font-awesome/4.1.0/css/font-awesome.min.css | |
| hxxp://vk.com/js/api/openapi.js?115 | |
| hxxp://presentaci.ru/fonts/glyphicons-halflings-regular.eot? | |
| hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/font-awesome/4.1.0/fonts/fontawesome-webfont.eot? | |
| hxxp://presentaci.ru/images/logo.png | |
| hxxp://counter.yadro.ru/hit?t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 | |
| hxxp://counter.yadro.ru/hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 | |
| hxxp://counter.rambler.ru/top100.jcn?2768890 | |
| hxxp://counter.rambler.ru/top100.scn?2768890&rn=139404967&v=0.3i&bs=1256x677&ce=1&rf&en=utf-8&pt=404 Ñтраница не найдена&cd=32-bit&sr=1276x846&la=en-us&ja=1&acn=Mozilla&an=Microsoft Internet Explorer&pl=Win32&tz=-120&fv=11.6 r602&sv&le=0 | |
| hxxp://vk.com/js/api/xdmHelper.js | |
| hxxp://googleapis.l.google.com/ajax/libs/jquery/2.1.1/jquery.min.js | |
| hxxp://cdnjs.cloudflare.com/ajax/libs/jquery-cookie/1.4.1/jquery.cookie.min.js | |
| hxxp://yandex.st/share/share.js | |
| hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/bootstrap/3.1.1/js/bootstrap.min.js | |
| hxxp://plus.l.google.com/analytics.js | |
| hxxp://mc.yandex.ru/metrika/watch.js | |
| hxxp://plus.l.google.com/r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 Ñтраница не найдена&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947 | |
| hxxp://a767.dspw65.akamai.net/msdownload/update/v3/static/trustedr/en/authrootseq.txt | |
| hxxp://a767.dspw65.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab | |
| hxxp://netdna.bootstrapcdn.com/bootstrap/3.1.1/js/bootstrap.min.js | |
| hxxp://www.google-analytics.com/r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 Ñтраница не найдена&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947 | |
| hxxp://ajax.googleapis.com/ajax/libs/jquery/2.1.1/jquery.min.js | |
| hxxp://maxcdn.bootstrapcdn.com/font-awesome/4.1.0/css/font-awesome.min.css | |
| hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt | |
| hxxp://maxcdn.bootstrapcdn.com/font-awesome/4.1.0/fonts/fontawesome-webfont.eot? | |
| hxxp://www.google-analytics.com/analytics.js | |
| hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | |
| apis.google.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /ajax/libs/jquery-cookie/1.4.1/jquery.cookie.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdnjs.cloudflare.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/javascript; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Mon, 28 Apr 2014 23:00:06 GMT
Expires: Sat, 25 Feb 2017 11:15:51 GMT
Cache-Control: public, max-age=30672000
Access-Control-Allow-Origin: *
Content-Encoding: gzip
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 27fda1c8f33302db-AMS22f............}[email protected].=...1AJ.....T.Z...$'.....`...B....c..FQO..7.
f......X..n.....o3......~~.....z.Z'N.M%...!B.m.&.R...~....H...c.v&S.Y@
[email protected]{s...H..........(.....>A.w )
...^@b:........_~...3.m."x<8h]@....!..t....."W....CU...#~3b..2...'.
2....26.`.`....mGG........./[email protected]..(.....I_U..c$,
Jh...n.31.....gku$Ng.>...TF7F..mO.Y.............N..F.($..].xN......
...D.T-..8...l../.W. \...'U..,..?.........&Y.....8..o..S$.O.".z]g28.}g
....:@..D......{.m.6..B*.$[..n....dm.)h-....0JSBPe..f.\@..5.}.........
\9.]...S..-7...8a...s.37.......]g)...v.A._...~5W..., .#!L.x<....}.v
....3........%.Yj..c.=........ux>..q.1.f..o.tP..t.......F.=...z....
.G.nF5......f._..>.......0..HTTP/1.1 200 OK..Date: Mon, 07 Mar 2016
11:15:51 GMT..Content-Type: application/javascript; charset=utf-8..Tr
ansfer-Encoding: chunked..Connection: keep-alive..Last-Modified: Mon,
28 Apr 2014 23:00:06 GMT..Expires: Sat, 25 Feb 2017 11:15:51 GMT..Cach
e-Control: public, max-age=30672000..Access-Control-Allow-Origin: *..C
ontent-Encoding: gzip..CF-Cache-Status: HIT..Server: cloudflare-nginx.
.CF-RAY: 27fda1c8f33302db-AMS..22f............}[email protected].=...1AJ.....T
.Z...$'.....`...B....c..FQO..7.f......X..n.....o3......~~.....z.Z'N.M%
[email protected][email protected]
{s...H..........(.....>A.w )...^@b:........_~...3.m."x<8h]@....!
..t....."W....CU...#~3b..2...'.2....26.`.`....mGG........./[email protected].
..lW..g4...m..R..(.....I_U..c$,Jh...n.31.....gku$Ng.>...TF7F..m<<< skipped >>>
GET /analytics.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.google-analytics.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 09:40:24 GMT
Expires: Mon, 07 Mar 2016 11:40:24 GMT
Last-Modified: Thu, 04 Feb 2016 00:31:28 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 10938
Age: 5728
Cache-Control: public, max-age=7200...........}.s...... .\.j&....r.s(gw.-^...Ii$.&.@f./1|...nI......U.Su.
..K....W..H.....oy.dU...{.i?J...O...Y{U..x.........)...A.1WT..H.....(v
.;.t/Y.4...........a......j...=......j.............kcc..^...f.l.z.....
.v>~...?8.|t|r.....s....z.....f8....tr{w....\..|......~8...x;u.....
.c.N......EC.q...?.......P.."..\.|.....\..a.}YX8.......FB9.-.F..9%.K&.
;[email protected]=..0.~..d...zL...X.l..,R......N!.~..\.\.yf.\...|.......
5..t....k..E.R5..X....%. (........J.O...?\B.....X::N.h.....\...8c.....
v..'.J.......}1.&i<..(.....P... ...:8..m3M5.X.[<.r...y.....8lF.{
."......4K..{.zn9....&.n.."V<Uo..F.S..n`\....d........O)..".v#.....
...O... Wo.......x4...D.&|(po....iq.4..Gw.ea...ni..`.(E...}...[...%...
...r.B."....).}..VK...8T...L.T.].=.8^x....s{.....-.g".h.:x....'U.i.'..
&.2x.0.@......@......*. .]8............7.m\..?.1..."..$*N_)8...%.....v
.s.O.q......#.,d.3 F.../..&..S ....t.ci/C]....w<..d.&...&,..=,..X].
8Vq.......i]./...OU...,.......^_>&.)a6.@'..,..t...z....z,j..{......
r:[email protected]!<......"...........a...l..
....m....]....Yd.N..........a<...<.=....C"...... ..L...De..Jq(..
fgT..]...x..C...M..|[email protected];.x..qCEG.....@T.[..3.\..9I..].4
. ..W.fI's]..q....f.... ^."...x.[[email protected]>....Gwl/.#[email protected]...
....@....%x.............W..pp.uz|MF...j..g....R[=.......|...jU..@L....
.YC......PSO.....XG.v4...9....k...............).....r......N..H...%..K
..*.]y.[....R.0.h....f9..-...S..=.`....T.-.j...2.B.........:.....e....
...hl...$..@P...=..j.............l@Z`.i.....G......S#...0,7Ky.k'.p<<< skipped >>>
GET /r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 Ñтраница не найдена&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.google-analytics.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Date: Mon, 07 Mar 2016 11:15:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Server: Golfe2
Content-Length: 35GIF89a.............,...........D..;HTTP/1.1 200 OK..Access-Control-All
ow-Origin: *..Date: Mon, 07 Mar 2016 11:15:52 GMT..Pragma: no-cache..E
xpires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, no-sto
re, must-revalidate..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-C
ontent-Type-Options: nosniff..Content-Type: image/gif..Server: Golfe2.
.Content-Length: 35..GIF89a.............,...........D..;..
GET /top100.jcn?2768890 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.rambler.ru
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.4.7
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NON ADM DEV TAI PSA PSD IVA OUR IND UNI COM NAV INT"
Set-Cookie: ruid= iAgBudi3VYzBQAAAbjm3g==; path=/; domain=.rambler.ru; expires=Thu, 05-Mar-26 11:15:51 GMT
Set-Cookie: top100rb=NDQ4KzQ4OSs0OTE=; path=/; domain=.rambler.ru; expires=Mon, 14 Mar 2016 11:15:51 GMTe1e..(function(window){var f=!0,i=!1,j,k=this;Math.floor(2147483648*Ma
th.random()).toString(36);function l(a,b){this.width=a;this.height=b}l
.prototype.toString=function(){return this.width "x" this.height};var
aa=/^[a-zA-Z0-9\-_.!~*'()]*$/;function m(a){a="" a;return!aa.test(a)?e
ncodeURIComponent(a):a};function o(){this.e={};this.i=[]}j=o.prototype
;j.a=0;j.j=function(){return this.a};j.c=function(a){return Object.pro
totype.hasOwnProperty.call(this.e,a)};j.set=function(a,b){Object.proto
type.hasOwnProperty.call(this.e,a)||(this.a ,this.i.push(a));this.e[a
]=b};j.get=function(a,b){return Object.prototype.hasOwnProperty.call(t
his.e,a)?this.e[a]:b};j.h=function(){return this.i.concat()};j.d=funct
ion(){for(var a=[],b=0;b<this.i.length;b )a.push(this.e[this.i[b]]
);return a};var p=Array.prototype;function q(a){return p.concat.apply(
p,arguments)};function r(a){this.b=new o;this.q=!!a}j=r.prototype;j.a=
0;j.j=function(){return this.a};j.c=function(a){a=s(this,a);return thi
s.b.c(a)};j.h=function(){for(var a=this.b.d(),b=this.b.h(),c=[],e=0;e&
lt;b.length;e )for(var g=a[e],d=0;d<g.length;d )c.push(b[e]);retu
rn c};j.d=function(a){var b=[];if(a)this.c(a)&&(b=q(b,this.b.get(s(thi
s,a))));else for(var a=this.b.d(),c=0;c<a.length;c )b=q(b,a[c]);re
turn b};.j.set=function(a,b){a=s(this,a);this.c(a)&&(this.a-=this.b.ge
t(a).length);this.b.set(a,[b]);this.a ;return this};j.get=function(a,
b){var c=a?this.d(a):[];return 0<c.length?c[0]:b};function s(a,b){v
ar c="" b;a.q&&(c=c.toLowerCase());return c}j.toString=function(){<<< skipped >>>
GET /top100.scn?2768890&rn=139404967&v=0.3i&bs=1256x677&ce=1&rf&en=utf-8&pt=404 Ñтраница не найдена&cd=32-bit&sr=1276x846&la=en-us&ja=1&acn=Mozilla&an=Microsoft Internet Explorer&pl=Win32&tz=-120&fv=11.6 r602&sv&le=0 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.rambler.ru
Connection: Keep-Alive
Cookie: ruid= iAgBudi3VYzBQAAAbjm3g==; top100rb=NDQ4KzQ4OSs0OTE=
HTTP/1.1 200 OK
Server: nginx/1.4.7
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: image/gif
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NON ADM DEV TAI PSA PSD IVA OUR IND UNI COM NAV INT"
Set-Cookie: top100rb=NDQ4KzQ4OSs0OTE=; path=/; domain=.rambler.ru; expires=Mon, 14 Mar 2016 11:15:51 GMT890..GIF87aX......4j..r...\.............f....\.$......\....4..........
..$.d...........ld..,.l...$~d$zlt.<......<v..r......l..|$.....,.
.......D........t..<...........|.T.........<r...l..L.......n.l.&
lt;D..$..D..........\4.|D~..z....<..l.....<n..z...l....j.\.$....
....L...........l......4..t.<...Dz..v.......4.................L..T.
$..l...|..4n..v...d..,.................,..................|..4.|...t.L
...<z.......\........d.....L.$.........,.....D..|.d..TL............
................d....j.\.,.v..........................................
......................................................................
......................................................................
......................................................................
...........................................,....X.......'..H.`. ......
!C8..X.8Q"...3V..................L.H..-.a..Is.M.8k....&..@."I..B...`.y
.TK..L.:..u...X]X..U .I'......S.~..=.6m..n.....J..x..p../..~....x.....
n....Q1y.....C..~,g...3...Cw^.8([email protected].:t.#[6...o..4..n..c..=....
...zc.P..4(H.!fL.<~h........;..........w...x..6..`$_..A.O'J$..$...r
[email protected]...%.]..~..W`.2L2F.Z ......A.~le
...L...........^..X...7..c.7bH...l...>d..........x.O....Ay...A....\
..!.K.ev.$P^.a.Vf...$.$.~....$..."....Z%[email protected].(.TI"..qc.
.....Vb.%..\....).(...X'[email protected]....^...=.q#... ...2...;l...j...
k......Q...>".c..J..$. Z...uj....r...P..AO......r..|^.'.`xE..Z zI..
.&......... P..M....g0...M{.....D...,. e......J...Gh.b.`....i.n...<<< skipped >>>
GET /ajax/libs/jquery/2.1.1/jquery.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ajax.googleapis.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Type: text/javascript; charset=UTF-8
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
Date: Tue, 01 Mar 2016 13:51:38 GMT
Expires: Wed, 01 Mar 2017 13:51:38 GMT
Last-Modified: Fri, 16 Oct 2015 18:27:31 GMT
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 29497
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=31536000, stale-while-revalidate=2592000
Age: 509053............{..../....CD.....);.;.1..d.N$.........$f.....y.|.[...F..%.
.{.:q4......z............w...n.l......^.....?3._...Y. VKu..2.R..[...6.
.y...m~....Z..e.r~....[%.y...h.~..&g.Uv7..../...z..m...(.f..n./w..jn..
.l(x,&~.,..f....2.?.j.Ym|O.b.....|{............./.`..ww......B..{4.|R,
..k....C..w.b..#..o..h4VY.v..!..U.Z..NM.r}...)]P...w.5.....f....nS,...
nf........:.......;........eT....&b..,..b.o.j.].2..^......../z...v..b.
.T.|.=.P....?.........P.......k...x...a...ew.Y.V...Q '\(...ns..V.p...&
lt;.K.S.|9........l...j...n...>...3.w..0C...[Q<.].C.....t..q(..a
.2...]..T...&4.E...\.....T\B..7....x........[s.....t.6.[...%%....M..*m
.}.b...0.....e.....T/.g...*...z=..{..2.mQ...lw.*.o......,r..2.m..; ...
.w|,g...|...^F.v;.L.#^.t<.GcT..N....~....#...Dm.%....Gm.<ut...E.
...v".q..i.C.....T.&...D.z...v.,.........V.0.:KV.y./K.9m...hZ.l. .t.u.
[email protected].. @..... H..(....3mEQ.....A
....b)s.gh8...7:=......i....v.2..)V2.....-...Gf..k.d.4|.*.............
..t....C}lx...y..f.../. .n..<Ns....aI..T..!...a..r.:.8..Ht...j.v..P
.]..M..G..48.#W..&..f...Or2....vL5.]9.P....."m..U.A.....x.._.W1.'..6|.
,ES.5......qw....t .)..W.V?..=.n...oU............U..g_-....=c.2p@W....
._..S.H.7.;.....x.w..<..F..D@..|......U...z...{J./....3.)..B.2.}^GM
E..B..MOA..NJ.y7.....j.c...6..kzI...H..wg.........y.'A.....K.D..X....
L.m..4^.s..M3..].V...^[email protected].~..xO.g...x..7...<.>i8Oq.a...
F=.(.A..hK...RK.........2....2._..x...&Bk.!. .).9.s.k|...../N.%...s...
....28...P.!`[email protected]..~4......5b&X...)U...[w[......HR.<<< skipped >>>
GET /hit?t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.yadro.ru
Connection: Keep-Alive
HTTP/1.1 302 Moved Temporarily
Date: Mon, 07 Mar 2016 11:15:51 GMT
Server: 0W/0.8c
Content-Type: text/html
Location: hXXp://counter.yadro.ru/hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165
Content-Length: 32
Expires: Sat, 07 Mar 2015 21:00:00 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="UNI"
Set-Cookie: FTID=1MtMBd3GLR5R1MtMBd; path=/; expires=Mon, 06 Mar 2017 21:00:00 GMT; domain=.yadro.ru<html><body>Moved</body></html>.....
GET /hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.yadro.ru
Connection: Keep-Alive
Cookie: FTID=1MtMBd3GLR5R1MtMBd
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Server: 0W/0.8c
Connection: Close
Content-Type: image/gif
Content-Length: 132
Expires: Sat, 07 Mar 2015 21:00:00 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="UNI"
Set-Cookie: VID=1sHqLj37UGbR1MtMBd; path=/; expires=Mon, 06 Mar 2017 21:00:00 GMT; domain=.yadro.ruGIF87a.......k.....,..........c......c...........(..'..4.......h...B.;
.;...`..*RN.....=...t.t.......2.0(.#&..f.........io.......P..;..
GET /js/api/openapi.js?115 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vk.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: application/x-javascript
Last-Modified: Fri, 13 Nov 2015 15:33:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
ETag: W/"564602cc-112d3"
Expires: Fri, 11 Mar 2016 11:15:50 GMT
Cache-Control: max-age=345600
Content-Encoding: gzip52ce.............}k{.G...........H..Y..[...c....Q.z(.e..H..,;...~..(..
.)...........B.P(..BU....'..hX.jd.....YV.j......=kd.|v9..~./.z...7<
...i..}...^.......z.x{pho.......J...S.&.... CA..o....k-.....jD...$....
........F..K{.....u...u.5.m..z...z.5...M..7..FC.hKX.._."O.U.?.q4....6.
.d4n..f6..g.,;.].gF!9......KE.....Ou.r.~...4...-..m....{.V.....n.i....
={...G......D\7.....NC..&7..QU.@o6....:......d`......0..bh....."..Z'..
7...r>.kS.[s.g.Lk.i...g.........5.x...... -........8..<.X.c....j
...O5.R.uk..h`.7...;}..u..O...^{....Z..}................q..\...._z....
.2of'..74*.W...yV' Fg.f..o.....6.a....t..ca[27\.Gk...........\X.].wk..
...............}.9J.......m`.>..R...$%......E.B>,$.A.........n..
-...........Of.N>..-...........O.. ...!.?..>..BO...._...T....Qb.
.}|j...].K.|.fv.7.l.=.bl..C...E2.W&F..1.....<.....(gJhD..w}..R.9>
;....../.....S..7..d.k....r....w......6.:..z..Y.....W....^......F.f...
)....M..[..;...S;`.##`.Z.X....r.*td.... .M7.......rz^?P[cX|!.6"..il.So
..5....2..........]A..0........u....s..m...F.....,...N..[.z.^.@.].6..H
..(...Yo..ak..Ls.......P......y..{.....h.q_[1_(.U..1...C.#6!..0...?]^
.."t<Xa|H~.P...G....M......i.........X..g...?.m]....3Xc!....,.S....
a".DT(`c..8....,.1...5..E&.....n..i. 'u........Cb..5.".....}.H.!g...U.
x2.'Xs..N.\.j..vW...jY..]......46|.....l..M8.Z.54....z.....gj.0......,
...........F;Y.>......s2.db..g..t.f....~g;..o......Z'..............
8]....Z.W..C>.........?...f.D!....?5..zW..].<.....7....-.0....P.
..D....H..t..!.'...w.a..]..,[email protected]..:... ...QS#.E_.}9<<< skipped >>>
GET /js/api/xdmHelper.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vk.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Last-Modified: Mon, 20 Jul 2015 23:21:19 GMT
Transfer-Encoding: chunked
Connection: keep-alive
ETag: W/"55ad826f-2c65"
Expires: Fri, 11 Mar 2016 11:15:51 GMT
Cache-Control: max-age=345600
Content-Encoding: gzipe96.............Zkw....._.a..4I.r..e .cK......$-....B...,.$u$....'....
4........;..]`8dGoOX..<-8.....YY.....,.g.....p..q.U.9..._...9.N.l:.
..m.8x......7......]u.....3;......se3cK?g.....xR....~..OG...<..g.hR
.<.....L.G.Q.n\..h..[..H<<%.G..x.xD....p.N.g}.#.....?M...2.L.
4.z'...E.y....>g..*..!OK.<...=/I....B.,b..........e\V.|a&I..d...
?.V..(eG.....t.#...FG.;.vG.ab.N.c2....u...9_.x :..Dn.=G.p..s.dqZ.3....
.._r....'Y..X....O.....S...lg...3rX...,}!H.[c...J..e..gvp.;^.q..X..#).
15..*yQ.!.f.....1)....?......q};:..~"|0.9..?...N.Ey...)loo.9r(.S..nM..
.7.H%..x.;.#'{...U...^...4.....WP.p...........G.OUv7.....[.Y.....h..O2
J...q..._X ..qq..1.T...[.I..Gn...Hc...9..'...$...s."F..0.:...%........
v..n%.y.....'.I.1..BS.x.6..8..H....c.dih..Ma.b..t.[...p.....S..J.}.!..
m4..g].a......\.~...$......./.....'3..,[. ...r...}.I:.4E..u..VB.bu...g
..&/....p.FRgl..e.'[email protected]..._..T. z..l.....Z...!B..cA...8...Z
..1&........J..).Ln..*/....3...}9.I.Fz...`fF.:Ye..u.N]6....)Z...$K*|..
`1.C...TNS.X.(V.....s#O....!..[r..,[email protected]
......bU't._,...p]i......s....>..t{.C..*A$Q.37.......*..Ck...z.....
q|...yD.....X.$._..jZ.O...~.....O.K..........;.gK%.....).S.....&..-..,
......P7*.1.......&..$V}.....ei[k...Q..da.X.c...=x.BAi%...k.sh.Y.mSN#.
..V..u.a..b1....&.-o..V\T......Pv.# ..`.../M......e...}.f<A........
...........U.!..<//d..a.4....w.H.J.......%p.O..........T..4a.......
..G..s.5......E.hGX;...T..Nm..'..qt.[.}....T..}V,p..ET2m-..^2.....h[[.
.H.Aj.....YAO...l.FC..jJ4....7. ah-.f.rl3.Z....R.....r.hm&2..E....<<< skipped >>>
GET /downloads/752_55394.ppt HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Server: nginx
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.28
Set-Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04; expires=Wed, 07-Mar-2018 11:15:50 GMT; path=/
Content-Encoding: gzipe55..............mo...{~.. &..I.vj....M1.H..h?..a...x6.cxG.r..M.bC.vm.
.........4^..M.....<G..5r..HD.......K..z....}.5.....P...iX .qb`....
......(q<.K..F..............i....~.u......Q.........k=l..].N....i..
F..F$be.G......]..]V..3.C... N}S:.g....O.......Z6<.".i...H.&D.g.#..
X..~qu.~.^Z[........Ab...(..\z,6.=.U.....$.p.. ....<.5f..i[.;"...N.
..8....c,.A..L$|.U..H......(ej.....C.....J..F.....tM.`R..^[email protected]
&..G*..b....u...D...Q?.8..M#n...p...eP..]...`vvjw..p.....:q|*e....s.3.
..!....p. ..#........ ...?d....1..zG..f....od`...Ci..yQ.L......EM..xPK
.;v.6Fi.X .k..>8R......p.'...oI.'....#.Jl..}.........}.......Z:FJ6.
i...u..J<..,..M.^......&...8 .q<..R.k&.Q\..|n..a....."...._.a.t.
&C...n....L.i.h...I..A..O..A".:..>.6h. .....c5....,#..7.....p.%5.J%
Q..^F.1 .M..x..].....V3.1].....'n..|.`.w.%..G...D...1.yj.}.|{.o...18..
[email protected]...)zR..P.......c...9.<v.<..O....P..??`.....%3.Bq...3
.....]$|h...a.,..*......K.[Xb.s.......tvJv....1.O...j......LH.`..... .
.T..BZ._....}I.....o..u.vc........REM%j5.....h~...........0......dv.i.
..A ..~.e"..3...qB....<.A_~.(...=.Z..c.g&.A-..-.|......... y..o}..X
........g.........8_..,B<.........!...........4- .......V.......T..
...^.b.KC.........S...].=..>>c.....2..MXS|...!=A.M....7 ...E4.;.
....$gx...3....K..2.wm.'.g.....d....T.XO.~<kbE..[...!..............
|....u.~..`..y. .=..3?..O....89.h3AF...x|.&.o....._0.O....:..w.<D..
5...;.=m....u.<c'.................F.H].....y..U|.Q..s......../...y.
b....(.......d............g..~?..#7 ....."..:E..V.....*.........~.<<< skipped >>>
GET /style.css HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/css
Last-Modified: Wed, 25 Nov 2015 11:42:28 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Tue, 07 Mar 2017 11:15:50 GMT
Cache-Control: max-age=31536000
Content-Encoding: gzip5858..............m....0.....`...3>...w.*...s_Rus.l><...E...1
%*"u^..._...h.....n..$...h4..t..h...w.|....KU5usNO...(.%..}...........
m.....Su.|...M4..d..5....h..<..|........X.Yt9f.9....*...o../...}.qS
.7.......!.......?......*.}....|....E..|H....h[[email protected]`Y.}
s(.....w..(??...........z....a.`.i..K.<&q..z.1..R4t.mSe.....\...[zn
.m......A.7iQ..]..MOMQ....s>...2N..4..y>W.......1.0...../....5 .
S.~~d...rK/YQ....CZ.N........k.2...,..PTX..9Ui9d|x>>n.:......j..
.eL9We...Aq...z..1f..q_dY~.i...V....-.n../....1..#.S.........p...o..h.
9...M..t.Tg....j.....>E..5.n......,...$c...lw....s.?......O.G6<.
...V#2./..#....$....^o..:?~.3.5....X.../....|]..[..j..OU]..z<..)..A
fsLMuz..f.....N.Gc..8< n0......<...<\9.we..Q..M......p..>.
....P..q....8>?.q.....:......4-....m &..l2&e..N.'g...cU..m>0..-.
.U.....8(..K3.N..s..&..>..s.^.0..=....`.0.Jb..}(.bS.....*f([B....z)
...O.H..c....^~.i.>.i.7..6J.....W..t.S.~.?.....\3.OU..zV....F...~..
..WU).w..lT..G1v.j{.......Q..n.d}J...g|..W(.r....l....6.n.S...yhd.L.O.
..q..6..'F... jX.....x......U.,$.2..z.'...yW.e.n.w]...@P`i...[NDIt6T!.
..9.....!..;L........"...dRo.B4>...M.....c..._G..9?f.....Nr=/......
Wh6I..T.....*..^.....j...!..4:..... 'g.O3.0......:7....1..Vk1.O..c....
R.n).:|.`.D6k..QX"R...?............7..7Q.4....!z...j. .(V......7.O....
...T5....7..7|.......3.|a.v.Z.!}f..../l.qC.1.P........b........5lMaj&T
....O..E...u.xz......Z.O{6...5..>._n..`..RH......@<b..&=...HP.1.
.........h...F[&&.`........iIfJxH..mT...$x...Q.l.h$.%$3}.......dY.<<< skipped >>>
GET /fonts/glyphicons-halflings-regular.eot? HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/vnd.ms-fontobject
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Mon, 13 Oct 2014 19:07:31 GMT
ETag: "12840296-4f6f-505529c4862c0"
Content-Encoding: gzip400a.............{[email protected]...]........Cp.. .....n.V.}....o.
...y...qQ...............[...(.?LQ..?.........s........z.U.,@. .P.(.4..
.....`......6...\t.:.._...j.p......!..F....x ......O....|....[.......X
......`......N.<;......?.?.....z\.Ux...,...y..W.......k..?;.....py.
...L........:...n._|(....Y28.sw....vK..w.S9...R...J..c..g..6 :........
...j....L*...._,cm.....rf..HZ.G.!.....=.n=&..`.W*.T|......[...D$...cv.
:1u............ ..FJ...{8`.=:. ...Q.(...-......4..}..1C*...p....._..{.
_..p,<.7.(.d?t.I-....S...bWr..T.....2{..I..~..m.CY...A7y...W.o2..QR
..F......:,.)5..T...{.....C&...$...*L....f.....CS0ne..\8..m].A/4z.....
..".y.-..{d.....Em{-_{.>.b...e.V.'V.c&rw...<..!.9:.......H.....b
......^y....^....R}%....g........!..N.....!.].o...\6ci.-...3.<=..&g
t;.N..>...cZU...f..z&..XqE..1.z.`....H.s.^W.`......E.TE......yoa..[
....~..!....yH.TR......h}s.1{.[.nu& v....z..*)?:.....`n.ciC..;.6T.?...
.pEI.r.]:.3..^.....,N ........f].i..G..O(.).......-...>.cY...[S..?.
o.LI1PG'...L...QL....o.0E......Q.j....=...A.`.y1....V.*.!....x.H...#"_
..O$`[email protected]}7..G..0.....W....#...|.>K.&.Ky.&....._..~..2.!.GN
...........m.Vt.,Y.`B........J..".Y.l..^1....V.....*..0*....P.5."8P?#.
........h..O..!............S.O.P66(.j..)..p.QD..%Q3p.p'..~...b...>n
...W....(D&....=..C....l!..S......?...H..@.*.v;..%.......v.mP..?......
8.m}...c..56S......rA.b.eH......H....]6.....Fw. ....>._...r.Y3...7S
.O..<.'...7...l0.R*......W.x%QQ.5HQ......'.p.`*^.kD.......}.E."Q...
p...q...m.Fs..?%Y4....v1g.4..d.....Q.....?...3.....5S.E.T. t^.,u8d<<< skipped >>>
GET /msdownload/update/v3/static/trustedr/en/authrootseq.txt HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: VVV.download.windowsupdate.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: text/plain
Last-Modified: Thu, 28 Jan 2016 17:51:53 GMT
Accept-Ranges: bytes
ETag: "80823092f459d11:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 18
Date: Mon, 07 Mar 2016 11:15:52 GMT
Connection: keep-alive
X-CCC: UA
X-CID: 21401D159F4929680B9....
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: VVV.download.windowsupdate.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: application/octet-stream
Last-Modified: Thu, 28 Jan 2016 18:43:43 GMT
Accept-Ranges: bytes
ETag: "80d9e4cffb59d11:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 49661
Date: Mon, 07 Mar 2016 11:15:52 GMT
Connection: keep-alive
X-CCC: UA
X-CID: 2MSCF............,...................I.......d.........<H.T .authroo
t.stl. ..-.8..CK...<Tk........./.........Z..e..P..D.&.BRTH...E..E.b
.["$qS)....-...[..}.o~g...q...Y...n...........aF\!.lI.4..0..ef.W.....C
`....Y..F.D5...Y.A....1.|..c.1...Nc.Y..x..D...NP[[email protected].....'.B.
......"(~3z-.@~..|}(.......g4.p.........h.n.dQz..t.V.......;.....Q...d
/../.pJ...6....E...A.@..]..T9..28..,..p...).....P:}.K...]=.7X.f..9..yB
.P....uP$$...Q.u..y..".=......7...........#.X..P.8....>U....v.[.$.e
...H.@~..........ea`.3...tLX...].-....<.........v.....M../..z6.t^..
...p....M...v(CP%F.......!eX..a...-..G.....S%..l.....Y..(.*.-....C.L0.
..G.....).rm8...(7.T{.Q...."...B`H.....3..9..-..Vv.5Q.e.W.../...RY.v.P
. .........l......8'.&z......3.;:...U4.."....yu... .."....d .e/7.;.XD*
tn%$.........];..fY.R...7.....o.=xh...]..4...\.:...v....t..9 .nO.i}.T.
./(uke..p.&.6.E#[email protected]...*.s....h......(/.s.%.3g...:*X.].7.IE....
E,.w.8......v...r4.qOh}~..E.5t...l...(*..2....`..F..".a:.t....9...W.kO
?5..=..HhYrI.Sf..[:...3..2..)DB...;......(...B.......U(...._F./#.k@...
.9c.Y..G'..]...p..;M_o..~.3?.}.1M.5.f5)._......t _.6...l..K....OsY.0..
....H...^..\$P;U....8..)...1........J...uE..#n.......h.......17.P=,P..
...}z.&..../..a.........p@.|KB..o.E..|..o.mr......m=.(v.:[email protected]
>4y....P........F...&... ....r$d..{B...)..A.`..x4E'~`V.."..(..(./G.
..@_Q`.....O...~`..~...x..KN~....Dko/A{..!...W..G,`)...*...#......q`..
H.........%m..G....5..4.....?.......F...{.%..2....l.L....."...Y.......
. ...].\........... D..Y...!1..*.....M?..G..A.|Ex......~...s.!.=..<<< skipped >>>
GET /font-awesome/4.1.0/css/font-awesome.min.css HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: maxcdn.bootstrapcdn.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/css
Content-Length: 20766
Connection: keep-alive
Last-Modified: Wed, 14 May 2014 20:41:32 GMT
ETag: "bbfef9385083d307ad2692c0cf99f611"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:50 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman [email protected] or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes/*!. * Font Awesome 4.1.0 by @davegandy - hXXp://fontawesome.io - @fo
ntawesome. * License - hXXp://fontawesome.io/license (Font: SIL OFL 1
.1, CSS: MIT License). */@font-face{font-family:'FontAwesome';src:url(
'../fonts/fontawesome-webfont.eot?v=4.1.0');src:url('../fonts/fontawes
ome-webfont.eot?#iefix&v=4.1.0') format('embedded-opentype'),url('../f
onts/fontawesome-webfont.woff?v=4.1.0') format('woff'),url('../fonts/f
ontawesome-webfont.ttf?v=4.1.0') format('truetype'),url('../fonts/font
awesome-webfont.svg?v=4.1.0#fontawesomeregular') format('svg');font-we
ight:normal;font-style:normal}.fa{display:inline-block;font-family:Fon
tAwesome;font-style:normal;font-weight:normal;line-height:1;-webkit-fo
nt-smoothing:antialiased;-moz-osx-font-smoothing:grayscale}.fa-lg{font
-size:1.33333333em;line-height:.75em;vertical-align:-15%}.fa-2x{font-s
ize:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em
}.fa-fw{width:1.28571429em;text-align:center}.fa-ul{padding-left:0;mar
gin-left:2.14285714em;list-style-type:none}.fa-ul>li{position:relat
ive}.fa-li{position:absolute;left:-2.14285714em;width:2.14285714em;top
:.14285714em;text-align:center}.fa-li.fa-lg{left:-1.85714286em}.fa-bor
der{padding:.2em .25em .15em;border:solid .08em #eee;border-radius:.1e
m}.pull-right{float:right}.pull-left{float:left}.fa.pull-left{margin-r
ight:.3em}.fa.pull-right{margin-left:.3em}.fa-spin{-webkit-animation:s
pin 2s infinite linear;-moz-animation:spin 2s infinite linear;-o-anima
tion:spin 2s infinite linear;animation:spin 2s infinite linear}@-m<<< skipped >>>
GET /font-awesome/4.1.0/fonts/fontawesome-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: maxcdn.bootstrapcdn.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/vnd.ms-fontobject
Content-Length: 72449
Connection: keep-alive
Last-Modified: Wed, 14 May 2014 20:41:33 GMT
ETag: "90186830c9c50a0fed932494581761d9"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:51 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman [email protected] or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes..................................LP........................!H........
..............F.o.n.t.A.w.e.s.o.m.e.....R.e.g.u.l.a.r...$.V.e.r.s.i.o.
n. .4...1...0. .2.0.1.3...&.F.o.n.t.A.w.e.s.o.m.e. .R.e.g.u.l.a.r.....
BSGP..................X.........B.....`.g.iSyR..&U:.47.4......mj...1..
....I.PJQ......X*i.Y.!G.....0.*.-.a.....Xn..$.X...2......RL....RD.....
.p...f..."..p.vU;..k..2.6IQ.}-T.y..I....z....E'....T.....`.D....].Y...
G......&.E.7e..%...:[email protected].)lI....FW.'&...
..X#............J.G.~.........e.0.sZ.. <.. ...p]..e...C.....h......
.[.....e}j.I.pr..n..#A".P...'!A..~B........mtv-.,....)2..YQI....o.....
.YA@&&....<c.(?........!....B.\K$.D........Ke.4p. S........>.P..
z..T...#............[[email protected]'.<..OY.....
.pB:..x..p.....)..A.gd.P....t.....6...P..{.b....Z..l......ka.tV..Y.Q2U
.,...l.'k.uW...A......}....~.m!.x..=&.%...V#....|;L.......[...".k.eT.B
..}....r|...O......}.4...=bC. .L..... .d......O.2E......G....8..%...!.
'H6..0..t...rO!Q..y.E..DP!..O....,..4....3...\...S$..............%$...
a...........;...df#DwFC..6b.f1...Y.F:CE......../.<.`...v..^...-..&g
t;......q$.........&...5s4.0.9...v.....!.WQ.J..n...L..8;q.O....w..m...
.....1>.1..e?...,I.c^e.D.-SP.....5......`."a....U.........a..>..
\.....t'..|.3.1HZ1....8..4...1.*[email protected]..[]..!9..U`......`.T.?....
.X#......W.........vz.uK9.5]"X.u...oR\[email protected]...
........x ...... ...n...........:{.M..?..*.=..:.z..x}z..p........._.`S
.G..%")v..f....F.Y._.u...*AG...4\[email protected].._.5Al.t.o....{L..._!.8.n.<<< skipped >>>
GET /share/share.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: yandex.st
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.8.1
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Tue, 26 Jan 2016 15:03:14 GMT
ETag: W/"56a78ab2-d3bd"
Expires: Thu, 10 Mar 2016 11:13:29 GMT
Cache-Control: max-age=259200
Cache-Control: public
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
Content-Encoding: gzip3580.............}k...q.w....<....y.,.....o......;[email protected].;
..u.rHa.z.%Y2-Q...C$-R........Y...._....Pxv...2.....BUVVfVVVVV........
...*..[..M..7..........N..w.].1Oj...[..,._.>~....n.%...o(.*I..b.Y..
g.9DW..fh..l6......G.t...../A?P....K5....9.....O.........S..}-nBX.....
yS.-..B.J*.D...j...d.X.c.......5k_.e........e....M..M'|...J..v&....R..
5....m.?0.^.......s...%].{J.h.*......lh.... .....r...M.7...Ms.......H.
&...aOL}.#....A.z.|.3.........M..d0..B[.0.Y.M=.L(.-.......0.SVz.'.[..9
8.Be.... .<>i...V.<5.Pn:m..g...,m~........s......>-.....M.
.[\t..e(.>.l......ZTZ...wv9[...{.....tvQ.U..$t1.-.f.c.[@8.oN ...pBQ
]}.9h.c.j.s...8....i.rF...i_Y.......<7..v.1.\{....k....v.;.....3.@.
.....x.5.d.j...........N......o......g......Z:mo..8. &.B.......Qq.. ..
.7.F#...i.:.\?4..,Pc.*..;.R}.`.j.$t.D^a&.6.....V`.,...4.E.-..z.9..1..?
.;.9'n....... ....vd.,.f.v.pF5.7.M.<...W..........'.y...jc.gg......
....=.. . .....{....$....-Y..bm.H....p...5....0l......R..F......y ...
m3'z....#D.dKk..P;0..............,.q.<yB...(c'.:.Q.....G.-.2l50....
......Vg=%U...4....(J..C.%...0....i...C.'...:f^\.......'~...s-'4..L...
.=D.<-V.,Z.z../\.t.Vo......Q..O.w"%....U...|s..41Wf.:..5G0.[..X.^SK
.A...RDu..9G..l...=..&.9.....{c..]g..Y.....^.#..r..<......H.1..<
....?/...W......c..Y`}ns._.....3.........>WK.;.U..K..... <..\.D.
....,P....o0."[email protected].... ."....V..S......D..>....f=5I.d..(.&.....
..Z...zb.....VL..T`.p.."Y&!.Z.`.|B.E.p .k.....i......c(.2....2O=.N...s
T82,'[A.........4.g...0.e...<y,sp.P_.L.|.y....>..{e.......Hk<<< skipped >>>
GET /images/logo.png HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: image/png
Content-Length: 1928
Last-Modified: Mon, 13 Oct 2014 18:58:38 GMT
Connection: keep-alive
Expires: Tue, 07 Mar 2017 11:15:51 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes.PNG........IHDR..............qr0...(PLTE.............................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..................................feB....tRNS.........................
..... !"%&'()* ,-./013679;=?@@ACDEFHIKLNPQSWX\]_`abcdeimoppqrswxy{|~.
......................................................................
..................wg....YIDATX......5..3.Z...(j..... ..@9,rU..#.sA..E.
`9e)..5.e.*....li.@..{.%3..L......~.~.&3/..&....!.......Q#AP.b...JW.l.
.KO...-..it....I.g&l6..c.........a......)G..3.a....$.!..5./n.s.....|..
.r.N..F...tG.......o....w<.h..#O@[email protected][email protected].
...U.c..S..7....Xi..{.Nm..b ..c.1.D.8D.l.....0...2......._.``...;?o.&n
.uR9.D|Lk.(z.yZN>e".pD..8Y.?V&.....{:.p`.4.}M.0.2...1...[.....?.4..
.u4.#...6.$...vrz..i.r........... .a..K.....?Gc..6...B.s"....6..a&.aY.
K....b..9ac....p..F...S".S.t.F...b3.....8..wi.eA5.{.....L......0..`.*.
.8`..6(.wA...r. ..D....sH..]....!`.$Y.c.`.]-H. ....'.....-J. .v'.aT.?7
!....^.1......*.`...^...!..6...b...aXiW...w.".c5]..............U.T$x.R
6R!$"P<^...x.\T.RjB.`.CW1j{.(.M......v....$\....b8....6.<..c<<< skipped >>>
GET /bootstrap/3.1.1/js/bootstrap.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: netdna.bootstrapcdn.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:52 GMT
Content-Type: application/javascript
Content-Length: 29110
Connection: keep-alive
Last-Modified: Tue, 01 Dec 2015 17:30:27 GMT
ETag: "ba847811448ef90d98d272aeccef2a95"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:52 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman [email protected] or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes/*!. * Bootstrap v3.1.1 (hXXp://getbootstrap.com). * Copyright 2011-20
14 Twitter, Inc.. * Licensed under MIT (hXXps://github.com/twbs/bootst
rap/blob/master/LICENSE). */.if("undefined"==typeof jQuery)throw new E
rror("Bootstrap's JavaScript requires jQuery"); function(a){"use stric
t";function b(){var a=document.createElement("bootstrap"),b={WebkitTra
nsition:"webkitTransitionEnd",MozTransition:"transitionend",OTransitio
n:"oTransitionEnd otransitionend",transition:"transitionend"};for(var
c in b)if(void 0!==a.style[c])return{end:b[c]};return!1}a.fn.emulateTr
ansitionEnd=function(b){var c=!1,d=this;a(this).one(a.support.transiti
on.end,function(){c=!0});var e=function(){c||a(d).trigger(a.support.tr
ansition.end)};return setTimeout(e,b),this},a(function(){a.support.tra
nsition=b()})}(jQuery), function(a){"use strict";var b='[data-dismiss=
"alert"]',c=function(c){a(c).on("click",b,this.close)};c.prototype.clo
se=function(b){function c(){f.trigger("closed.bs.alert").remove()}var
d=a(this),e=d.attr("data-target");e||(e=d.attr("href"),e=e&&e.replace(
/.*(?=#[^\s]*$)/,""));var f=a(e);b&&b.preventDefault(),f.length||(f=d.
hasClass("alert")?d:d.parent()),f.trigger(b=a.Event("close.bs.alert"))
,b.isDefaultPrevented()||(f.removeClass("in"),a.support.transition&&f.
hasClass("fade")?f.one(a.support.transition.end,c).emulateTransitionEn
d(150):c())};var d=a.fn.alert;a.fn.alert=function(b){return this.each(
function(){var d=a(this),e=d.data("bs.alert");e||d.data("bs.alert",e=n
ew c(this)),"string"==typeof b&&e[b].call(d)})},a.fn.alert.Constru<<< skipped >>>
GET /metrika/watch.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: mc.yandex.ru
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx/1.8.0
Date: Mon, 07 Mar 2016 11:15:52 GMT
Content-Type: text/html
Content-Length: 184
Connection: keep-alive
Location: hXXps://mc.yandex.ru/metrika/watch.js<html>..<head><title>301 Moved Permanently</title
></head>..<body bgcolor="white">..<center><h1&
gt;301 Moved Permanently</h1></center>..<hr><cent
er>nginx/1.8.0</center>..</body>..</html>..HTTP/1
.1 301 Moved Permanently..Server: nginx/1.8.0..Date: Mon, 07 Mar 2016
11:15:52 GMT..Content-Type: text/html..Content-Length: 184..Connection
: keep-alive..Location: hXXps://mc.yandex.ru/metrika/watch.js..<htm
l>..<head><title>301 Moved Permanently</title><
;/head>..<body bgcolor="white">..<center><h1>301
Moved Permanently</h1></center>..<hr><center>n
ginx/1.8.0</center>..</body>..</html>....
The Trojan connects to the servers at the folowing location(s):
%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
msisetup.exe:592
msisetup.exe:1564
%original file name%.exe:348 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\BYBRWJVG\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3I2TUWDI\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TFZ1DZO2\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\B55C40TD\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (169540 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.