Trojan.Win32.IEDummy_20e36ad04f

by malwarelabrobot on March 8th, 2016 in Malware Descriptions.

HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.Win32.IEDummy.FD (Lavasoft MAS)
Behaviour: Trojan


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 20e36ad04ff6515d68b61362b2a06512
SHA1: 4f0152fe37f0d5dffa275d3d786b90c9582ac834
SHA256: 1c4994fb9ea24c0037e8d905211e66ab0a005631c39ff05cc43127c8c7f92886
SSDeep: 98304:BmRAsB9AM0rOOXF7rW12QyUf9axezFFoE1PK7BdUCAqNpDg8zA:Bm7B9AM0jXQmUfIezFfY/Ju8E
Size: 4868347 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2007-09-20 15:34:46
Analyzed on: WindowsXP SP3 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

msisetup.exe:592
msisetup.exe:1564
%original file name%.exe:348

The Trojan injects its code into the following process(es):
No processes have been created.

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process msisetup.exe:1564 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\BYBRWJVG\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3I2TUWDI\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TFZ1DZO2\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\B55C40TD\desktop.ini (67 bytes)

The process %original file name%.exe:348 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (169540 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\__tmp_rar_sfx_access_check_276359 (0 bytes)

Registry activity

The process msisetup.exe:592 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "57 C2 E6 CE AF AC 73 5A 48 55 74 E7 61 0A DD 3F"

The process msisetup.exe:1564 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryCount" = "16"

[HKLM\SOFTWARE\Microsoft\ESENT\Process\msisetup\DEBUG]
"Trace Level" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"ControlFlags" = "1"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
"LogSessionName" = "stdout"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"TypesSupported" = "7"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CB CA 54 A3 1E 27 84 CB 97 9B 4D AF 74 DA 5D 15"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Internet Explorer]
"iexplore.exe" = "Internet Explorer"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile" = "%System%\ESENT.dll"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\ESENT\Process\msisetup\DEBUG]
"Trace Level"

The process %original file name%.exe:348 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A7 7E D6 77 38 55 F4 D6 3C 61 DA E3 FF 1D F3 C3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\RarSFX0]
"msisetup.exe" = "msisetup"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Dropped PE files

MD5 File path
52801f1610d2b3121b1a374b49b68eb8 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\RarSFX0\msisetup.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

No information is available.

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 81920 79872 4.48153 8c499086717691066d921075ed5bdb09
.data 86016 28672 2560 3.40313 0cb811e47f78b5404a658fb36b591857
.idata 114688 4096 4096 3.55201 8bf175092a70a21f11fd06cc4087c7d0
.rsrc 118784 16822 16896 2.98979 e56287babd73f9c7a9cd2d4d38334457

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://presentaci.ru/downloads/752_55394.ppt 5.187.5.232
hxxp://presentaci.ru/style.css 5.187.5.232
hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/font-awesome/4.1.0/css/font-awesome.min.css
hxxp://vk.com/js/api/openapi.js?115 87.240.131.120
hxxp://presentaci.ru/fonts/glyphicons-halflings-regular.eot? 5.187.5.232
hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/font-awesome/4.1.0/fonts/fontawesome-webfont.eot?
hxxp://presentaci.ru/images/logo.png 5.187.5.232
hxxp://counter.yadro.ru/hit?t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 88.212.196.101
hxxp://counter.yadro.ru/hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 88.212.196.101
hxxp://counter.rambler.ru/top100.jcn?2768890 81.19.88.80
hxxp://counter.rambler.ru/top100.scn?2768890&rn=139404967&v=0.3i&bs=1256x677&ce=1&rf&en=utf-8&pt=404 страница не найдена&cd=32-bit&sr=1276x846&la=en-us&ja=1&acn=Mozilla&an=Microsoft Internet Explorer&pl=Win32&tz=-120&fv=11.6 r602&sv&le=0 81.19.88.80
hxxp://vk.com/js/api/xdmHelper.js 87.240.131.120
hxxp://googleapis.l.google.com/ajax/libs/jquery/2.1.1/jquery.min.js
hxxp://cdnjs.cloudflare.com/ajax/libs/jquery-cookie/1.4.1/jquery.cookie.min.js 198.41.215.66
hxxp://yandex.st/share/share.js 178.154.131.217
hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/bootstrap/3.1.1/js/bootstrap.min.js
hxxp://plus.l.google.com/analytics.js
hxxp://mc.yandex.ru/metrika/watch.js 87.250.250.119
hxxp://plus.l.google.com/r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 страница не найдена&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947
hxxp://a767.dspw65.akamai.net/msdownload/update/v3/static/trustedr/en/authrootseq.txt
hxxp://a767.dspw65.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab
hxxp://netdna.bootstrapcdn.com/bootstrap/3.1.1/js/bootstrap.min.js 108.161.188.218
hxxp://www.google-analytics.com/r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 страница не найдена&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947 216.58.214.238
hxxp://ajax.googleapis.com/ajax/libs/jquery/2.1.1/jquery.min.js 216.58.209.202
hxxp://maxcdn.bootstrapcdn.com/font-awesome/4.1.0/css/font-awesome.min.css 108.161.188.218
hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt 77.222.148.97
hxxp://maxcdn.bootstrapcdn.com/font-awesome/4.1.0/fonts/fontawesome-webfont.eot? 108.161.188.218
hxxp://www.google-analytics.com/analytics.js 216.58.214.238
hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab 77.222.148.97
apis.google.com 216.58.214.238


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

GET /ajax/libs/jquery-cookie/1.4.1/jquery.cookie.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdnjs.cloudflare.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/javascript; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Mon, 28 Apr 2014 23:00:06 GMT
Expires: Sat, 25 Feb 2017 11:15:51 GMT
Cache-Control: public, max-age=30672000
Access-Control-Allow-Origin: *
Content-Encoding: gzip
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 27fda1c8f33302db-AMS
22f............}[email protected].=...1AJ.....T.Z...$'.....`...B....c..FQO..7.
f......X..n.....o3......~~.....z.Z'N.M%...!B.m.&.R...~....H...c.v&S.Y@
[email protected]{s...H..........(.....>A.w )
...^@b:........_~...3.m."x<8h]@....!..t....."W....CU...#~3b..2...'.
2....26.`.`....mGG........./[email protected]..(.....I_U..c$,
Jh...n.31.....gku$Ng.>...TF7F..mO.Y.............N..F.($..].xN......
...D.T-..8...l../.W. \...'U..,..?.........&Y.....8..o..S$.O.".z]g28.}g
....:@..D......{.m.6..B*.$[..n....dm.)h-....0JSBPe..f.\@..5.}.........
\9.]...S..-7...8a...s.37.......]g)...v.A._...~5W..., .#!L.x<....}.v
....3........%.Yj..c.=........ux>..q.1.f..o.tP..t.......F.=...z....
.G.nF5......f._..>.......0..HTTP/1.1 200 OK..Date: Mon, 07 Mar 2016
11:15:51 GMT..Content-Type: application/javascript; charset=utf-8..Tr
ansfer-Encoding: chunked..Connection: keep-alive..Last-Modified: Mon,
28 Apr 2014 23:00:06 GMT..Expires: Sat, 25 Feb 2017 11:15:51 GMT..Cach
e-Control: public, max-age=30672000..Access-Control-Allow-Origin: *..C
ontent-Encoding: gzip..CF-Cache-Status: HIT..Server: cloudflare-nginx.
.CF-RAY: 27fda1c8f33302db-AMS..22f............}[email protected].=...1AJ.....T
.Z...$'.....`...B....c..FQO..7.f......X..n.....o3......~~.....z.Z'N.M%
[email protected][email protected]
{s...H..........(.....>A.w )...^@b:........_~...3.m."x<8h]@....!
..t....."W....CU...#~3b..2...'.2....26.`.`....mGG........./[email protected].
..lW..g4...m..R..(.....I_U..c$,Jh...n.31.....gku$Ng.>...TF7F..m

<<< skipped >>>

GET /analytics.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.google-analytics.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 09:40:24 GMT
Expires: Mon, 07 Mar 2016 11:40:24 GMT
Last-Modified: Thu, 04 Feb 2016 00:31:28 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 10938
Age: 5728
Cache-Control: public, max-age=7200
...........}.s...... .\.j&....r.s(gw.-^...Ii$.&.@f./1|...nI......U.Su.
..K....W..H.....oy.dU...{.i?J...O...Y{U..x.........)...A.1WT..H.....(v
.;.t/Y.4...........a......j...=......j.............kcc..^...f.l.z.....
.v>~...?8.|t|r.....s....z.....f8....tr{w....\..|......~8...x;u.....
.c.N......EC.q...?.......P.."..\.|.....\..a.}YX8.......FB9.-.F..9%.K&.
;[email protected]=..0.~..d...zL...X.l..,R......N!.~..\.\.yf.\...|.......
5..t....k..E.R5..X....%. (........J.O...?\B.....X::N.h.....\...8c.....
v..'.J.......}1.&i<..(.....P... ...:8..m3M5.X.[<.r...y.....8lF.{
."......4K..{.zn9....&.n.."V<Uo..F.S..n`\....d........O)..".v#.....
...O... Wo.......x4...D.&|(po....iq.4..Gw.ea...ni..`.(E...}...[...%...
...r.B."....).}..VK...8T...L.T.].=.8^x....s{.....-.g".h.:x....'U.i.'..
&.2x.0.@......@......*. .]8............7.m\..?.1..."..$*N_)8...%.....v
.s.O.q......#.,d.3 F.../..&..S ....t.ci/C]....w<..d.&...&,..=,..X].
8Vq.......i]./...OU...,.......^_>&.)a6.@'..,..t...z....z,j..{......
r:[email protected]!<......"...........a...l..
....m....]....Yd.N..........a<...<.=....C"...... ..L...De..Jq(..
fgT..]...x..C...M..|[email protected];.x..qCEG.....@T.[..3.\..9I..].4
. ..W.fI's]..q....f.... ^."...x.[[email protected]>....Gwl/.#[email protected]...
....@....%x.............W..pp.uz|MF...j..g....R[=.......|...jU..@L....
.YC......PSO.....XG.v4...9....k...............).....r......N..H...%..K
..*.]y.[....R.0.h....f9..-...S..=.`....T.-.j...2.B.........:.....e....
...hl...$..@P...=..j.............l@Z`.i.....G......S#...0,7Ky.k'.p

<<< skipped >>>

GET /r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 страница не найдена&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947 HTTP/1.1

Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.google-analytics.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Date: Mon, 07 Mar 2016 11:15:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Server: Golfe2
Content-Length: 35
GIF89a.............,...........D..;HTTP/1.1 200 OK..Access-Control-All
ow-Origin: *..Date: Mon, 07 Mar 2016 11:15:52 GMT..Pragma: no-cache..E
xpires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, no-sto
re, must-revalidate..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-C
ontent-Type-Options: nosniff..Content-Type: image/gif..Server: Golfe2.
.Content-Length: 35..GIF89a.............,...........D..;..


GET /top100.jcn?2768890 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.rambler.ru
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.4.7
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NON ADM DEV TAI PSA PSD IVA OUR IND UNI COM NAV INT"
Set-Cookie: ruid= iAgBudi3VYzBQAAAbjm3g==; path=/; domain=.rambler.ru; expires=Thu, 05-Mar-26 11:15:51 GMT
Set-Cookie: top100rb=NDQ4KzQ4OSs0OTE=; path=/; domain=.rambler.ru; expires=Mon, 14 Mar 2016 11:15:51 GMT
e1e..(function(window){var f=!0,i=!1,j,k=this;Math.floor(2147483648*Ma
th.random()).toString(36);function l(a,b){this.width=a;this.height=b}l
.prototype.toString=function(){return this.width "x" this.height};var
aa=/^[a-zA-Z0-9\-_.!~*'()]*$/;function m(a){a="" a;return!aa.test(a)?e
ncodeURIComponent(a):a};function o(){this.e={};this.i=[]}j=o.prototype
;j.a=0;j.j=function(){return this.a};j.c=function(a){return Object.pro
totype.hasOwnProperty.call(this.e,a)};j.set=function(a,b){Object.proto
type.hasOwnProperty.call(this.e,a)||(this.a ,this.i.push(a));this.e[a
]=b};j.get=function(a,b){return Object.prototype.hasOwnProperty.call(t
his.e,a)?this.e[a]:b};j.h=function(){return this.i.concat()};j.d=funct
ion(){for(var a=[],b=0;b<this.i.length;b )a.push(this.e[this.i[b]]
);return a};var p=Array.prototype;function q(a){return p.concat.apply(
p,arguments)};function r(a){this.b=new o;this.q=!!a}j=r.prototype;j.a=
0;j.j=function(){return this.a};j.c=function(a){a=s(this,a);return thi
s.b.c(a)};j.h=function(){for(var a=this.b.d(),b=this.b.h(),c=[],e=0;e&
lt;b.length;e )for(var g=a[e],d=0;d<g.length;d )c.push(b[e]);retu
rn c};j.d=function(a){var b=[];if(a)this.c(a)&&(b=q(b,this.b.get(s(thi
s,a))));else for(var a=this.b.d(),c=0;c<a.length;c )b=q(b,a[c]);re
turn b};.j.set=function(a,b){a=s(this,a);this.c(a)&&(this.a-=this.b.ge
t(a).length);this.b.set(a,[b]);this.a ;return this};j.get=function(a,
b){var c=a?this.d(a):[];return 0<c.length?c[0]:b};function s(a,b){v
ar c="" b;a.q&&(c=c.toLowerCase());return c}j.toString=function(){

<<< skipped >>>

GET /top100.scn?2768890&rn=139404967&v=0.3i&bs=1256x677&ce=1&rf&en=utf-8&pt=404 страница не найдена&cd=32-bit&sr=1276x846&la=en-us&ja=1&acn=Mozilla&an=Microsoft Internet Explorer&pl=Win32&tz=-120&fv=11.6 r602&sv&le=0 HTTP/1.1

Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.rambler.ru
Connection: Keep-Alive
Cookie: ruid= iAgBudi3VYzBQAAAbjm3g==; top100rb=NDQ4KzQ4OSs0OTE=


HTTP/1.1 200 OK
Server: nginx/1.4.7
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: image/gif
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NON ADM DEV TAI PSA PSD IVA OUR IND UNI COM NAV INT"
Set-Cookie: top100rb=NDQ4KzQ4OSs0OTE=; path=/; domain=.rambler.ru; expires=Mon, 14 Mar 2016 11:15:51 GMT
890..GIF87aX......4j..r...\.............f....\.$......\....4..........
..$.d...........ld..,.l...$~d$zlt.<......<v..r......l..|$.....,.
.......D........t..<...........|.T.........<r...l..L.......n.l.&
lt;D..$..D..........\4.|D~..z....<..l.....<n..z...l....j.\.$....
....L...........l......4..t.<...Dz..v.......4.................L..T.
$..l...|..4n..v...d..,.................,..................|..4.|...t.L
...<z.......\........d.....L.$.........,.....D..|.d..TL............
................d....j.\.,.v..........................................
......................................................................
......................................................................
......................................................................
...........................................,....X.......'..H.`. ......
!C8..X.8Q"...3V..................L.H..-.a..Is.M.8k....&..@."I..B...`.y
.TK..L.:..u...X]X..U .I'......S.~..=.6m..n.....J..x..p../..~....x.....
n....Q1y.....C..~,g...3...Cw^.8([email protected].:t.#[6...o..4..n..c..=....
...zc.P..4(H.!fL.<~h........;..........w...x..6..`$_..A.O'J$..$...r
[email protected]...%.]..~..W`.2L2F.Z ......A.~le
...L...........^..X...7..c.7bH...l...>d..........x.O....Ay...A....\
..!.K.ev.$P^.a.Vf...$.$.~....$..."....Z%[email protected].(.TI"..qc.
.....Vb.%..\....).(...X'[email protected]....^...=.q#... ...2...;l...j...
k......Q...>".c..J..$. Z...uj....r...P..AO......r..|^.'.`xE..Z zI..
.&......... P..M....g0...M{.....D...,. e......J...Gh.b.`....i.n...

<<< skipped >>>

GET /ajax/libs/jquery/2.1.1/jquery.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ajax.googleapis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Type: text/javascript; charset=UTF-8
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
Date: Tue, 01 Mar 2016 13:51:38 GMT
Expires: Wed, 01 Mar 2017 13:51:38 GMT
Last-Modified: Fri, 16 Oct 2015 18:27:31 GMT
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 29497
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=31536000, stale-while-revalidate=2592000
Age: 509053
............{..../....CD.....);.;.1..d.N$.........$f.....y.|.[...F..%.
.{.:q4......z............w...n.l......^.....?3._...Y. VKu..2.R..[...6.
.y...m~....Z..e.r~....[%.y...h.~..&g.Uv7..../...z..m...(.f..n./w..jn..
.l(x,&~.,..f....2.?.j.Ym|O.b.....|{............./.`..ww......B..{4.|R,
..k....C..w.b..#..o..h4VY.v..!..U.Z..NM.r}...)]P...w.5.....f....nS,...
nf........:.......;........eT....&b..,..b.o.j.].2..^......../z...v..b.
.T.|.=.P....?.........P.......k...x...a...ew.Y.V...Q '\(...ns..V.p...&
lt;.K.S.|9........l...j...n...>...3.w..0C...[Q<.].C.....t..q(..a
.2...]..T...&4.E...\.....T\B..7....x........[s.....t.6.[...%%....M..*m
.}.b...0.....e.....T/.g...*...z=..{..2.mQ...lw.*.o......,r..2.m..; ...
.w|,g...|...^F.v;.L.#^.t<.GcT..N....~....#...Dm.%....Gm.<ut...E.
...v".q..i.C.....T.&...D.z...v.,.........V.0.:KV.y./K.9m...hZ.l. .t.u.
[email protected].. @..... H..(....3mEQ.....A
....b)s.gh8...7:=......i....v.2..)V2.....-...Gf..k.d.4|.*.............
..t....C}lx...y..f.../. .n..<Ns....aI..T..!...a..r.:.8..Ht...j.v..P
.]..M..G..48.#W..&..f...Or2....vL5.]9.P....."m..U.A.....x.._.W1.'..6|.
,ES.5......qw....t .)..W.V?..=.n...oU............U..g_-....=c.2p@W....
._..S.H.7.;.....x.w..<..F..D@..|......U...z...{J./....3.)..B.2.}^GM
E..B..MOA..NJ.y7.....j.c...6..kzI...H..wg.........y.'A.....K.D..X....
L.m..4^.s..M3..].V...^[email protected].~..xO.g...x..7...<.>i8Oq.a...
F=.(.A..hK...RK.........2....2._..x...&Bk.!. .).9.s.k|...../N.%...s...
....28...P.!`[email protected]..~4......5b&X...)U...[w[......HR.

<<< skipped >>>

GET /hit?t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.yadro.ru
Connection: Keep-Alive


HTTP/1.1 302 Moved Temporarily
Date: Mon, 07 Mar 2016 11:15:51 GMT
Server: 0W/0.8c
Content-Type: text/html
Location: hXXp://counter.yadro.ru/hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165
Content-Length: 32
Expires: Sat, 07 Mar 2015 21:00:00 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="UNI"
Set-Cookie: FTID=1MtMBd3GLR5R1MtMBd; path=/; expires=Mon, 06 Mar 2017 21:00:00 GMT; domain=.yadro.ru
<html><body>Moved</body></html>.....



GET /hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 HTTP/1.1

Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.yadro.ru
Connection: Keep-Alive
Cookie: FTID=1MtMBd3GLR5R1MtMBd


HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Server: 0W/0.8c
Connection: Close
Content-Type: image/gif
Content-Length: 132
Expires: Sat, 07 Mar 2015 21:00:00 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="UNI"
Set-Cookie: VID=1sHqLj37UGbR1MtMBd; path=/; expires=Mon, 06 Mar 2017 21:00:00 GMT; domain=.yadro.ru
GIF87a.......k.....,..........c......c...........(..'..4.......h...B.;
.;...`..*RN.....=...t.t.......2.0(.#&..f.........io.......P..;..


GET /js/api/openapi.js?115 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vk.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: application/x-javascript
Last-Modified: Fri, 13 Nov 2015 15:33:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
ETag: W/"564602cc-112d3"
Expires: Fri, 11 Mar 2016 11:15:50 GMT
Cache-Control: max-age=345600
Content-Encoding: gzip
52ce.............}k{.G...........H..Y..[...c....Q.z(.e..H..,;...~..(..
.)...........B.P(..BU....'..hX.jd.....YV.j......=kd.|v9..~./.z...7<
...i..}...^.......z.x{pho.......J...S.&.... CA..o....k-.....jD...$....
........F..K{.....u...u.5.m..z...z.5...M..7..FC.hKX.._."O.U.?.q4....6.
.d4n..f6..g.,;.].gF!9......KE.....Ou.r.~...4...-..m....{.V.....n.i....
={...G......D\7.....NC..&7..QU.@o6....:......d`......0..bh....."..Z'..
7...r>.kS.[s.g.Lk.i...g.........5.x...... -........8..<.X.c....j
...O5.R.uk..h`.7...;}..u..O...^{....Z..}................q..\...._z....
.2of'..74*.W...yV' Fg.f..o.....6.a....t..ca[27\.Gk...........\X.].wk..
...............}.9J.......m`.>..R...$%......E.B>,$.A.........n..
-...........Of.N>..-...........O.. ...!.?..>..BO...._...T....Qb.
.}|j...].K.|.fv.7.l.=.bl..C...E2.W&F..1.....<.....(gJhD..w}..R.9>
;....../.....S..7..d.k....r....w......6.:..z..Y.....W....^......F.f...
)....M..[..;...S;`.##`.Z.X....r.*td.... .M7.......rz^?P[cX|!.6"..il.So
..5....2..........]A..0........u....s..m...F.....,...N..[.z.^.@.].6..H
..(...Yo..ak..Ls.......P......y..{.....h.q_[1_(.U..1...C.#6!..0...?]^
.."t<Xa|H~.P...G....M......i.........X..g...?.m]....3Xc!....,.S....
a".DT(`c..8....,.1...5..E&.....n..i. 'u........Cb..5.".....}.H.!g...U.
x2.'Xs..N.\.j..vW...jY..]......46|.....l..M8.Z.54....z.....gj.0......,
...........F;Y.>......s2.db..g..t.f....~g;..o......Z'..............
8]....Z.W..C>.........?...f.D!....?5..zW..].<.....7....-.0....P.
..D....H..t..!.'...w.a..]..,[email protected]..:... ...QS#.E_.}9

<<< skipped >>>

GET /js/api/xdmHelper.js HTTP/1.1

Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vk.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Last-Modified: Mon, 20 Jul 2015 23:21:19 GMT
Transfer-Encoding: chunked
Connection: keep-alive
ETag: W/"55ad826f-2c65"
Expires: Fri, 11 Mar 2016 11:15:51 GMT
Cache-Control: max-age=345600
Content-Encoding: gzip
e96.............Zkw....._.a..4I.r..e .cK......$-....B...,.$u$....'....
4........;..]`8dGoOX..<-8.....YY.....,.g.....p..q.U.9..._...9.N.l:.
..m.8x......7......]u.....3;......se3cK?g.....xR....~..OG...<..g.hR
.<.....L.G.Q.n\..h..[..H<<%.G..x.xD....p.N.g}.#.....?M...2.L.
4.z'...E.y....>g..*..!OK.<...=/I....B.,b..........e\V.|a&I..d...
?.V..(eG.....t.#...FG.;.vG.ab.N.c2....u...9_.x :..Dn.=G.p..s.dqZ.3....
.._r....'Y..X....O.....S...lg...3rX...,}!H.[c...J..e..gvp.;^.q..X..#).
15..*yQ.!.f.....1)....?......q};:..~"|0.9..?...N.Ey...)loo.9r(.S..nM..
.7.H%..x.;.#'{...U...^...4.....WP.p...........G.OUv7.....[.Y.....h..O2
J...q..._X ..qq..1.T...[.I..Gn...Hc...9..'...$...s."F..0.:...%........
v..n%.y.....'.I.1..BS.x.6..8..H....c.dih..Ma.b..t.[...p.....S..J.}.!..
m4..g].a......\.~...$......./.....'3..,[. ...r...}.I:.4E..u..VB.bu...g
..&/....p.FRgl..e.'[email protected]..._..T. z..l.....Z...!B..cA...8...Z
..1&........J..).Ln..*/....3...}9.I.Fz...`fF.:Ye..u.N]6....)Z...$K*|..
`1.C...TNS.X.(V.....s#O....!..[r..,[email protected]
......bU't._,...p]i......s....>..t{.C..*A$Q.37.......*..Ck...z.....
q|...yD.....X.$._..jZ.O...~.....O.K..........;.gK%.....).S.....&..-..,
......P7*.1.......&..$V}.....ei[k...Q..da.X.c...=x.BAi%...k.sh.Y.mSN#.
..V..u.a..b1....&.-o..V\T......Pv.# ..`.../M......e...}.f<A........
...........U.!..<//d..a.4....w.H.J.......%p.O..........T..4a.......
..G..s.5......E.hGX;...T..Nm..'..qt.[.}....T..}V,p..ET2m-..^2.....h[[.
.H.Aj.....YAO...l.FC..jJ4....7. ah-.f.rl3.Z....R.....r.hm&2..E....

<<< skipped >>>

GET /downloads/752_55394.ppt HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Server: nginx
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.28
Set-Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04; expires=Wed, 07-Mar-2018 11:15:50 GMT; path=/
Content-Encoding: gzip
e55..............mo...{~.. &..I.vj....M1.H..h?..a...x6.cxG.r..M.bC.vm.
.........4^..M.....<G..5r..HD.......K..z....}.5.....P...iX .qb`....
......(q<.K..F..............i....~.u......Q.........k=l..].N....i..
F..F$be.G......]..]V..3.C... N}S:.g....O.......Z6<.".i...H.&D.g.#..
X..~qu.~.^Z[........Ab...(..\z,6.=.U.....$.p.. ....<.5f..i[.;"...N.
..8....c,.A..L$|.U..H......(ej.....C.....J..F.....tM.`R..^[email protected]
&..G*..b....u...D...Q?.8..M#n...p...eP..]...`vvjw..p.....:q|*e....s.3.
..!....p. ..#........ ...?d....1..zG..f....od`...Ci..yQ.L......EM..xPK
.;v.6Fi.X .k..>8R......p.'...oI.'....#.Jl..}.........}.......Z:FJ6.
i...u..J<..,..M.^......&...8 .q<..R.k&.Q\..|n..a....."...._.a.t.
&C...n....L.i.h...I..A..O..A".:..>.6h. .....c5....,#..7.....p.%5.J%
Q..^F.1 .M..x..].....V3.1].....'n..|.`.w.%..G...D...1.yj.}.|{.o...18..
[email protected]...)zR..P.......c...9.<v.<..O....P..??`.....%3.Bq...3
.....]$|h...a.,..*......K.[Xb.s.......tvJv....1.O...j......LH.`..... .
.T..BZ._....}I.....o..u.vc........REM%j5.....h~...........0......dv.i.
..A ..~.e"..3...qB....<.A_~.(...=.Z..c.g&.A-..-.|......... y..o}..X
........g.........8_..,B<.........!...........4- .......V.......T..
...^.b.KC.........S...].=..>>c.....2..MXS|...!=A.M....7 ...E4.;.
....$gx...3....K..2.wm.'.g.....d....T.XO.~<kbE..[...!..............
|....u.~..`..y. .=..3?..O....89.h3AF...x|.&.o....._0.O....:..w.<D..
5...;.=m....u.<c'.................F.H].....y..U|.Q..s......../...y.
b....(.......d............g..~?..#7 ....."..:E..V.....*.........~.

<<< skipped >>>

GET /style.css HTTP/1.1

Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04


HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/css
Last-Modified: Wed, 25 Nov 2015 11:42:28 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Tue, 07 Mar 2017 11:15:50 GMT
Cache-Control: max-age=31536000
Content-Encoding: gzip
5858..............m....0.....`...3>...w.*...s_Rus.l><...E...1
%*"u^..._...h.....n..$...h4..t..h...w.|....KU5usNO...(.%..}...........
m.....Su.|...M4..d..5....h..<..|........X.Yt9f.9....*...o../...}.qS
.7.......!.......?......*.}....|....E..|H....h[[email protected]`Y.}
s(.....w..(??...........z....a.`.i..K.<&q..z.1..R4t.mSe.....\...[zn
.m......A.7iQ..]..MOMQ....s>...2N..4..y>W.......1.0...../....5 .
S.~~d...rK/YQ....CZ.N........k.2...,..PTX..9Ui9d|x>>n.:......j..
.eL9We...Aq...z..1f..q_dY~.i...V....-.n../....1..#.S.........p...o..h.
9...M..t.Tg....j.....>E..5.n......,...$c...lw....s.?......O.G6<.
...V#2./..#....$....^o..:?~.3.5....X.../....|]..[..j..OU]..z<..)..A
fsLMuz..f.....N.Gc..8< n0......<...<\9.we..Q..M......p..>.
....P..q....8>?.q.....:......4-....m &..l2&e..N.'g...cU..m>0..-.
.U.....8(..K3.N..s..&..>..s.^.0..=....`.0.Jb..}(.bS.....*f([B....z)
...O.H..c....^~.i.>.i.7..6J.....W..t.S.~.?.....\3.OU..zV....F...~..
..WU).w..lT..G1v.j{.......Q..n.d}J...g|..W(.r....l....6.n.S...yhd.L.O.
..q..6..'F... jX.....x......U.,$.2..z.'...yW.e.n.w]...@P`i...[NDIt6T!.
..9.....!..;L........"...dRo.B4>...M.....c..._G..9?f.....Nr=/......
Wh6I..T.....*..^.....j...!..4:..... 'g.O3.0......:7....1..Vk1.O..c....
R.n).:|.`.D6k..QX"R...?............7..7Q.4....!z...j. .(V......7.O....
...T5....7..7|.......3.|a.v.Z.!}f..../l.qC.1.P........b........5lMaj&T
....O..E...u.xz......Z.O{6...5..>._n..`..RH......@<b..&=...HP.1.
.........h...F[&&.`........iIfJxH..mT...$x...Q.l.h$.%$3}.......dY.

<<< skipped >>>

GET /fonts/glyphicons-halflings-regular.eot? HTTP/1.1

Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04


HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/vnd.ms-fontobject
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Mon, 13 Oct 2014 19:07:31 GMT
ETag: "12840296-4f6f-505529c4862c0"
Content-Encoding: gzip
400a.............{[email protected]...]........Cp.. .....n.V.}....o.
...y...qQ...............[...(.?LQ..?.........s........z.U.,@. .P.(.4..
.....`......6...\t.:.._...j.p......!..F....x ......O....|....[.......X
......`......N.<;......?.?.....z\.Ux...,...y..W.......k..?;.....py.
...L........:...n._|(....Y28.sw....vK..w.S9...R...J..c..g..6 :........
...j....L*...._,cm.....rf..HZ.G.!.....=.n=&..`.W*.T|......[...D$...cv.
:1u............ ..FJ...{8`.=:. ...Q.(...-......4..}..1C*...p....._..{.
_..p,<.7.(.d?t.I-....S...bWr..T.....2{..I..~..m.CY...A7y...W.o2..QR
..F......:,.)5..T...{.....C&...$...*L....f.....CS0ne..\8..m].A/4z.....
..".y.-..{d.....Em{-_{.>.b...e.V.'V.c&rw...<..!.9:.......H.....b
......^y....^....R}%....g........!..N.....!.].o...\6ci.-...3.<=..&g
t;.N..>...cZU...f..z&..XqE..1.z.`....H.s.^W.`......E.TE......yoa..[
....~..!....yH.TR......h}s.1{.[.nu& v....z..*)?:.....`n.ciC..;.6T.?...
.pEI.r.]:.3..^.....,N ........f].i..G..O(.).......-...>.cY...[S..?.
o.LI1PG'...L...QL....o.0E......Q.j....=...A.`.y1....V.*.!....x.H...#"_
..O$`[email protected]}7..G..0.....W....#...|.>K.&.Ky.&....._..~..2.!.GN
...........m.Vt.,Y.`B........J..".Y.l..^1....V.....*..0*....P.5."8P?#.
........h..O..!............S.O.P66(.j..)..p.QD..%Q3p.p'..~...b...>n
...W....(D&....=..C....l!..S......?...H..@.*.v;..%.......v.mP..?......
8.m}...c..56S......rA.b.eH......H....]6.....Fw. ....>._...r.Y3...7S
.O..<.'...7...l0.R*......W.x%QQ.5HQ......'.p.`*^.kD.......}.E."Q...
p...q...m.Fs..?%Y4....v1g.4..d.....Q.....?...3.....5S.E.T. t^.,u8d

<<< skipped >>>

GET /msdownload/update/v3/static/trustedr/en/authrootseq.txt HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: VVV.download.windowsupdate.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: text/plain
Last-Modified: Thu, 28 Jan 2016 17:51:53 GMT
Accept-Ranges: bytes
ETag: "80823092f459d11:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 18
Date: Mon, 07 Mar 2016 11:15:52 GMT
Connection: keep-alive
X-CCC: UA
X-CID: 2
1401D159F4929680B9....



GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1

Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: VVV.download.windowsupdate.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: application/octet-stream
Last-Modified: Thu, 28 Jan 2016 18:43:43 GMT
Accept-Ranges: bytes
ETag: "80d9e4cffb59d11:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 49661
Date: Mon, 07 Mar 2016 11:15:52 GMT
Connection: keep-alive
X-CCC: UA
X-CID: 2
MSCF............,...................I.......d.........<H.T .authroo
t.stl. ..-.8..CK...<Tk........./.........Z..e..P..D.&.BRTH...E..E.b
.["$qS)....-...[..}.o~g...q...Y...n...........aF\!.lI.4..0..ef.W.....C
`....Y..F.D5...Y.A....1.|..c.1...Nc.Y..x..D...NP[[email protected].....'.B.
......"(~3z-.@~..|}(.......g4.p.........h.n.dQz..t.V.......;.....Q...d
/../.pJ...6....E...A.@..]..T9..28..,..p...).....P:}.K...]=.7X.f..9..yB
.P....uP$$...Q.u..y..".=......7...........#.X..P.8....>U....v.[.$.e
...H.@~..........ea`.3...tLX...].-....<.........v.....M../..z6.t^..
...p....M...v(CP%F.......!eX..a...-..G.....S%..l.....Y..(.*.-....C.L0.
..G.....).rm8...(7.T{.Q...."...B`H.....3..9..-..Vv.5Q.e.W.../...RY.v.P
. .........l......8'.&z......3.;:...U4.."....yu... .."....d .e/7.;.XD*
tn%$.........];..fY.R...7.....o.=xh...]..4...\.:...v....t..9 .nO.i}.T.
./(uke..p.&.6.E#[email protected]...*.s....h......(/.s.%.3g...:*X.].7.IE....
E,.w.8......v...r4.qOh}~..E.5t...l...(*..2....`..F..".a:.t....9...W.kO
?5..=..HhYrI.Sf..[:...3..2..)DB...;......(...B.......U(...._F./#.k@...
.9c.Y..G'..]...p..;M_o..~.3?.}.1M.5.f5)._......t _.6...l..K....OsY.0..
....H...^..\$P;U....8..)...1........J...uE..#n.......h.......17.P=,P..
...}z.&..../..a.........p@.|KB..o.E..|..o.mr......m=.(v.:[email protected]
>4y....P........F...&... ....r$d..{B...)..A.`..x4E'~`V.."..(..(./G.
..@_Q`.....O...~`..~...x..KN~....Dko/A{..!...W..G,`)...*...#......q`..
H.........%m..G....5..4.....?.......F...{.%..2....l.L....."...Y.......
. ...].\........... D..Y...!1..*.....M?..G..A.|Ex......~...s.!.=..

<<< skipped >>>

GET /font-awesome/4.1.0/css/font-awesome.min.css HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: maxcdn.bootstrapcdn.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/css
Content-Length: 20766
Connection: keep-alive
Last-Modified: Wed, 14 May 2014 20:41:32 GMT
ETag: "bbfef9385083d307ad2692c0cf99f611"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:50 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman [email protected] or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes
/*!. *  Font Awesome 4.1.0 by @davegandy - hXXp://fontawesome.io - @fo
ntawesome. * License - hXXp://fontawesome.io/license (Font: SIL OFL 1
.1, CSS: MIT License). */@font-face{font-family:'FontAwesome';src:url(
'../fonts/fontawesome-webfont.eot?v=4.1.0');src:url('../fonts/fontawes
ome-webfont.eot?#iefix&v=4.1.0') format('embedded-opentype'),url('../f
onts/fontawesome-webfont.woff?v=4.1.0') format('woff'),url('../fonts/f
ontawesome-webfont.ttf?v=4.1.0') format('truetype'),url('../fonts/font
awesome-webfont.svg?v=4.1.0#fontawesomeregular') format('svg');font-we
ight:normal;font-style:normal}.fa{display:inline-block;font-family:Fon
tAwesome;font-style:normal;font-weight:normal;line-height:1;-webkit-fo
nt-smoothing:antialiased;-moz-osx-font-smoothing:grayscale}.fa-lg{font
-size:1.33333333em;line-height:.75em;vertical-align:-15%}.fa-2x{font-s
ize:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em
}.fa-fw{width:1.28571429em;text-align:center}.fa-ul{padding-left:0;mar
gin-left:2.14285714em;list-style-type:none}.fa-ul>li{position:relat
ive}.fa-li{position:absolute;left:-2.14285714em;width:2.14285714em;top
:.14285714em;text-align:center}.fa-li.fa-lg{left:-1.85714286em}.fa-bor
der{padding:.2em .25em .15em;border:solid .08em #eee;border-radius:.1e
m}.pull-right{float:right}.pull-left{float:left}.fa.pull-left{margin-r
ight:.3em}.fa.pull-right{margin-left:.3em}.fa-spin{-webkit-animation:s
pin 2s infinite linear;-moz-animation:spin 2s infinite linear;-o-anima
tion:spin 2s infinite linear;animation:spin 2s infinite linear}@-m

<<< skipped >>>

GET /font-awesome/4.1.0/fonts/fontawesome-webfont.eot? HTTP/1.1

Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: maxcdn.bootstrapcdn.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/vnd.ms-fontobject
Content-Length: 72449
Connection: keep-alive
Last-Modified: Wed, 14 May 2014 20:41:33 GMT
ETag: "90186830c9c50a0fed932494581761d9"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:51 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman [email protected] or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes
..................................LP........................!H........
..............F.o.n.t.A.w.e.s.o.m.e.....R.e.g.u.l.a.r...$.V.e.r.s.i.o.
n. .4...1...0. .2.0.1.3...&.F.o.n.t.A.w.e.s.o.m.e. .R.e.g.u.l.a.r.....
BSGP..................X.........B.....`.g.iSyR..&U:.47.4......mj...1..
....I.PJQ......X*i.Y.!G.....0.*.-.a.....Xn..$.X...2......RL....RD.....
.p...f..."..p.vU;..k..2.6IQ.}-T.y..I....z....E'....T.....`.D....].Y...
G......&.E.7e..%...:[email protected].)lI....FW.'&...
..X#............J.G.~.........e.0.sZ.. <.. ...p]..e...C.....h......
.[.....e}j.I.pr..n..#A".P...'!A..~B........mtv-.,....)2..YQI....o.....
.YA@&&....<c.(?........!....B.\K$.D........Ke.4p. S........>.P..
z..T...#............[[email protected]'.<..OY.....
.pB:..x..p.....)..A.gd.P....t.....6...P..{.b....Z..l......ka.tV..Y.Q2U
.,...l.'k.uW...A......}....~.m!.x..=&.%...V#....|;L.......[...".k.eT.B
..}....r|...O......}.4...=bC. .L..... .d......O.2E......G....8..%...!.
'H6..0..t...rO!Q..y.E..DP!..O....,..4....3...\...S$..............%$...
a...........;...df#DwFC..6b.f1...Y.F:CE......../.<.`...v..^...-..&g
t;......q$.........&...5s4.0.9...v.....!.WQ.J..n...L..8;q.O....w..m...
.....1>.1..e?...,I.c^e.D.-SP.....5......`."a....U.........a..>..
\.....t'..|.3.1HZ1....8..4...1.*[email protected]..[]..!9..U`......`.T.?....
.X#......W.........vz.uK9.5]"X.u...oR\[email protected]...
........x ...... ...n...........:{.M..?..*.=..:.z..x}z..p........._.`S
.G..%")v..f....F.Y._.u...*AG...4\[email protected].._.5Al.t.o....{L..._!.8.n.

<<< skipped >>>

GET /share/share.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: yandex.st
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.8.1
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Tue, 26 Jan 2016 15:03:14 GMT
ETag: W/"56a78ab2-d3bd"
Expires: Thu, 10 Mar 2016 11:13:29 GMT
Cache-Control: max-age=259200
Cache-Control: public
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
Content-Encoding: gzip
3580.............}k...q.w....<....y.,.....o......;[email protected].;
..u.rHa.z.%Y2-Q...C$-R........Y...._....Pxv...2.....BUVVfVVVVV........
...*..[..M..7..........N..w.].1Oj...[..,._.>~....n.%...o(.*I..b.Y..
g.9DW..fh..l6......G.t...../A?P....K5....9.....O.........S..}-nBX.....
yS.-..B.J*.D...j...d.X.c.......5k_.e........e....M..M'|...J..v&....R..
5....m.?0.^.......s...%].{J.h.*......lh.... .....r...M.7...Ms.......H.
&...aOL}.#....A.z.|.3.........M..d0..B[.0.Y.M=.L(.-.......0.SVz.'.[..9
8.Be.... .<>i...V.<5.Pn:m..g...,m~........s......>-.....M.
.[\t..e(.>.l......ZTZ...wv9[...{.....tvQ.U..$t1.-.f.c.[@8.oN ...pBQ
]}.9h.c.j.s...8....i.rF...i_Y.......<7..v.1.\{....k....v.;.....3.@.
.....x.5.d.j...........N......o......g......Z:mo..8. &.B.......Qq.. ..
.7.F#...i.:.\?4..,Pc.*..;.R}.`.j.$t.D^a&.6.....V`.,...4.E.-..z.9..1..?
.;.9'n....... ....vd.,.f.v.pF5.7.M.<...W..........'.y...jc.gg......
....=.. . .....{....$....-Y..bm.H....p...5....0l......R..F......y ...
m3'z....#D.dKk..P;0..............,.q.<yB...(c'.:.Q.....G.-.2l50....
......Vg=%U...4....(J..C.%...0....i...C.'...:f^\.......'~...s-'4..L...
.=D.<-V.,Z.z../\.t.Vo......Q..O.w"%....U...|s..41Wf.:..5G0.[..X.^SK
.A...RDu..9G..l...=..&.9.....{c..]g..Y.....^.#..r..<......H.1..<
....?/...W......c..Y`}ns._.....3.........>WK.;.U..K..... <..\.D.
....,P....o0."[email protected].... ."....V..S......D..>....f=5I.d..(.&.....
..Z...zb.....VL..T`.p.."Y&!.Z.`.|B.E.p .k.....i......c(.2....2O=.N...s
T82,'[A.........4.g...0.e...<y,sp.P_.L.|.y....>..{e.......Hk

<<< skipped >>>

GET /images/logo.png HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04


HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: image/png
Content-Length: 1928
Last-Modified: Mon, 13 Oct 2014 18:58:38 GMT
Connection: keep-alive
Expires: Tue, 07 Mar 2017 11:15:51 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes
.PNG........IHDR..............qr0...(PLTE.............................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..................................feB....tRNS.........................
..... !"%&'()* ,-./013679;=?@@ACDEFHIKLNPQSWX\]_`abcdeimoppqrswxy{|~.
......................................................................
..................wg....YIDATX......5..3.Z...(j..... ..@9,rU..#.sA..E.
`9e)..5.e.*....li.@..{.%3..L......~.~.&3/..&....!.......Q#AP.b...JW.l.
.KO...-..it....I.g&l6..c.........a......)G..3.a....$.!..5./n.s.....|..
.r.N..F...tG.......o....w<.h..#O@[email protected][email protected].
...U.c..S..7....Xi..{.Nm..b ..c.1.D.8D.l.....0...2......._.``...;?o.&n
.uR9.D|Lk.(z.yZN>e".pD..8Y.?V&.....{:.p`.4.}M.0.2...1...[.....?.4..
.u4.#...6.$...vrz..i.r........... .a..K.....?Gc..6...B.s"....6..a&.aY.
K....b..9ac....p..F...S".S.t.F...b3.....8..wi.eA5.{.....L......0..`.*.
.8`..6(.wA...r. ..D....sH..]....!`.$Y.c.`.]-H. ....'.....-J. .v'.aT.?7
!....^.1......*.`...^...!..6...b...aXiW...w.".c5]..............U.T$x.R
6R!$"P<^...x.\T.RjB.`.CW1j{.(.M......v....$\....b8....6.<..c

<<< skipped >>>

GET /bootstrap/3.1.1/js/bootstrap.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: netdna.bootstrapcdn.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:52 GMT
Content-Type: application/javascript
Content-Length: 29110
Connection: keep-alive
Last-Modified: Tue, 01 Dec 2015 17:30:27 GMT
ETag: "ba847811448ef90d98d272aeccef2a95"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:52 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman [email protected] or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes
/*!. * Bootstrap v3.1.1 (hXXp://getbootstrap.com). * Copyright 2011-20
14 Twitter, Inc.. * Licensed under MIT (hXXps://github.com/twbs/bootst
rap/blob/master/LICENSE). */.if("undefined"==typeof jQuery)throw new E
rror("Bootstrap's JavaScript requires jQuery"); function(a){"use stric
t";function b(){var a=document.createElement("bootstrap"),b={WebkitTra
nsition:"webkitTransitionEnd",MozTransition:"transitionend",OTransitio
n:"oTransitionEnd otransitionend",transition:"transitionend"};for(var
c in b)if(void 0!==a.style[c])return{end:b[c]};return!1}a.fn.emulateTr
ansitionEnd=function(b){var c=!1,d=this;a(this).one(a.support.transiti
on.end,function(){c=!0});var e=function(){c||a(d).trigger(a.support.tr
ansition.end)};return setTimeout(e,b),this},a(function(){a.support.tra
nsition=b()})}(jQuery), function(a){"use strict";var b='[data-dismiss=
"alert"]',c=function(c){a(c).on("click",b,this.close)};c.prototype.clo
se=function(b){function c(){f.trigger("closed.bs.alert").remove()}var
d=a(this),e=d.attr("data-target");e||(e=d.attr("href"),e=e&&e.replace(
/.*(?=#[^\s]*$)/,""));var f=a(e);b&&b.preventDefault(),f.length||(f=d.
hasClass("alert")?d:d.parent()),f.trigger(b=a.Event("close.bs.alert"))
,b.isDefaultPrevented()||(f.removeClass("in"),a.support.transition&&f.
hasClass("fade")?f.one(a.support.transition.end,c).emulateTransitionEn
d(150):c())};var d=a.fn.alert;a.fn.alert=function(b){return this.each(
function(){var d=a(this),e=d.data("bs.alert");e||d.data("bs.alert",e=n
ew c(this)),"string"==typeof b&&e[b].call(d)})},a.fn.alert.Constru

<<< skipped >>>

GET /metrika/watch.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: mc.yandex.ru
Connection: Keep-Alive


HTTP/1.1 301 Moved Permanently
Server: nginx/1.8.0
Date: Mon, 07 Mar 2016 11:15:52 GMT
Content-Type: text/html
Content-Length: 184
Connection: keep-alive
Location: hXXps://mc.yandex.ru/metrika/watch.js
<html>..<head><title>301 Moved Permanently</title
></head>..<body bgcolor="white">..<center><h1&
gt;301 Moved Permanently</h1></center>..<hr><cent
er>nginx/1.8.0</center>..</body>..</html>..HTTP/1
.1 301 Moved Permanently..Server: nginx/1.8.0..Date: Mon, 07 Mar 2016
11:15:52 GMT..Content-Type: text/html..Content-Length: 184..Connection
: keep-alive..Location: hXXps://mc.yandex.ru/metrika/watch.js..<htm
l>..<head><title>301 Moved Permanently</title><
;/head>..<body bgcolor="white">..<center><h1>301
Moved Permanently</h1></center>..<hr><center>n
ginx/1.8.0</center>..</body>..</html>....


The Trojan connects to the servers at the folowing location(s):

iexplore.exe_1940:

%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG
;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    msisetup.exe:592
    msisetup.exe:1564
    %original file name%.exe:348

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\BYBRWJVG\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3I2TUWDI\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TFZ1DZO2\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\B55C40TD\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (169540 bytes)

  4. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  5. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now