Dropped.Trojan.Generic.20281016_b03464cb3b

by malwarelabrobot on May 16th, 2017 in Malware Descriptions.

Dropped:Trojan.Generic.20281016 (B) (Emsisoft), Dropped:Trojan.Generic.20281016 (AdAware), Trojan.Win32.FlyStudio.FD, GenericEmailWorm.YR, TrojanFlyStudio.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, EmailWorm


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: b03464cb3b39f6eef19436344224d9bc
SHA1: 82227729be2dbfb22a283b1793717102acd30b7d
SHA256: 8a6ac87aef1b02ab59e037254e28ec8963bb5d46f384f619f56c8786ef4563d5
SSDeep: 49152:wwPcDMe0FNDMTTwr92yjAdxD uYRUAiuoaGGn5sQXi:fP8Me0fMv0UyjAdxD nqSDsQXi
Size: 2678784 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6, MicrosoftVisualC, MicrosoftVisualCv50v60MFC, MicrosoftVisualC50, Armadillov171
Company: no certificate found
Created at: 2017-01-15 22:22:06
Analyzed on: Windows7 SP1 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

Behaviour Description
EmailWorm Worm can send e-mails.


Process activity

The Dropped creates the following process(es):

CDM.exe:3436

The Dropped injects its code into the following process(es):

%original file name%.exe:2180

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process %original file name%.exe:2180 makes changes in the file system.
The Dropped creates and/or writes to the following file(s):

C:\%original file name%.exe (18248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\error[1].htm (2704 bytes)
C:\CDM.exe (1810 bytes)

The process CDM.exe:3436 makes changes in the file system.
The Dropped creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\dlldy[1].htm (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gengxin[1].htm (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\dlldy[1].htm (17 bytes)
C:\Proxy.dll (326 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UVH22G43.txt (109 bytes)

Registry activity

The process %original file name%.exe:2180 makes changes in the system registry.
The Dropped creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASMANCS]
"EnableFileTracing" = "0"
"FileTracingMask" = "4294901760"
"ConsoleTracingMask" = "4294901760"
"MaxFileSize" = "1048576"

[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASAPI32]
"EnableConsoleTracing" = "0"
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"

[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASMANCS]
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3C 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASMANCS]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\b03464cb3b39f6eef19436344224d9bc_RASAPI32]
"EnableFileTracing" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Dropped deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process CDM.exe:3436 makes changes in the system registry.
The Dropped creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"EnableFileTracing" = "0"
"FileTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASMANCS]
"ConsoleTracingMask" = "4294901760"

"FileTracingMask" = "4294901760"
"EnableFileTracing" = "0"
"EnableConsoleTracing" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3D 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASAPI32]
"MaxFileSize" = "1048576"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASAPI32]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\CDM_RASMANCS]
"MaxFileSize" = "1048576"
"FileDirectory" = "%windir%\tracing"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

To automatically run itself each time Windows is booted, the Dropped adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Î񵀮ô¶¯Ïî" = "C:\CDM.exe"

The Dropped deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

Dropped PE files

MD5 File path
beb1ea045490ba658f11b9f564e50068 c:\CDM.exe
2ac708267bb532ad405adaa1af140eec c:\Program Files\VMware\VMware Tools\VMwareTray.exe.bak
65eca73f39f1c9d671519035e0585314 c:\Proxy.dll
c187f718b9f4bbe6813b51e3b0eb87e3 c:\%original file name%.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name:
Product Name: ?????
Product Version: 1.0.0.0
Legal Copyright: ?????? ????????
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.0.0
File Description: ?????
Comments: ??????????(http://www.dywt.com.cn)
Language: Chinese (Simplified, PRC)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 686982 688128 4.52934 ab0706c97bedce50507da9e0f5474db1
.rdata 692224 1085098 1085440 4.25681 9c9475af0aeffa6c70a0310060ee77ad
.data 1777664 363912 106496 3.65446 534e0dfb12fe425c6d5957bfc67c4405
.rsrc 2142208 94420 98304 3.62674 9f6d5518b0bcabefd81cd94237b0fd08
.bak 2240512 6403 8192 4.38113 4eb3f35c8bf55823feb258ef493c0849
.bak 2248704 6403 8192 4.37507 7a0b8d43cfcdd0b346898197f1cc0b68
.bak 2256896 6403 8192 4.40826 c4c732ab5a318c6039e5babf1016a0b9
.bak 2265088 6403 8192 4.39516 7d90b9376b771ebe2e18ea04eeef2da0
.bak 2273280 6403 8192 4.40941 f3a6a21cf8a6915bf1414daabf1436db
.bak 2281472 6403 8192 4.32451 6327d4ac0975cfc2cb9126f5e722e11e
.bak 2289664 6403 8192 4.38369 11868f342ad19f03e2964f5c63de6a4c
.bak 2297856 6403 8192 4.40462 a2b1ca2532daa29f039dbdee7422dd46
.bak 2306048 6403 8192 4.33146 1e5c99ee9cbca3f197b0e1c5bbf46e4e
.bak 2314240 6403 8192 4.41334 59dc7a5e1b4d7afa753de9acd13a61e3
.bak 2322432 6403 8192 4.35977 01aae6158fbebaf9410e5ebfc4aed164
.bak 2330624 6403 8192 4.29377 d8029b4ad637c3172d4a486f439a3430
.bak 2338816 6403 8192 4.36712 c674cde4bafe27312891fb1e02a965c3
.bak 2347008 6403 8192 4.40381 16eeb5bff577478403deb5ff53026b0d
.bak 2355200 6403 8192 4.40262 c1837c80162fbb8aac38d5d35de52b59
.bak 2363392 6403 8192 4.39975 facd56c3fda10c87aab7ce2241166cfa
.bak 2371584 6403 8192 4.36125 13e9a4827d0a8fdfe191282b519661dd
.bak 2379776 6403 8192 4.3845 d8c01ebb01fd80b3889186c86e15d647
.bak 2387968 6403 8192 4.37363 fe7a22fbdf4cc1fe06b64d5a322b75d7
.bak 2396160 6403 8192 4.39039 9751a79b58c9ef503ccb1180f54d3991
.bak 2404352 6403 8192 4.40671 4d16a99a01b997fc5c534aa1af0e85f5
.bak 2412544 6403 8192 4.36217 cf90f784da78545d4f2e66d1e4d355be
.bak 2420736 6403 8192 4.3897 b5ae8dc650df0600c4cf48cf152e90fc
.bak 2428928 6403 8192 4.39471 630e10ce48a5bb80948684bff0093c0a
.bak 2437120 6403 8192 4.39011 2e223f2f6a5bd87f867ad23b5631fda4
.bak 2445312 6403 8192 4.35558 4833cf89f70ac9a1ad5acfe7875f2222
.bak 2453504 6403 8192 4.30352 878a30e724a68f6f207c6b0b333374dd
.bak 2461696 6403 8192 4.35721 6fce5ae996cf2c1b02a949e8297dbb34
.bak 2469888 6403 8192 4.39586 4f776ad5e904560b7b1beba74eb42aa2
.bak 2478080 6403 8192 4.34614 789d622c3f632a0b34737a8e68c508a9
.bak 2486272 6403 8192 4.41374 1b52151f5e7dfbcd35e25c8bfcf24b33
.bak 2494464 6403 8192 4.33752 0e052cf915bf233a70cf71977d14a020
.bak 2502656 6403 8192 4.33453 49b43ccc24714bcb89c97b1ab2ea35ba
.bak 2510848 6403 8192 4.36256 ff56a9b4e6dd17810a331699457eced2
.bak 2519040 6403 8192 4.39543 30ebbcd4bf4ae45ee4966a81460be0e9
.bak 2527232 6403 8192 4.37961 1f374ccac86a0d4061271aaf7b72f889
.bak 2535424 6403 8192 4.39373 9fbe75c1843fbc1e33cbbbec53059049
.bak 2543616 6403 8192 4.38681 f533136265bec1c9529022764f477b87
.bak 2551808 6403 8192 4.40418 46e39545b5578e848a576a75ae426f6d
.bak 2560000 6403 8192 4.3933 9cd3444587310abeb309d35bc99f3275
.bak 2568192 6403 8192 4.41648 19c28bb84df067d25595ec7f7c6d7c3d
.bak 2576384 6403 8192 4.39337 2bb4214af4bb4d6fd5aa53c3f70d844f
.bak 2584576 6403 8192 4.42723 47d70604abb22a4330b5f1daf84e660d
.bak 2592768 6403 8192 4.40041 c1d29c684b207b1279505b3109940b40
.bak 2600960 6403 8192 4.35812 f02bc1c516dda2eb650f5aa3e4678c4a
.bak 2609152 6403 8192 4.36857 f87127e63b944e26240d14d62937f9e9
.bak 2617344 6403 8192 4.41511 f498446dfae80da9a13b4a3bf5c9941e
.bak 2625536 6403 8192 4.36551 2bf8cbf8acd9c04ceefa96b13b24753b
.bak 2633728 6403 8192 4.35017 7873619523a31c4642851de759150714
.bak 2641920 6403 8192 4.38499 03bee09979133841fffbd8429fc852b9
.bak 2650112 6403 8192 4.42283 47fdbe72a68a6843dcbd0c6656432c20
.bak 2658304 6403 8192 4.33423 45a4b8360c856d9334db987e89edf25c
.bak 2666496 6403 8192 4.33416 aa34dfdbbab16c5e63ec0b495e2ed125
.bak 2674688 6403 8192 4.36392 a929ead532a61896227b71da4396a8e5
.bak 2682880 6403 8192 4.35125 a7b47bcd13f83b1218df0715a7f8ac57
.bak 2691072 6403 8192 4.39885 5656ec91423d3133ff77bade66b7f18a
.bak 2699264 6403 8192 4.40442 81782588c7c8effa2b83f99a57c9993e
.bak 2707456 6403 8192 4.40022 c0526e2203c682c371dd813a990b4518
.bak 2715648 6403 8192 4.42288 e21356522e1b949f1c0846303fe46cae
.bak 2723840 6403 8192 4.39322 bc6f945b1305e93a59397f342a1d76d0
.bak 2732032 6403 8192 4.39672 6d63a9d9182a44ec2af3033f3e36f2c2
.bak 2740224 6403 8192 4.40175 177f0767636faed1d31eb1b7ea4c2b1b
.bak 2748416 6403 8192 4.39168 c9e1db24a7ce684cc81c587b8d8d394c
.bak 2756608 6403 8192 4.37374 87cef8a7f0eb8c4e090ae4fd409ff296
.bak 2764800 6403 8192 4.40628 837264aba7d3acdcf938524b80b19439
.bak 2772992 6403 8192 4.28668 d33b479bad9a4374fd90a7d5e3e02c18
.bak 2781184 6403 8192 4.39664 67478c29b9e2e2bfa3914fd3c19c17aa
.bak 2789376 6403 8192 4.40733 f9fa35e5a9bef47f83c7435f023bcaea
.bak 2797568 6403 8192 4.38883 27888b15dde7c1db3657adedf20521eb
.bak 2805760 6403 8192 4.33154 08a18cf6c69be5a6d1b689b270b55c45
.bak 2813952 6403 8192 4.40163 4fc2797de5334bb093880f9a24bd3dd6
.bak 2822144 6403 8192 4.41645 27c65c128f5e5143c781c3a703cbe81c
.bak 2830336 6403 8192 4.36288 04ccecae62497c091370c9980066a0ec
.bak 2838528 6403 8192 4.36997 5c999c2d755b0ec838ecf56b883104c9
.bak 2846720 6403 8192 4.39797 91d86d558e7811b39dded43f268e4f23
.bak 2854912 6403 8192 4.38341 62688e0d74b30d50dcb3ec1af93702e0
.bak 2863104 6403 8192 4.37007 0e7f5dd01be4801e0ab515e8281e6884
.bak 2871296 6403 8192 4.41067 7a1128f6b8639b1e7a76c54e94c2b474
.bak 2879488 6403 8192 4.39609 db339bed9147ae0a2dd827874fc68496
.bak 2887680 6403 8192 4.38494 1254edadca037e1d0bd9444ce768afcc
.bak 2895872 6403 8192 4.39282 729a543a293a1194f7fa49e202f025ac
.bak 2904064 6403 8192 4.39696 9a0d909540689febfa1d2f996ad45364
.bak 2912256 6403 8192 4.4071 55d154dda64dad139b8bb09aa45ff6b3
.bak 2920448 6403 8192 4.41175 1eb0de4b25e95ef1d1102fc96f81bd71
.bak 2928640 6403 8192 4.25652 9d3d03401259cd982fec479657922f8b

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://rj.xie6.cn/gengxin.asp?id=845&bs=MAYI&_r=31114 162.159.211.13
hxxp://120.24.185.26/yixiuge/xxl.txt
hxxp://rj.xie6.cn/dlldy.asp?cz=hqfwq&bs=MAYI 162.159.211.13
hxxp://rj.xie6.cn/dlldy.asp?cz=hqzjip 162.159.211.13
hxxp://im2.n.shifen.com/search/error.html
hxxp://hi.baidu.com/aegifjftrggluze/item/be185dc989cae4f4984aa0df 123.125.114.169
hxxp://im.baidu.com/search/error.html 123.125.114.169


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET POLICY Unsupported/Fake Windows NT Version 5.0

Traffic

GET /search/error.html HTTP/1.1
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0
Host: im.baidu.com
Cache-Control: no-cache
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 15 May 2017 16:10:51 GMT
Server: Apache
Last-Modified: Mon, 07 Dec 2015 10:58:51 GMT
ETag: "a92"
Accept-Ranges: bytes
Content-Length: 2706
Connection: Keep-Alive
Content-Type: text/html
<html>.<head>..<title>....--..............</title
>..<META http-equiv=content-type content="text/html; charset=gb2
312">.<META content="MSHTML 6.00.2462.0" name=GENERATOR></
HEAD>.</head>.<style type="text/css">..p1 {..FONT-SIZE:
14px; LINE-HEIGHT: 24px; FONT-FAMILY: "....".}...f12 {..FONT-SIZE: 12
px; LINE-HEIGHT: 20px.}..p2 {..FONT-SIZE: 14px; LINE-HEIGHT: 24px; col
or: #333333.}.</style>.<body text=#000000 vLink=#0033cc aLink
=#800080 link=#0033cc bgColor=#ffffff .topMargin=0>.<center>.
<table width=650 border=0 align="center">. <tr height=60>
. <td width=139 valign="top" height="66"><a href="hXXps://
VVV.baidu.com"><img src="img/logo.gif" border="0"></a>&
lt;/td>. <td valign="bottom" width="100%">. <table
width="100%" border="0" cellpadding="0" cellspacing="0">. &
lt;tr bgcolor="#e5ecf9">. <td height="24"> <
b class="p1">..............</b></td>. <td h
eight="24" class="p2">. <div align="right"><a
href="hXXps://VVV.baidu.com">........</a>  </div>
</td>. </tr>. <tr>. <td he
ight="20" class="p2" colspan="2"></td>. </tr>.
</table></td>. </tr>.</table>.<br>.&l
t;table width=650 border=0 align="center" cellpadding=8 cellspacing=0&
gt;. <tr> . <td align=center><div align="left"

<<< skipped >>>

GET /gengxin.asp?id=845&bs=MAYI&_r=31114 HTTP/1.1
Accept: */*
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Cache-Control: no-cache
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET4.0C; .NET4.0E)
Host: rj.xie6.cn


HTTP/1.1 200 OK
Date: Mon, 15 May 2017 16:10:48 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=def4c611713752abe0eabf8024a3df3121494864647; expires=Tue, 15-May-18 16:10:47 GMT; path=/; domain=.xie6.cn; HttpOnly
Cache-Control: private
Vary: Accept-Encoding
Set-Cookie: ASPSESSIONIDACRBABCB=AJNNEIOAKOHEHOMEHOLIDDEG; path=/
X-Powered-By: ASP.NET
Server: yunjiasu-nginx
CF-RAY: 35f75e9056a64e2a-DME
e8..416B1BD09594E42FB1E8ADF1280D5C2B5AB6E09F50956C14DC636013AF636312D2
5D5BEE288489943286E61CDC686615DD646611D9116367D8166613DC116364DD686718
DC656217D8156712DC156367DD686718DC616660DC616718D8166619DD116411DD6267
67DD686618D8156710DD636611..0..HTTP/1.1 200 OK..Date: Mon, 15 May 2017
16:10:48 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Co
nnection: keep-alive..Set-Cookie: __cfduid=def4c611713752abe0eabf8024a
3df3121494864647; expires=Tue, 15-May-18 16:10:47 GMT; path=/; domain=
.xie6.cn; HttpOnly..Cache-Control: private..Vary: Accept-Encoding..Set
-Cookie: ASPSESSIONIDACRBABCB=AJNNEIOAKOHEHOMEHOLIDDEG; path=/..X-Powe
red-By: ASP.NET..Server: yunjiasu-nginx..CF-RAY: 35f75e9056a64e2a-DME.
.e8..416B1BD09594E42FB1E8ADF1280D5C2B5AB6E09F50956C14DC636013AF636312D
25D5BEE288489943286E61CDC686615DD646611D9116367D8166613DC116364DD68671
8DC656217D8156712DC156367DD686718DC616660DC616718D8166619DD116411DD626
767DD686618D8156710DD636611..0..
....



GET /dlldy.asp?cz=hqfwq&bs=MAYI HTTP/1.1

Accept: */*
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Cache-Control: no-cache
User-Agent: 30098
Host: rj.xie6.cn
Cookie: __cfduid=def4c611713752abe0eabf8024a3df3121494864647; ASPSESSIONIDACRBABCB=AJNNEIOAKOHEHOMEHOLIDDEG


HTTP/1.1 200 OK
Date: Mon, 15 May 2017 16:10:50 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: private
Vary: Accept-Encoding
Set-Cookie: ASPSESSIONIDAQCCBCDD=HBBGIMLABLFLAMCBHJOBEMBL; path=/
X-Powered-By: ASP.NET
Server: yunjiasu-nginx
CF-RAY: 35f75ea0a6554e2a-DME
2b..ok:222.186.56.243:5600|222.186.56.243:5500|..0......



GET /dlldy.asp?cz=hqzjip HTTP/1.1

Accept: */*
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Host: rj.xie6.cn
Cookie: __cfduid=def4c611713752abe0eabf8024a3df3121494864647; ASPSESSIONIDACRBABCB=AJNNEIOAKOHEHOMEHOLIDDEG; ASPSESSIONIDAQCCBCDD=HBBGIMLABLFLAMCBHJOBEMBL


HTTP/1.1 200 OK
Date: Mon, 15 May 2017 16:10:51 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: private
Vary: Accept-Encoding
X-Powered-By: ASP.NET
Server: yunjiasu-nginx
CF-RAY: 35f75ea4d23b4e2a-DME
11..ip:194.242.96.218..0..HTTP/1.1 200 OK..Date: Mon, 15 May 2017 16:1
0:51 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Connect
ion: keep-alive..Cache-Control: private..Vary: Accept-Encoding..X-Powe
red-By: ASP.NET..Server: yunjiasu-nginx..CF-RAY: 35f75ea4d23b4e2a-DME.
.11..ip:194.242.96.218..0..


GET /yixiuge/xxl.txt HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Accept: */*
Host: 120.24.185.26
Cache-Control: no-cache


HTTP/1.1 404 Not Found
Server: nginx
Date: Mon, 15 May 2017 16:11:03 GMT
Content-Type: text/html
Content-Length: 564
Connection: keep-alive
Vary: Accept-Encoding
<html>..<head><title>404 Not Found</title><
/head>..<body bgcolor="white">..<center><h1>404 N
ot Found</h1></center>..<hr><center>nginx</
center>..</body>..</html>..<!-- a padding to disable
MSIE and Chrome friendly error page -->..<!-- a padding to disa
ble MSIE and Chrome friendly error page -->..<!-- a padding to d
isable MSIE and Chrome friendly error page -->..<!-- a padding t
o disable MSIE and Chrome friendly error page -->..<!-- a paddin
g to disable MSIE and Chrome friendly error page -->..<!-- a pad
ding to disable MSIE and Chrome friendly error page -->..HTTP/1.1 4
04 Not Found..Server: nginx..Date: Mon, 15 May 2017 16:11:03 GMT..Cont
ent-Type: text/html..Content-Length: 564..Connection: keep-alive..Vary
: Accept-Encoding..<html>..<head><title>404 Not Foun
d</title></head>..<body bgcolor="white">..<center
><h1>404 Not Found</h1></center>..<hr><c
enter>nginx</center>..</body>..</html>..<!-- a
padding to disable MSIE and Chrome friendly error page -->..<!-
- a padding to disable MSIE and Chrome friendly error page -->..<
;!-- a padding to disable MSIE and Chrome friendly error page -->..
<!-- a padding to disable MSIE and Chrome friendly error page -->
;..<!-- a padding to disable MSIE and Chrome friendly error page --
>..<!-- a padding to disable MSIE and Chrome friendly error

<<< skipped >>>

GET /aegifjftrggluze/item/be185dc989cae4f4984aa0df HTTP/1.1
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:16.0) Gecko/20100101 Firefox/16.0
Host: hi.baidu.com
Cache-Control: no-cache


HTTP/1.1 302 Found
Date: Mon, 15 May 2017 16:10:48 GMT
Server: Apache
Location: hXXp://im.baidu.com/search/error.html
Content-Length: 221
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html>&
lt;head>.<title>302 Found</title>.</head><body
>.<h1>Found</h1>.<p>The document has moved <a
href="hXXp://im.baidu.com/search/error.html">here</a>.</p&
gt;.</body></html>.HTTP/1.1 302 Found..Date: Mon, 15 May 2
017 16:10:48 GMT..Server: Apache..Location: hXXp://im.baidu.com/search
/error.html..Content-Length: 221..Connection: Keep-Alive..Content-Type
: text/html; charset=iso-8859-1..<!DOCTYPE HTML PUBLIC "-//IETF//DT
D HTML 2.0//EN">.<html><head>.<title>302 Found<
;/title>.</head><body>.<h1>Found</h1>.<p
>The document has moved <a href="hXXp://im.baidu.com/search/erro
r.html">here</a>.</p>.</body></html>...


The Dropped connects to the servers at the folowing location(s):

%original file name%.exe_2180:

.text
`.rdata
@.data
.rsrc
@.bak
t$(SSh
~%UVW
u$SShe
iu2.iu
K(.wS
user32.dll
gdiplus.dll
{A068799B-7551-46b9-8CA8-EEF8357AFEA4}
hXXp://120.24.185.26/yixiuge/xxl.txt
Proxy.dll
Kernel32.dll
kernel32.dll
\CDM.exe
software\microsoft\windows\CurrentVersion\Run\
\Proxy.dll
@.reloc
f9z.vk
__MSVCRT_HEAP_SELECT
CreateIoCompletionPort
GetProcessHeap
KERNEL32.dll
MsgWaitForMultipleObjects
USER32.dll
GDI32.dll
ADVAPI32.dll
ole32.dll
WS2_32.dll
SHLWAPI.dll
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
WININET.dll
OLEAUT32.dll
WINMM.dll
GetCPInfo
proxy_AA555.dll
8@HNetCfg.FwMgr
hXXps://
hXXp://
https
http:
Client: VVV.xie6.cn
https:
HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
/gengxin.asp?id=
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET4.0C; .NET4.0E)
@/dlldy.asp?cz=hqfwq&bs=MAYI
/dlldy.asp?cz=hqzjip
4@0.0.0.0
<@WinINet.dll
ws2_32.dll
urlmon
URLDownloadToFileA
program internal error number is %d.
%s%x.tmp
:"%s"
:"%s".
zcÁ
7!8 808:8
0#0 040=0
5$5(5,5054585<5@5
$0004080
%d&&'
123456789
00003333
deflate 1.1.3 Copyright 1995-1998 Jean-loup Gailly
inflate 1.1.3 Copyright 1995-1998 Mark Adler
%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
Broken pipe
Inappropriate I/O control operation
Operation not permitted
RASAPI32.dll
WinExec
GetKeyState
GetViewportOrgEx
WINSPOOL.DRV
RegCloseKey
RegOpenKeyExA
RegCreateKeyA
ShellExecuteA
SHELL32.dll
COMCTL32.dll
CreateDialogIndirectParamA
UnhookWindowsHookEx
SetWindowsHookExA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportExtEx
comdlg32.dll
RegCreateKeyExA
.PAVCException@@
Shell32.dll
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
.PAVCFileException@@
: %d]
(*.*)|*.*||
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|PNG
(*.PNG)|*.PNG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
%s:%d
windows
.PAVCNotSupportedException@@
out.prn
(*.prn)|*.prn|
%d.%d
%d/%d
1.6.9
unsupported zlib version
png_read_image: unsupported transformation
%d / %d
Bogus message code %d
libpng error: %s
libpng warning: %s
1.1.3
bad keyword
libpng does not support gamma background rgb_to_gray
Palette is NULL in indexed image
(%d-%d):
%ld%c
;3 #>6.&
'2, / 0&7!4-)1#
%s <%s>
Reply-To: %s
From: %s
To: %s
Subject: %s
Date: %s
Cc: %s
%a, %d %b %Y %H:%M:%S
SMTP
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCArchiveException@@
#include "l.chs\afxres.rc" // Standard components
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADC:\CDM.exe
VVV.168guaji.com
1.2.18
F%*.*f
MSWHEEL_ROLLMSG
MSVFW32.dll
AVIFIL32.dll
InternetCrackUrlA
InternetCanonicalizeUrlA
(*.avi)|*.avi
WPFT532.CNV
WPFT632.CNV
EXCEL32.CNV
write32.wpc
Windows Write
mswrd632.wpc
Word for Windows 6.0
wword5.cnv
Word for Windows 5.0
mswrd832.cnv
mswrd632.cnv
Word 6.0/95 for Windows & Macintosh
html32.cnv
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
HTTP/1.0
c:\%original file name%.exe
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
%S'vSG$wL"'vHN0rH&<
F.VnQ2
f.La1}ONz.
,vPK85\K82EV$rME5jMI:1\K8%U
aqt%v(1!gjezjf|9.sa%n{r4v{~;-jy!o~:-o~=4rb}<ase<m|>-o~*$?"?l.8>
.yyh"
z$5."$%X{}zGx%}//v~
&.dUz;,D`:?S;(%Fr
".dUz;-D/{8
9.dUz; D/{.
8<(&8=):
.vcH~
:j%c;n
.Sz~XGy
!H}~JJ:$GMldAN:$/.adACe~/-bsGC{%
%uPZW
%uN|-
O:J%S2
qvyB4>~b.pr]i.6
tT.zc
&nfY.}wA.qx
d.eMD
mdS%sfG
`{LxE%s
..skt
ZzY[.UQ
z_[.UQ
.PIZ(
AUrl/ 
Up0%xs
8U.Ix
.GiD}DF
%.bqA@D}[GNp
UúS
$H;%f
m.XQs,L
c.jK%Q
c/qC%s0Dxw>
4k{5#$q>;%s41ct;0~`61fg 3%{%3g=33;*d2i iois4bl&hn>s0fntQ
>httpu
hTTP/h
hXXp://hi.baidu.com/aegifjftrggluze/item/be185dc989cae4f4984aa0df
baidu.com
1.6.2.1
(*.*)
1.0.0.0
(hXXp://VVV.dywt.com.cn)

%original file name%.exe_2180_rwx_006CB000_00002000:

>httpu
hTTP/h
hXXp://hi.baidu.com/aegifjftrggluze/item/be185dc989cae4f4984aa0df
baidu.com

CDM.exe_3436:

.text
`.rdata
@.data
.rsrc
t$(SSh
~%UVW
u$SShe
iu2.iu
K(.wS
Proxy.dll
Kernel32.dll
kernel32.dll
user32.dll
gdiplus.dll
{A068799B-7551-46b9-8CA8-EEF8357AFEA4}
\CDM.exe
software\microsoft\windows\CurrentVersion\Run\
\Proxy.dll
@.reloc
f9z.vk
__MSVCRT_HEAP_SELECT
CreateIoCompletionPort
GetProcessHeap
KERNEL32.dll
MsgWaitForMultipleObjects
USER32.dll
GDI32.dll
ADVAPI32.dll
ole32.dll
WS2_32.dll
SHLWAPI.dll
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
WININET.dll
OLEAUT32.dll
WINMM.dll
GetCPInfo
proxy_AA555.dll
8@HNetCfg.FwMgr
hXXps://
hXXp://
https
http:
Client: VVV.xie6.cn
https:
HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
/gengxin.asp?id=
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET4.0C; .NET4.0E)
@/dlldy.asp?cz=hqfwq&bs=MAYI
/dlldy.asp?cz=hqzjip
4@0.0.0.0
<@WinINet.dll
ws2_32.dll
urlmon
URLDownloadToFileA
program internal error number is %d.
%s%x.tmp
:"%s"
:"%s".
zcÁ
7!8 808:8
0#0 040=0
5$5(5,5054585<5@5
$0004080
%d&&'
123456789
00003333
deflate 1.1.3 Copyright 1995-1998 Jean-loup Gailly
inflate 1.1.3 Copyright 1995-1998 Mark Adler
%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
Broken pipe
Inappropriate I/O control operation
Operation not permitted
RASAPI32.dll
WinExec
GetKeyState
GetViewportOrgEx
WINSPOOL.DRV
RegCloseKey
RegOpenKeyExA
RegCreateKeyA
ShellExecuteA
SHELL32.dll
COMCTL32.dll
CreateDialogIndirectParamA
UnhookWindowsHookEx
SetWindowsHookExA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportExtEx
comdlg32.dll
RegCreateKeyExA
.PAVCException@@
Shell32.dll
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
.PAVCFileException@@
: %d]
(*.*)|*.*||
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|PNG
(*.PNG)|*.PNG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
%s:%d
windows
.PAVCNotSupportedException@@
out.prn
(*.prn)|*.prn|
%d.%d
%d/%d
1.6.9
unsupported zlib version
png_read_image: unsupported transformation
%d / %d
Bogus message code %d
libpng error: %s
libpng warning: %s
1.1.3
bad keyword
libpng does not support gamma background rgb_to_gray
Palette is NULL in indexed image
(%d-%d):
%ld%c
;3 #>6.&
'2, / 0&7!4-)1#
%s <%s>
Reply-To: %s
From: %s
To: %s
Subject: %s
Date: %s
Cc: %s
%a, %d %b %Y %H:%M:%S
SMTP
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCArchiveException@@
C:\CDM.exe
#include "l.chs\afxres.rc" // Standard components
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
1.6.2.1
(*.*)
1.0.0.0
(hXXp://VVV.dywt.com.cn)

%original file name%.exe_2180_rwx_01580000_00002000:

>httpu
hTTP/h
hXXp://hi.baidu.com/aegifjftrggluze/item/be185dc989cae4f4984aa0df
baidu.com


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    CDM.exe:3436

  2. Delete the original Dropped file.
  3. Delete or disinfect the following files created/modified by the Dropped:

    C:\%original file name%.exe (18248 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\error[1].htm (2704 bytes)
    C:\CDM.exe (1810 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\dlldy[1].htm (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gengxin[1].htm (232 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\dlldy[1].htm (17 bytes)
    C:\Proxy.dll (326 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UVH22G43.txt (109 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Î񵀮ô¶¯Ïî" = "C:\CDM.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now