Dropped.Trojan.Generic.20281016_b03464cb3b
Dropped:Trojan.Generic.20281016 (B) (Emsisoft), Dropped:Trojan.Generic.20281016 (AdAware), Trojan.Win32.FlyStudio.FD, GenericEmailWorm.YR, TrojanFlyStudio.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, EmailWorm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: b03464cb3b39f6eef19436344224d9bc
SHA1: 82227729be2dbfb22a283b1793717102acd30b7d
SHA256: 8a6ac87aef1b02ab59e037254e28ec8963bb5d46f384f619f56c8786ef4563d5
SSDeep: 49152:wwPcDMe0FNDMTTwr92yjAdxD uYRUAiuoaGGn5sQXi:fP8Me0fMv0UyjAdxD nqSDsQXi
Size: 2678784 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6, MicrosoftVisualC, MicrosoftVisualCv50v60MFC, MicrosoftVisualC50, Armadillov171
Company: no certificate found
Created at: 2017-01-15 22:22:06
Analyzed on: Windows7 SP1 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
| Behaviour | Description |
|---|---|
| EmailWorm | Worm can send e-mails. |
Process activity
The Dropped creates the following process(es):
CDM.exe:3436
The Dropped injects its code into the following process(es):
%original file name%.exe:2180
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:2180 makes changes in the file system.
The Dropped creates and/or writes to the following file(s):
C:\%original file name%.exe (18248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\error[1].htm (2704 bytes)
C:\CDM.exe (1810 bytes)
The process CDM.exe:3436 makes changes in the file system.
The Dropped creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\dlldy[1].htm (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gengxin[1].htm (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\dlldy[1].htm (17 bytes)
C:\Proxy.dll (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UVH22G43.txt (109 bytes)
Registry activity
The process %original file name%.exe:2180 makes changes in the system registry.
The Dropped creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASAPI32]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASMANCS]
"EnableFileTracing" = "0"
"FileTracingMask" = "4294901760"
"ConsoleTracingMask" = "4294901760"
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASAPI32]
"EnableConsoleTracing" = "0"
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASMANCS]
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASAPI32]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3C 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASAPI32]
"EnableFileTracing" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Dropped deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process CDM.exe:3436 makes changes in the system registry.
The Dropped creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"EnableFileTracing" = "0"
"FileTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASMANCS]
"ConsoleTracingMask" = "4294901760"
"FileTracingMask" = "4294901760"
"EnableFileTracing" = "0"
"EnableConsoleTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3D 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASAPI32]
"MaxFileSize" = "1048576"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASAPI32]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASMANCS]
"MaxFileSize" = "1048576"
"FileDirectory" = "%windir%\tracing"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
To automatically run itself each time Windows is booted, the Dropped adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Î񵀮ô¶¯ÃÂî" = "C:\CDM.exe"
The Dropped deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"
Dropped PE files
| MD5 | File path |
|---|---|
| beb1ea045490ba658f11b9f564e50068 | c:\CDM.exe |
| 2ac708267bb532ad405adaa1af140eec | c:\Program Files\VMware\VMware Tools\VMwareTray.exe.bak |
| 65eca73f39f1c9d671519035e0585314 | c:\Proxy.dll |
| c187f718b9f4bbe6813b51e3b0eb87e3 | c:\%original file name%.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name: ?????
Product Version: 1.0.0.0
Legal Copyright: ?????? ????????
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.0.0
File Description: ?????
Comments: ??????????(http://www.dywt.com.cn)
Language: Chinese (Simplified, PRC)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 686982 | 688128 | 4.52934 | ab0706c97bedce50507da9e0f5474db1 |
| .rdata | 692224 | 1085098 | 1085440 | 4.25681 | 9c9475af0aeffa6c70a0310060ee77ad |
| .data | 1777664 | 363912 | 106496 | 3.65446 | 534e0dfb12fe425c6d5957bfc67c4405 |
| .rsrc | 2142208 | 94420 | 98304 | 3.62674 | 9f6d5518b0bcabefd81cd94237b0fd08 |
| .bak | 2240512 | 6403 | 8192 | 4.38113 | 4eb3f35c8bf55823feb258ef493c0849 |
| .bak | 2248704 | 6403 | 8192 | 4.37507 | 7a0b8d43cfcdd0b346898197f1cc0b68 |
| .bak | 2256896 | 6403 | 8192 | 4.40826 | c4c732ab5a318c6039e5babf1016a0b9 |
| .bak | 2265088 | 6403 | 8192 | 4.39516 | 7d90b9376b771ebe2e18ea04eeef2da0 |
| .bak | 2273280 | 6403 | 8192 | 4.40941 | f3a6a21cf8a6915bf1414daabf1436db |
| .bak | 2281472 | 6403 | 8192 | 4.32451 | 6327d4ac0975cfc2cb9126f5e722e11e |
| .bak | 2289664 | 6403 | 8192 | 4.38369 | 11868f342ad19f03e2964f5c63de6a4c |
| .bak | 2297856 | 6403 | 8192 | 4.40462 | a2b1ca2532daa29f039dbdee7422dd46 |
| .bak | 2306048 | 6403 | 8192 | 4.33146 | 1e5c99ee9cbca3f197b0e1c5bbf46e4e |
| .bak | 2314240 | 6403 | 8192 | 4.41334 | 59dc7a5e1b4d7afa753de9acd13a61e3 |
| .bak | 2322432 | 6403 | 8192 | 4.35977 | 01aae6158fbebaf9410e5ebfc4aed164 |
| .bak | 2330624 | 6403 | 8192 | 4.29377 | d8029b4ad637c3172d4a486f439a3430 |
| .bak | 2338816 | 6403 | 8192 | 4.36712 | c674cde4bafe27312891fb1e02a965c3 |
| .bak | 2347008 | 6403 | 8192 | 4.40381 | 16eeb5bff577478403deb5ff53026b0d |
| .bak | 2355200 | 6403 | 8192 | 4.40262 | c1837c80162fbb8aac38d5d35de52b59 |
| .bak | 2363392 | 6403 | 8192 | 4.39975 | facd56c3fda10c87aab7ce2241166cfa |
| .bak | 2371584 | 6403 | 8192 | 4.36125 | 13e9a4827d0a8fdfe191282b519661dd |
| .bak | 2379776 | 6403 | 8192 | 4.3845 | d8c01ebb01fd80b3889186c86e15d647 |
| .bak | 2387968 | 6403 | 8192 | 4.37363 | fe7a22fbdf4cc1fe06b64d5a322b75d7 |
| .bak | 2396160 | 6403 | 8192 | 4.39039 | 9751a79b58c9ef503ccb1180f54d3991 |
| .bak | 2404352 | 6403 | 8192 | 4.40671 | 4d16a99a01b997fc5c534aa1af0e85f5 |
| .bak | 2412544 | 6403 | 8192 | 4.36217 | cf90f784da78545d4f2e66d1e4d355be |
| .bak | 2420736 | 6403 | 8192 | 4.3897 | b5ae8dc650df0600c4cf48cf152e90fc |
| .bak | 2428928 | 6403 | 8192 | 4.39471 | 630e10ce48a5bb80948684bff0093c0a |
| .bak | 2437120 | 6403 | 8192 | 4.39011 | 2e223f2f6a5bd87f867ad23b5631fda4 |
| .bak | 2445312 | 6403 | 8192 | 4.35558 | 4833cf89f70ac9a1ad5acfe7875f2222 |
| .bak | 2453504 | 6403 | 8192 | 4.30352 | 878a30e724a68f6f207c6b0b333374dd |
| .bak | 2461696 | 6403 | 8192 | 4.35721 | 6fce5ae996cf2c1b02a949e8297dbb34 |
| .bak | 2469888 | 6403 | 8192 | 4.39586 | 4f776ad5e904560b7b1beba74eb42aa2 |
| .bak | 2478080 | 6403 | 8192 | 4.34614 | 789d622c3f632a0b34737a8e68c508a9 |
| .bak | 2486272 | 6403 | 8192 | 4.41374 | 1b52151f5e7dfbcd35e25c8bfcf24b33 |
| .bak | 2494464 | 6403 | 8192 | 4.33752 | 0e052cf915bf233a70cf71977d14a020 |
| .bak | 2502656 | 6403 | 8192 | 4.33453 | 49b43ccc24714bcb89c97b1ab2ea35ba |
| .bak | 2510848 | 6403 | 8192 | 4.36256 | ff56a9b4e6dd17810a331699457eced2 |
| .bak | 2519040 | 6403 | 8192 | 4.39543 | 30ebbcd4bf4ae45ee4966a81460be0e9 |
| .bak | 2527232 | 6403 | 8192 | 4.37961 | 1f374ccac86a0d4061271aaf7b72f889 |
| .bak | 2535424 | 6403 | 8192 | 4.39373 | 9fbe75c1843fbc1e33cbbbec53059049 |
| .bak | 2543616 | 6403 | 8192 | 4.38681 | f533136265bec1c9529022764f477b87 |
| .bak | 2551808 | 6403 | 8192 | 4.40418 | 46e39545b5578e848a576a75ae426f6d |
| .bak | 2560000 | 6403 | 8192 | 4.3933 | 9cd3444587310abeb309d35bc99f3275 |
| .bak | 2568192 | 6403 | 8192 | 4.41648 | 19c28bb84df067d25595ec7f7c6d7c3d |
| .bak | 2576384 | 6403 | 8192 | 4.39337 | 2bb4214af4bb4d6fd5aa53c3f70d844f |
| .bak | 2584576 | 6403 | 8192 | 4.42723 | 47d70604abb22a4330b5f1daf84e660d |
| .bak | 2592768 | 6403 | 8192 | 4.40041 | c1d29c684b207b1279505b3109940b40 |
| .bak | 2600960 | 6403 | 8192 | 4.35812 | f02bc1c516dda2eb650f5aa3e4678c4a |
| .bak | 2609152 | 6403 | 8192 | 4.36857 | f87127e63b944e26240d14d62937f9e9 |
| .bak | 2617344 | 6403 | 8192 | 4.41511 | f498446dfae80da9a13b4a3bf5c9941e |
| .bak | 2625536 | 6403 | 8192 | 4.36551 | 2bf8cbf8acd9c04ceefa96b13b24753b |
| .bak | 2633728 | 6403 | 8192 | 4.35017 | 7873619523a31c4642851de759150714 |
| .bak | 2641920 | 6403 | 8192 | 4.38499 | 03bee09979133841fffbd8429fc852b9 |
| .bak | 2650112 | 6403 | 8192 | 4.42283 | 47fdbe72a68a6843dcbd0c6656432c20 |
| .bak | 2658304 | 6403 | 8192 | 4.33423 | 45a4b8360c856d9334db987e89edf25c |
| .bak | 2666496 | 6403 | 8192 | 4.33416 | aa34dfdbbab16c5e63ec0b495e2ed125 |
| .bak | 2674688 | 6403 | 8192 | 4.36392 | a929ead532a61896227b71da4396a8e5 |
| .bak | 2682880 | 6403 | 8192 | 4.35125 | a7b47bcd13f83b1218df0715a7f8ac57 |
| .bak | 2691072 | 6403 | 8192 | 4.39885 | 5656ec91423d3133ff77bade66b7f18a |
| .bak | 2699264 | 6403 | 8192 | 4.40442 | 81782588c7c8effa2b83f99a57c9993e |
| .bak | 2707456 | 6403 | 8192 | 4.40022 | c0526e2203c682c371dd813a990b4518 |
| .bak | 2715648 | 6403 | 8192 | 4.42288 | e21356522e1b949f1c0846303fe46cae |
| .bak | 2723840 | 6403 | 8192 | 4.39322 | bc6f945b1305e93a59397f342a1d76d0 |
| .bak | 2732032 | 6403 | 8192 | 4.39672 | 6d63a9d9182a44ec2af3033f3e36f2c2 |
| .bak | 2740224 | 6403 | 8192 | 4.40175 | 177f0767636faed1d31eb1b7ea4c2b1b |
| .bak | 2748416 | 6403 | 8192 | 4.39168 | c9e1db24a7ce684cc81c587b8d8d394c |
| .bak | 2756608 | 6403 | 8192 | 4.37374 | 87cef8a7f0eb8c4e090ae4fd409ff296 |
| .bak | 2764800 | 6403 | 8192 | 4.40628 | 837264aba7d3acdcf938524b80b19439 |
| .bak | 2772992 | 6403 | 8192 | 4.28668 | d33b479bad9a4374fd90a7d5e3e02c18 |
| .bak | 2781184 | 6403 | 8192 | 4.39664 | 67478c29b9e2e2bfa3914fd3c19c17aa |
| .bak | 2789376 | 6403 | 8192 | 4.40733 | f9fa35e5a9bef47f83c7435f023bcaea |
| .bak | 2797568 | 6403 | 8192 | 4.38883 | 27888b15dde7c1db3657adedf20521eb |
| .bak | 2805760 | 6403 | 8192 | 4.33154 | 08a18cf6c69be5a6d1b689b270b55c45 |
| .bak | 2813952 | 6403 | 8192 | 4.40163 | 4fc2797de5334bb093880f9a24bd3dd6 |
| .bak | 2822144 | 6403 | 8192 | 4.41645 | 27c65c128f5e5143c781c3a703cbe81c |
| .bak | 2830336 | 6403 | 8192 | 4.36288 | 04ccecae62497c091370c9980066a0ec |
| .bak | 2838528 | 6403 | 8192 | 4.36997 | 5c999c2d755b0ec838ecf56b883104c9 |
| .bak | 2846720 | 6403 | 8192 | 4.39797 | 91d86d558e7811b39dded43f268e4f23 |
| .bak | 2854912 | 6403 | 8192 | 4.38341 | 62688e0d74b30d50dcb3ec1af93702e0 |
| .bak | 2863104 | 6403 | 8192 | 4.37007 | 0e7f5dd01be4801e0ab515e8281e6884 |
| .bak | 2871296 | 6403 | 8192 | 4.41067 | 7a1128f6b8639b1e7a76c54e94c2b474 |
| .bak | 2879488 | 6403 | 8192 | 4.39609 | db339bed9147ae0a2dd827874fc68496 |
| .bak | 2887680 | 6403 | 8192 | 4.38494 | 1254edadca037e1d0bd9444ce768afcc |
| .bak | 2895872 | 6403 | 8192 | 4.39282 | 729a543a293a1194f7fa49e202f025ac |
| .bak | 2904064 | 6403 | 8192 | 4.39696 | 9a0d909540689febfa1d2f996ad45364 |
| .bak | 2912256 | 6403 | 8192 | 4.4071 | 55d154dda64dad139b8bb09aa45ff6b3 |
| .bak | 2920448 | 6403 | 8192 | 4.41175 | 1eb0de4b25e95ef1d1102fc96f81bd71 |
| .bak | 2928640 | 6403 | 8192 | 4.25652 | 9d3d03401259cd982fec479657922f8b |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://rj.xie6.cn/gengxin.asp?id=845&bs=MAYI&_r=31114 | |
| hxxp://120.24.185.26/yixiuge/xxl.txt | |
| hxxp://rj.xie6.cn/dlldy.asp?cz=hqfwq&bs=MAYI | |
| hxxp://rj.xie6.cn/dlldy.asp?cz=hqzjip | |
| hxxp://im2.n.shifen.com/search/error.html | |
| hxxp://hi.baidu.com/aegifjftrggluze/item/be185dc989cae4f4984aa0df | |
| hxxp://im.baidu.com/search/error.html |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET POLICY Unsupported/Fake Windows NT Version 5.0
Traffic
GET /search/error.html HTTP/1.1
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0
Host: im.baidu.com
Cache-Control: no-cache
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 15 May 2017 16:10:51 GMT
Server: Apache
Last-Modified: Mon, 07 Dec 2015 10:58:51 GMT
ETag: "a92"
Accept-Ranges: bytes
Content-Length: 2706
Connection: Keep-Alive
Content-Type: text/html<html>.<head>..<title>....--..............</title
>..<META http-equiv=content-type content="text/html; charset=gb2
312">.<META content="MSHTML 6.00.2462.0" name=GENERATOR></
HEAD>.</head>.<style type="text/css">..p1 {..FONT-SIZE:
14px; LINE-HEIGHT: 24px; FONT-FAMILY: "....".}...f12 {..FONT-SIZE: 12
px; LINE-HEIGHT: 20px.}..p2 {..FONT-SIZE: 14px; LINE-HEIGHT: 24px; col
or: #333333.}.</style>.<body text=#000000 vLink=#0033cc aLink
=#800080 link=#0033cc bgColor=#ffffff .topMargin=0>.<center>.
<table width=650 border=0 align="center">. <tr height=60>
. <td width=139 valign="top" height="66"><a href="hXXps://
VVV.baidu.com"><img src="img/logo.gif" border="0"></a>&
lt;/td>. <td valign="bottom" width="100%">. <table
width="100%" border="0" cellpadding="0" cellspacing="0">. &
lt;tr bgcolor="#e5ecf9">. <td height="24"> <
b class="p1">..............</b></td>. <td h
eight="24" class="p2">. <div align="right"><a
href="hXXps://VVV.baidu.com">........</a> </div>
</td>. </tr>. <tr>. <td he
ight="20" class="p2" colspan="2"></td>. </tr>.
</table></td>. </tr>.</table>.<br>.&l
t;table width=650 border=0 align="center" cellpadding=8 cellspacing=0&
gt;. <tr> . <td align=center><div align="left"<<< skipped >>>
GET /gengxin.asp?id=845&bs=MAYI&_r=31114 HTTP/1.1
Accept: */*
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Cache-Control: no-cache
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET4.0C; .NET4.0E)
Host: rj.xie6.cn
HTTP/1.1 200 OK
Date: Mon, 15 May 2017 16:10:48 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=def4c611713752abe0eabf8024a3df3121494864647; expires=Tue, 15-May-18 16:10:47 GMT; path=/; domain=.xie6.cn; HttpOnly
Cache-Control: private
Vary: Accept-Encoding
Set-Cookie: ASPSESSIONIDACRBABCB=AJNNEIOAKOHEHOMEHOLIDDEG; path=/
X-Powered-By: ASP.NET
Server: yunjiasu-nginx
CF-RAY: 35f75e9056a64e2a-DMEe8..416B1BD09594E42FB1E8ADF1280D5C2B5AB6E09F50956C14DC636013AF636312D2
5D5BEE288489943286E61CDC686615DD646611D9116367D8166613DC116364DD686718
DC656217D8156712DC156367DD686718DC616660DC616718D8166619DD116411DD6267
67DD686618D8156710DD636611..0..HTTP/1.1 200 OK..Date: Mon, 15 May 2017
16:10:48 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Co
nnection: keep-alive..Set-Cookie: __cfduid=def4c611713752abe0eabf8024a
3df3121494864647; expires=Tue, 15-May-18 16:10:47 GMT; path=/; domain=
.xie6.cn; HttpOnly..Cache-Control: private..Vary: Accept-Encoding..Set
-Cookie: ASPSESSIONIDACRBABCB=AJNNEIOAKOHEHOMEHOLIDDEG; path=/..X-Powe
red-By: ASP.NET..Server: yunjiasu-nginx..CF-RAY: 35f75e9056a64e2a-DME.
.e8..416B1BD09594E42FB1E8ADF1280D5C2B5AB6E09F50956C14DC636013AF636312D
25D5BEE288489943286E61CDC686615DD646611D9116367D8166613DC116364DD68671
8DC656217D8156712DC156367DD686718DC616660DC616718D8166619DD116411DD626
767DD686618D8156710DD636611..0......
GET /dlldy.asp?cz=hqfwq&bs=MAYI HTTP/1.1
Accept: */*
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Cache-Control: no-cache
User-Agent: 30098
Host: rj.xie6.cn
Cookie: __cfduid=def4c611713752abe0eabf8024a3df3121494864647; ASPSESSIONIDACRBABCB=AJNNEIOAKOHEHOMEHOLIDDEG
HTTP/1.1 200 OK
Date: Mon, 15 May 2017 16:10:50 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: private
Vary: Accept-Encoding
Set-Cookie: ASPSESSIONIDAQCCBCDD=HBBGIMLABLFLAMCBHJOBEMBL; path=/
X-Powered-By: ASP.NET
Server: yunjiasu-nginx
CF-RAY: 35f75ea0a6554e2a-DME2b..ok:222.186.56.243:5600|222.186.56.243:5500|..0......
GET /dlldy.asp?cz=hqzjip HTTP/1.1
Accept: */*
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Host: rj.xie6.cn
Cookie: __cfduid=def4c611713752abe0eabf8024a3df3121494864647; ASPSESSIONIDACRBABCB=AJNNEIOAKOHEHOMEHOLIDDEG; ASPSESSIONIDAQCCBCDD=HBBGIMLABLFLAMCBHJOBEMBL
HTTP/1.1 200 OK
Date: Mon, 15 May 2017 16:10:51 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: private
Vary: Accept-Encoding
X-Powered-By: ASP.NET
Server: yunjiasu-nginx
CF-RAY: 35f75ea4d23b4e2a-DME11..ip:194.242.96.218..0..HTTP/1.1 200 OK..Date: Mon, 15 May 2017 16:1
0:51 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Connect
ion: keep-alive..Cache-Control: private..Vary: Accept-Encoding..X-Powe
red-By: ASP.NET..Server: yunjiasu-nginx..CF-RAY: 35f75ea4d23b4e2a-DME.
.11..ip:194.242.96.218..0..
GET /yixiuge/xxl.txt HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Accept: */*
Host: 120.24.185.26
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Server: nginx
Date: Mon, 15 May 2017 16:11:03 GMT
Content-Type: text/html
Content-Length: 564
Connection: keep-alive
Vary: Accept-Encoding<html>..<head><title>404 Not Found</title><
/head>..<body bgcolor="white">..<center><h1>404 N
ot Found</h1></center>..<hr><center>nginx</
center>..</body>..</html>..<!-- a padding to disable
MSIE and Chrome friendly error page -->..<!-- a padding to disa
ble MSIE and Chrome friendly error page -->..<!-- a padding to d
isable MSIE and Chrome friendly error page -->..<!-- a padding t
o disable MSIE and Chrome friendly error page -->..<!-- a paddin
g to disable MSIE and Chrome friendly error page -->..<!-- a pad
ding to disable MSIE and Chrome friendly error page -->..HTTP/1.1 4
04 Not Found..Server: nginx..Date: Mon, 15 May 2017 16:11:03 GMT..Cont
ent-Type: text/html..Content-Length: 564..Connection: keep-alive..Vary
: Accept-Encoding..<html>..<head><title>404 Not Foun
d</title></head>..<body bgcolor="white">..<center
><h1>404 Not Found</h1></center>..<hr><c
enter>nginx</center>..</body>..</html>..<!-- a
padding to disable MSIE and Chrome friendly error page -->..<!-
- a padding to disable MSIE and Chrome friendly error page -->..<
;!-- a padding to disable MSIE and Chrome friendly error page -->..
<!-- a padding to disable MSIE and Chrome friendly error page -->
;..<!-- a padding to disable MSIE and Chrome friendly error page --
>..<!-- a padding to disable MSIE and Chrome friendly error<<< skipped >>>
GET /aegifjftrggluze/item/be185dc989cae4f4984aa0df HTTP/1.1
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0
Host: hi.baidu.com
Cache-Control: no-cache
HTTP/1.1 302 Found
Date: Mon, 15 May 2017 16:10:48 GMT
Server: Apache
Location: hXXp://im.baidu.com/search/error.html
Content-Length: 221
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html>&
lt;head>.<title>302 Found</title>.</head><body
>.<h1>Found</h1>.<p>The document has moved <a
href="hXXp://im.baidu.com/search/error.html">here</a>.</p&
gt;.</body></html>.HTTP/1.1 302 Found..Date: Mon, 15 May 2
017 16:10:48 GMT..Server: Apache..Location: hXXp://im.baidu.com/search
/error.html..Content-Length: 221..Connection: Keep-Alive..Content-Type
: text/html; charset=iso-8859-1..<!DOCTYPE HTML PUBLIC "-//IETF//DT
D HTML 2.0//EN">.<html><head>.<title>302 Found<
;/title>.</head><body>.<h1>Found</h1>.<p
>The document has moved <a href="hXXp://im.baidu.com/search/erro
r.html">here</a>.</p>.</body></html>...
The Dropped connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
@.bak
t$(SSh
~%UVW
u$SShe
iu2.iu
K(.wS
user32.dll
gdiplus.dll
{A068799B-7551-46b9-8CA8-EEF8357AFEA4}hXXp://120.24.185.26/yixiuge/xxl.txt
Proxy.dll
Kernel32.dll
kernel32.dll
\CDM.exe
software\microsoft\windows\CurrentVersion\Run\
\Proxy.dll
@.reloc
f9z.vk
__MSVCRT_HEAP_SELECT
CreateIoCompletionPort
GetProcessHeap
KERNEL32.dll
MsgWaitForMultipleObjects
USER32.dll
GDI32.dll
ADVAPI32.dll
ole32.dll
WS2_32.dll
SHLWAPI.dll
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
WININET.dll
OLEAUT32.dll
WINMM.dll
GetCPInfo
proxy_AA555.dll
8@HNetCfg.FwMgr
hXXps://
hXXp://
https
http:
Client: VVV.xie6.cn
https:
HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
/gengxin.asp?id=
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET4.0C; .NET4.0E)
@/dlldy.asp?cz=hqfwq&bs=MAYI
/dlldy.asp?cz=hqzjip
4@0.0.0.0
<@WinINet.dll
ws2_32.dll
urlmon
URLDownloadToFileA
program internal error number is %d.
%s%x.tmp
:"%s"
:"%s".
zcÁ
7!8 808:8
0#0 040=0
5$5(5,5054585<5@5
$0004080
%d&&'
123456789
00003333
deflate 1.1.3 Copyright 1995-1998 Jean-loup Gailly
inflate 1.1.3 Copyright 1995-1998 Mark Adler
%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
Broken pipe
Inappropriate I/O control operation
Operation not permitted
RASAPI32.dll
WinExec
GetKeyState
GetViewportOrgEx
WINSPOOL.DRV
RegCloseKey
RegOpenKeyExA
RegCreateKeyA
ShellExecuteA
SHELL32.dll
COMCTL32.dll
CreateDialogIndirectParamA
UnhookWindowsHookEx
SetWindowsHookExA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportExtEx
comdlg32.dll
RegCreateKeyExA
.PAVCException@@
Shell32.dll
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
.PAVCFileException@@
: %d]
(*.*)|*.*||
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|PNG
(*.PNG)|*.PNG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
%s:%d
windows
.PAVCNotSupportedException@@
out.prn
(*.prn)|*.prn|
%d.%d
%d/%d
1.6.9
unsupported zlib version
png_read_image: unsupported transformation
%d / %d
Bogus message code %d
libpng error: %s
libpng warning: %s
1.1.3
bad keyword
libpng does not support gamma background rgb_to_gray
Palette is NULL in indexed image
(%d-%d):
%ld%c
;3 #>6.&
'2, / 0&7!4-)1#
%s <%s>
Reply-To: %s
From: %s
To: %s
Subject: %s
Date: %s
Cc: %s
%a, %d %b %Y %H:%M:%S
SMTP
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCArchiveException@@
#include "l.chs\afxres.rc" // Standard components
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADC:\CDM.exe
VVV.168guaji.com
1.2.18
F%*.*f
MSWHEEL_ROLLMSG
MSVFW32.dll
AVIFIL32.dll
InternetCrackUrlA
InternetCanonicalizeUrlA
(*.avi)|*.avi
WPFT532.CNV
WPFT632.CNV
EXCEL32.CNV
write32.wpc
Windows Write
mswrd632.wpc
Word for Windows 6.0
wword5.cnv
Word for Windows 5.0
mswrd832.cnv
mswrd632.cnv
Word 6.0/95 for Windows & Macintosh
html32.cnv
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
HTTP/1.0
c:\%original file name%.exe
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
%S'vSG$wL"'vHN0rH&<
F.VnQ2
f.La1}ONz.
,vPK85\K82EV$rME5jMI:1\K8%U
aqt%v(1!gjezjf|9.sa%n{r4v{~;-jy!o~:-o~=4rb}<ase<m|>-o~*$?"?l.8>.yyh"
z$5."$%X{}zGx%}//v~&.dUz;,D`:?S;(%Fr
".dUz;-D/{89.dUz; D/{.8<(&8=):
.vcH~
:j%c;n
.Sz~XGy
!H}~JJ:$GMldAN:$/.adACe~/-bsGC{%%uPZW
%uN|-
O:J%S2
qvyB4>~b.pr]i.6
tT.zc
&nfY.}wA.qx
d.eMD
mdS%sfG
`{LxE%s..skt
ZzY[.UQ
z_[.UQ
.PIZ(
AUrl/
Up0%xs
8U.Ix
.GiD}DF
%.bqA@D}[GNp
UúS
$H;%f
m.XQs,L
c.jK%Q
c/qC%s0Dxw>
4k{5#$q>;%s41ct;0~`61fg 3%{%3g=33;*d2i iois4bl&hn>s0fntQ>httpu
hTTP/h
hXXp://hi.baidu.com/aegifjftrggluze/item/be185dc989cae4f4984aa0df
baidu.com
1.6.2.1
(*.*)
1.0.0.0
(hXXp://VVV.dywt.com.cn)
%original file name%.exe_2180_rwx_006CB000_00002000:
>httpu
hTTP/h
hXXp://hi.baidu.com/aegifjftrggluze/item/be185dc989cae4f4984aa0df
baidu.com
CDM.exe_3436:
.text
`.rdata
@.data
.rsrc
t$(SSh
~%UVW
u$SShe
iu2.iu
K(.wS
Proxy.dll
Kernel32.dll
kernel32.dll
user32.dll
gdiplus.dll
{A068799B-7551-46b9-8CA8-EEF8357AFEA4}\CDM.exe
software\microsoft\windows\CurrentVersion\Run\
\Proxy.dll
@.reloc
f9z.vk
__MSVCRT_HEAP_SELECT
CreateIoCompletionPort
GetProcessHeap
KERNEL32.dll
MsgWaitForMultipleObjects
USER32.dll
GDI32.dll
ADVAPI32.dll
ole32.dll
WS2_32.dll
SHLWAPI.dll
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
WININET.dll
OLEAUT32.dll
WINMM.dll
GetCPInfo
proxy_AA555.dll
8@HNetCfg.FwMgr
hXXps://
hXXp://
https
http:
Client: VVV.xie6.cn
https:
HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
/gengxin.asp?id=
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET4.0C; .NET4.0E)
@/dlldy.asp?cz=hqfwq&bs=MAYI
/dlldy.asp?cz=hqzjip
4@0.0.0.0
<@WinINet.dll
ws2_32.dll
urlmon
URLDownloadToFileA
program internal error number is %d.
%s%x.tmp
:"%s"
:"%s".
zcÁ
7!8 808:8
0#0 040=0
5$5(5,5054585<5@5
$0004080
%d&&'
123456789
00003333
deflate 1.1.3 Copyright 1995-1998 Jean-loup Gailly
inflate 1.1.3 Copyright 1995-1998 Mark Adler
%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
Broken pipe
Inappropriate I/O control operation
Operation not permitted
RASAPI32.dll
WinExec
GetKeyState
GetViewportOrgEx
WINSPOOL.DRV
RegCloseKey
RegOpenKeyExA
RegCreateKeyA
ShellExecuteA
SHELL32.dll
COMCTL32.dll
CreateDialogIndirectParamA
UnhookWindowsHookEx
SetWindowsHookExA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportExtEx
comdlg32.dll
RegCreateKeyExA
.PAVCException@@
Shell32.dll
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
.PAVCFileException@@
: %d]
(*.*)|*.*||
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|PNG
(*.PNG)|*.PNG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
%s:%d
windows
.PAVCNotSupportedException@@
out.prn
(*.prn)|*.prn|
%d.%d
%d/%d
1.6.9
unsupported zlib version
png_read_image: unsupported transformation
%d / %d
Bogus message code %d
libpng error: %s
libpng warning: %s
1.1.3
bad keyword
libpng does not support gamma background rgb_to_gray
Palette is NULL in indexed image
(%d-%d):
%ld%c
;3 #>6.&
'2, / 0&7!4-)1#
%s <%s>
Reply-To: %s
From: %s
To: %s
Subject: %s
Date: %s
Cc: %s
%a, %d %b %Y %H:%M:%S
SMTP
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCArchiveException@@
C:\CDM.exe
#include "l.chs\afxres.rc" // Standard components
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
1.6.2.1
(*.*)
1.0.0.0
(hXXp://VVV.dywt.com.cn)
%original file name%.exe_2180_rwx_01580000_00002000:
>httpu
hTTP/h
hXXp://hi.baidu.com/aegifjftrggluze/item/be185dc989cae4f4984aa0df
baidu.com
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
CDM.exe:3436
- Delete the original Dropped file.
- Delete or disinfect the following files created/modified by the Dropped:
C:\%original file name%.exe (18248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\error[1].htm (2704 bytes)
C:\CDM.exe (1810 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\dlldy[1].htm (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gengxin[1].htm (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\dlldy[1].htm (17 bytes)
C:\Proxy.dll (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UVH22G43.txt (109 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Î񵀮ô¶¯ÃÂî" = "C:\CDM.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.