Gen.Variant.Barys.2143_349d277291
Trojan-Dropper.Win32.Delf.efnz (Kaspersky), Gen:Variant.Barys.2143 (B) (Emsisoft), Gen:Variant.Barys.2143 (AdAware), Backdoor.Win32.Fynloski.FD, Trojan-Banker.Win32.Brasil.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Iconomon.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, BackdoorFynloski.YR, GenericDownloader.YR, GenericInjector.YR, TrojanDownloaderAndromeda.YR (Lavasoft MAS)
Behaviour: Trojan-Dropper, Trojan-Downloader, Banker, Trojan, Backdoor, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: 349d2772917254f5a09e6753867d046a
SHA1: 4824c5fcc14a30d5389db36b28e404ddeab3476f
SHA256: ceb0abea798bef4e33414c9f2a0b82feb8b48759427f79f1867c6331a143d026
SSDeep: 98304:fCfL2Nz1dh5DanDM L5rctxLOn5BAULHcIN0:fCfQdOnDM L5Yt4OaS
Size: 5212160 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company:
Created at: 1992-06-20 01:22:17
Analyzed on: Windows7 SP1 32-bit
Summary:
Trojan-Dropper. Trojan program, intended for stealth installation of other malware into user's system.
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:3668
434ÃÂ6.exe:3676
The Trojan injects its code into the following process(es):
kophack-70.exe:2624
Windows.exe:3188
notepad.exe:3144
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:3668 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\434ÃÂ6.exe (1414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kophack-70.exe (489 bytes)
The process 434ÃÂ6.exe:3676 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe (4545 bytes)
Registry activity
The process kophack-70.exe:2624 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASMANCS]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASMANCS]
"EnableFileTracing" = "0"
"MaxFileSize" = "1048576"
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"EnableFileTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3E 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASMANCS]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"EnableConsoleTracing" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process %original file name%.exe:3668 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process 434ÃÂ6.exe:3676 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
The Trojan adds the reference to itself to be executed when a user logs on:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "C:\Windows\system32\userinit.exe,C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"windows.exe" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
Dropped PE files
MD5 | File path |
---|---|
7be000b351000cf02bed01a1dada3576 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\434Ã6.exe |
7be000b351000cf02bed01a1dada3576 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe |
ba1add29800ea7182b32507b0c94b8ba | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\kophack-70.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
CODE | 4096 | 5048 | 5120 | 4.39524 | e5913936857bed3b3b2fbac53e973471 |
DATA | 12288 | 124 | 512 | 0.77468 | cef89de607e490725490a3cd679af6bb |
BSS | 16384 | 1685 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 20480 | 770 | 1024 | 2.41029 | 3d2f2fc4e279cba623217ec9de264c4f |
.tls | 24576 | 4 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 28672 | 24 | 512 | 0.138011 | 467f29e48f3451df774e13adae5aafc2 |
.reloc | 32768 | 456 | 512 | 4.00868 | 9859d413c7408cb699cca05d648c2502 |
.rsrc | 36864 | 5203228 | 5203456 | 4.62763 | 00f0f1c8e8f4887e9aad32dc00fcd974 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
URL | IP |
---|---|
hxxp://baza.hack-games-vk.ru/KopHack/version-70.php | ![]() |
nikita256455.ddns.net | ![]() |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /KopHack/version-70.php HTTP/1.1
Host: baza.hack-games-vk.ru
Accept: text/html, */*
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Server: nginx-reuseport/1.11.6
Date: Sat, 03 Dec 2016 13:26:59 GMT
Content-Type: text/html
Content-Length: 1
Connection: keep-alive
Keep-Alive: timeout=30
X-Powered-By: PHP/5.2.17HTTP/1.1 200 OK..Server: nginx-reuseport/1.11.6..Date: Sat, 03 Dec 20
16 13:26:59 GMT..Content-Type: text/html..Content-Length: 1..Connectio
n: keep-alive..Keep-Alive: timeout=30..X-Powered-By: PHP/5.2.17.. ..
The Trojan connects to the servers at the folowing location(s):
.idata
.rdata
P.reloc
P.rsrc
kernel32.dll
Windows
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
u%CNu
%s[%d]
%s_%d
EInvalidGraphicOperation
USER32.DLL
comctl32.dll
uxtheme.dll
PasswordCharL7E
OnKeyDownp
OnKeyPress$
OnKeyUpH
OnKeyUp
TListBoxp%C
Proportional
%s%s%s%s%s%s%s%s%s%s
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
TKeyEvent
TKeyPressEvent
HelpKeyword
crSQLWait
%s (%s)
Uh.cD
imm32.dll
AutoHotkeysl-E
AutoHotkeys
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreview`4E
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
User32.dll
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
WS2_32.DLL
127.0.0.1
TIdSocketListWindows
TIdStackWindowsU
IdStackWindows
%s, %.2d %s %.4d %s %s
%s, %d %s %d %s %s
Unsupported operation.
Content-Disposition: form-data; name="%s"; filename="%s"
Content-Type: %s
Content-Disposition: form-data; name="%s"
PSAPI.dll
MAPI32.DLL
TsWindowShowMode
user32.dll
colorui.dll
shell32.dll
comdlg32.dll
compstui.dll
inetres.dll
1.2.3
Invalid ZStream operation!
msimg32.dll
Cannot load image. %s not supported for %s files.
Cannot load image. Palette in %s file is invalid.
Cannot load image. Invalid or unexpected %s image format.
Cannot load image. CRC error found in %s file.
Cannot load image. Extra compressed data found in %s file.
Cannot load image. Compression error found in %s file.
Invalid color format in %s file.
3333333
Conversion between indexed and non-indexed pixel formats is not supported.
Portable network graphics (AlphaControls)
TsShowTimer
TsShowTimerd
TacMDIWnd
gdi32.dll
WEBBUTTON
PROGRESSH
TacMenuSupport
Webdings
Uh.TP
TAddItemExEvent
DWMAPI.DLL
acMDIIcons
|$(;<$}?
ole32.dll
ClickKey(
FormKeyPress
### ### ##0.00;-### ### ##0.00;0
sEditHexKeyPress
PickFormKeyDown
CRASPIPETTE
TacScrollBarsSupport
TacScrollBarsSupport4
TacButtonsSupport
TacButtonsSupport$
TacLabelsSupport
MenuSupport
KeyList
c:\Skins
Options.dat
.JPEG
1.tmp
Please, update skins to latest or contact the AlphaControls support for upgrading of existing skin.
This version of the skin has not complete support by used AlphaControls package release.
Secure key has incorrect format
opera.exe
firefox.exe
chrome.exe
browser.exe
plugin-container.exe
safari.exe
KopatelOnline.exe
SteamTestApp.exe
amigo.exe
ftpTransfer
ftpReady
ftpAborted
ClientPortMin<
ClientPortMax
Port
EIdCanNotBindPortInRange
EIdInvalidPortRangeSVW
saUsernamePassword
Password<
0.0.0.1
UhC%U
TIdTCPConnection
IdTCPConnection
EIdTCPConnectionError
CommentURL
password
Password
IdHTTPHeaderInfo
ProxyPassword<
ProxyPort
Mozilla/3.0 (compatible; Indy Library)
TIdTCPClient
IdTCPClient
BoundPort
PortU
libeay32.dll
ssleay32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_certificate_file
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
X509_STORE_CTX_get_current_cert
des_set_key
sslvrfFailIfNoPeerCert
TPasswordEvent
Certificate
RootCertFileD
CertFileD
KeyFiled
OnGetPassword
EIdOSSLLoadingRootCertError0
EIdOSSLLoadingCertError
EIdOSSLLoadingKeyError
TIdHTTPMethod
IdHTTP
TIdHTTPOption
TIdHTTPOptions
TIdHTTPProtocolVersion
IdHTTPl
TIdHTTPOnHeadersAvailable
TIdHTTPOnRedirectEvent
TIdHTTPResponse
TIdHTTPRequest
TIdHTTPRequestX
TIdHTTPProtocoll
TIdCustomHTTP
TIdCustomHTTPl
TIdHTTPT
TIdHTTP
HTTPOptionsh
EIdHTTPProtocolException
HTTPS
https
This request method is supported in HTTP 1.1
HTTP/1.0 200 OK
HTTP/
IdHTTP1
768352325.jks
auth_key
IdHTTP1
768352321.jks
07 00 00 00
12 00 00 00
40 00 00 00
41 00 00 00
42 00 00 00
08 00 00 00
11 00 00 00
22 00 00 00
23 00 00 00
21 00 00 00
24 00 00 00
25 00 00 00
26 00 00 00
28 00 00 00
31 00 00 00
32 00 00 00
33 00 00 00
34 00 00 00
35 00 00 00
06 00 00 00
09 00 00 00
04 00 00 00
01 00 00 00
05 00 00 00
13 00 00 00
14 00 00 00
15 00 00 00
16 00 00 00
17 00 00 00
18 00 00 00
19 00 00 00
43 00 00 00
44 00 00 00
45 00 00 00
46 00 00 00
47 00 00 00
48 00 00 00
49 00 00 00
50 00 00 00
39 00 00 00
03 00 00 00
53 00 00 00
54 00 00 00
55 00 00 00
56 00 00 00
51 00 00 00
52 00 00 00
00 00 00 54
00 00 00 55
00 00 00 56
00 00 00 57
00 00 00 58
00 00 00 59
00 00 00 60
00 00 00 61
00 00 00 62
00 00 00 63
00 00 00 64
00 00 00 65
00 00 00 70
00 00 00 71
00 00 00 72
00 00 00 73
00 00 00 74
00 00 00 75
00 00 00 29
00 00 00 36
00 00 00 38
00 00 00 67
00 00 00 66
00 00 00 69
00 00 00 68
00 00 00 78
00 00 00 79
00 00 00 80
00 00 00 81
00 00 00 33
00 00 00 34
00 00 00 35
00 00 00 39
00 00 00 76
00 00 00 77
00 00 00 51
00 00 00 50
57 00 00 00
58 00 00 00
59 00 00 00
83 00 00 00
84 00 00 00
85 00 00 00
86 00 00 00
87 00 00 00
88 00 00 00
89 00 00 00
80 00 00 00
81 00 00 00
82 00 00 00
65 00 00 00
66 00 00 00
67 00 00 00
68 00 00 00
69 00 00 00
70 00 00 00
71 00 00 00
73 00 00 00
74 00 00 00
76 00 00 00
77 00 00 00
78 00 00 00
79 00 00 00
60 00 00 00
61 00 00 00
62 00 00 00
63 00 00 00
hXXp://baza.hack-games-vk.ru/KopHack/version-70.php
hXXp://baza.hack-games-vk.ru/KopHack/download.php
hXXp://hack-games-vk.ru/topic/4949-chit-na-kopatel-onlain-kophack/
hXXp://vzlom-games.ru/kop_hack_v70.php?id=
&authkeyshop=false
google chrome
IdHTTP1`
89 48 08 90 90 90 90
40 00 00
363465123.jks
hXXps://VVV.youtube.com/channel/UClV7COFnkC-4If9kSG9OZcA
hXXp://hack-games-vk.ru/forum/2-chity-dlia-igr-vkcom/
hXXp://85.25.118.169/VK3/get_profile.php/
auth_key!
hXXp://85.25.118.169/VK3/set_name.php
hXXp://85.25.118.169/VK2/everyday_bonus.php/
hXXp://85.25.118.169/VK3/modify_map_name.php
inflate 1.2.3 Copyright 1995-2005 Mark Adler
If you have a key for this skin, please insert it in the KeyList.
?456789:;<=
!"#$%&'()* ,-./0123
GetKeyboardType
advapi32.dll
RegOpenKeyExA
RegCloseKey
RegFlushKey
RegCreateKeyExA
GetCPInfo
version.dll
SetViewportOrgEx
GetViewportOrgEx
UnhookWindowsHookEx
SetWindowsHookExA
SetKeyboardState
MsgWaitForMultipleObjects
MapVirtualKeyA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
EnumWindows
EnumThreadWindows
EnumChildWindows
ActivateKeyboardLayout
ShellExecuteA
wininet.dll
; ;$;(;,;0;4;8;
= =$=(=,=0=4=8=<=@=\=|=
5#5'5 5/535
3!4%4)4-41454
4 4(4@4]4
=$=4=<=|=
= =$=(=,=0=4=8=;>
1-191O1}1
4#4'4 4/444
4(5,5054585
6#6'6 606
7Œ9
3"4-454D4X4f4n4}4
8 8$8(8,8
;0,2<253
: :$:(:,:0:
= =$=(=,=0=4=8=<=
9 9$9(9,909
2/33373<3
>%>0>8>~>
11p142
8 8&8?8[8
1)1-111P1T1X1y1}1
6"6&6*6.62666:6
7 7$7(7,70747:7
333333333333333333
33333833
3333339
3333333333333338
:*"*"$3338
33333333
33333333333
3333333333338
33338?383
333333333333
:*3:"$3338
333333333333333
KWindows
UrlMon
%sPopupClndr
IdTCPStream
0IdHTTPHeaderInfo
IdTCPServer
IdHTTPServer
IdCustomHTTPServer
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
Icon.Data
SkinData.SkinSection
hack-games-vk.ru
ProxyParams.BasicAuthentication
ProxyParams.ProxyPort
Request.ContentLength
Request.ContentRangeEnd
Request.ContentRangeStart
Request.Accept
Request.BasicAuthentication
Request.UserAgent
&Mozilla/3.0 (compatible; Indy Library)
HTTPOptions
Glyph.Data
BoundLabel.Indent
BoundLabel.Font.Charset
BoundLabel.Font.Color
BoundLabel.Font.Height
BoundLabel.Font.Name
BoundLabel.Font.Style
BoundLabel.Layout
BoundLabel.MaxWidth
BoundLabel.UseSkinColor
auth_key
: VVV.hack-games-vk.ru
sSkinManager1 AnimEffects.BlendOnMoving.Active
AnimEffects.DialogShow.Time
AnimEffects.FormShow.Time
AnimEffects.FormHide.Time
AnimEffects.DialogHide.Time
AnimEffects.Minimizing.Time
ButtonsOptions.ShowFocusRect
V%Xs2l-yRo7Qn
Huge.bmp6
L:Z.Nr
g8~XkÄ
Master.bmpLf
.WScc
Vi...ON
l,.nBZJJ
jurl6
CloseAG.png9
CloseG.png
MaxG.png
MinG.png
NormG.png!
MenuSupport.IcoLineSkin
ICOLINE!MenuSupport.ExtraLineFont.Charset
MenuSupport.ExtraLineFont.Color
clWindowText MenuSupport.ExtraLineFont.Height
MenuSupport.ExtraLineFont.Name
MenuSupport.ExtraLineFont.Style
C:\Skins
ThirdParty.ThirdEdits
THotKey
TJvHotKey
TRzHotKeyEdit
ThirdParty.ThirdButtons
ThirdParty.ThirdBitBtns
ThirdParty.ThirdCheckBoxes
ThirdParty.ThirdGroupBoxes
ThirdParty.ThirdListViews
ThirdParty.ThirdPanels
ThirdParty.ThirdGrids
ThirdParty.ThirdTreeViews
ThirdParty.ThirdComboBoxes
TwwTempKeyCombo
ThirdParty.ThirdWWEdits
ThirdParty.ThirdVirtualTrees
ThirdParty.ThirdGridEh
ThirdParty.ThirdPageControl
ThirdParty.ThirdTabControl
ThirdParty.ThirdToolBar
ThirdParty.ThirdStatusBar
ThirdParty.ThirdSpeedButton
ThirdParty.ThirdScrollControl
ThirdParty.ThirdUpDown
ThirdParty.ThirdScrollBar
ThirdParty.ThirdStaticText
ThirdParty.ThirdNativePaint
AddedTitle.Font.Charset
AddedTitle.Font.Color
AddedTitle.Font.Height
AddedTitle.Font.Name
AddedTitle.Font.Style
FormHeader.AdditionalHeight
Constraints.MinHeight
Constraints.MinWidth
TsShellTreeView
sShellTreeView1
sShellTreeView1Change
BoundLabel.Active
BoundLabel.Caption
VertScrollBar.Tracking
KeyPreview
OnKeyPress
Constraints.MaxHeight
Constraints.MaxWidth
GlyphMode.Blend
GlyphMode.Grayed
Colors.Strings
Brush.Color
Pen.Color
Pen.Width
Add to custom colors set8Listbox (%s) style must be virtual in order to set Count
Error setting %s.Count
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Could not load certificate.#Could not load key, check password.
SSL status: "%s"
JPEG error #%d
Command not supported.
Address type not supported.$Error accepting connection with SSL.
Error creating SSL context. Could not load root certificate.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
Chunk StartedDThis authentication method is already registered with class name %s.
%s is not a valid service.
Socket Error # %d
%s is not a valid IP address.
Operation would block.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
No data to read.$Can not bind in port range (%d - %d)
Invalid Port Range (%d - %d)
Max line length exceeded.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
No help keyword specified.
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.4Failed attempting to retrieve time zone information.
File "%s" not found1Only one TIdAntiFreeze can exist per application."%d: Circular links are not allowed
8Listbox (%s) style must be virtual in order to set Count"Unable to find a Table of Contents
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard/Menu '%s' is already being used by another form
Invalid input value7Invalid input value. Use escape key to abandon changes
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)
Unsupported clipboard format
$''%s'' is not a valid component name
Invalid property element: %s
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Failed to get data for '%s'
Resource %s not found
%s.Seek not implemented
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Operation not supported
External exception %x
Interface not supported
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
!'%s' is not a valid integer value('%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time
I/O error %d
Windows.exe_3188:
.text
`.itext
`.data
.idata
.rdata
@.reloc
B.rsrc
kernel32.dll
Windows
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
%s_%d
EInvalidGraphicOperation
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
%s, ClassID: %s
%s, ProgID: "%s"
ole32.dll
TUploadFTP
user32.dll
1.2.3
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
127.0.0.1
TDCWebCam
wlanapi.dll
80211_SHARED_KEY
\Internet Explorer\iexplore.exe
explorer.exe
USER32.DLL
uxtheme.dll
DWMAPI.DLL
clWebSnow
clWebFloralWhite
clWebLavenderBlush
clWebOldLace
clWebIvory
clWebCornSilk
clWebBeige
clWebAntiqueWhite
clWebWheat
clWebAliceBlue
clWebGhostWhite
clWebLavender
clWebSeashell
clWebLightYellow
clWebPapayaWhip
clWebNavajoWhite
clWebMoccasin
clWebBurlywood
clWebAzure
clWebMintcream
clWebHoneydew
clWebLinen
clWebLemonChiffon
clWebBlanchedAlmond
clWebBisque
clWebPeachPuff
clWebTan
clWebYellow
clWebDarkOrange
clWebRed
clWebDarkRed
clWebMaroon
clWebIndianRed
clWebSalmon
clWebCoral
clWebGold
clWebTomato
clWebCrimson
clWebBrown
clWebChocolate
clWebSandyBrown
clWebLightSalmon
clWebLightCoral
clWebOrange
clWebOrangeRed
clWebFirebrick
clWebSaddleBrown
clWebSienna
clWebPeru
clWebDarkSalmon
clWebRosyBrown
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebOlive
clWebForestGreen
clWebGreenYellow
clWebChartreuse
clWebLightGreen
clWebAquamarine
clWebSeaGreen
clWebGoldenRod
clWebKhaki
clWebOliveDrab
clWebGreen
clWebYellowGreen
clWebLawnGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkgreen
clWebLimeGreen
clWebLime
clWebSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebLightCyan
clWebLightBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebIndigo
clWebMediumTurquoise
clWebTurquoise
clWebCyan
clWebPowderBlue
clWebSkyBlue
clWebRoyalBlue
clWebMediumBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebCadetBlue
clWebDarkCyan
clWebTeal
clWebDeepskyBlue
clWebDodgerBlue
clWebBlue
clWebNavy
clWebDarkViolet
clWebDarkOrchid
clWebMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebMediumOrchid
clWebMediumPurple
clWebPurple
clWebDeepPink
clWebLightPink
clWebViolet
clWebOrchid
clWebPlum
clWebThistle
clWebHotPink
clWebPink
clWebLightSteelBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebWhite
clWebLightgrey
clWebGray
clWebSteelBlue
clWebSlateBlue
clWebSlateGray
clWebWhiteSmoke
clWebSilver
clWebDimGray
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlategray
clWebGainsboro
clWebDarkGray
clWebBlack
comctl32.dll
AutoHotkeys
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
TKeyEvent
TKeyPressEvent
HelpKeyword
crSQLWait
%s (%s)
imm32.dll
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreview
WindowState
OnKeyDown$
OnKeyPress
OnKeyUp
Uhx%F
UhX%F
Uh %F
GlassFrame.Bottom
GlassFrame.Enabled
GlassFrame.Left
GlassFrame.Right
GlassFrame.SheetOfGlass
GlassFrame.Top
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
User32.dll
PSAPI.dll
\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
*.torrent
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hkey
cmd.exe
TSocketPort
%d.%d.%d.%d
0.0.0.0
POST /index.php/1.0
BTRESULTHTTP Flood|Http Flood task finished!|
BTRESULTVisit URL|finished to visit
BTERRORVisit URL|An exception occured in the thread|
PortScanAdd
BTRESULTUDP Flood|UDP Flood task finished!|
FTPPORT
FTPPASS
FTPUSER
FTPHOST
FTPROOT
FTPUPLOADK
FTPSIZE
TCaptureWebcam
taskmgr.exe
ERR|Cannot listen to port, try another one..|
UPLOADEXEC
UPANDEXEC
PASSWORD
out.txt
tmp.txt
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows NT\CurrentVersion\Winlogon
127.0.0.1:1604
#KCMDDC51#-
5.3.0
\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
DC3_FEXEC
Windows NT 4.0
Windows 2000
Windows XP
Windows Server 2003
Windows Vista
Windows 7
Windows 95
Windows 98
Windows Me
S-%u-
Mozilla
BTRESULTDownload File|Mass Download : File Downloaded , Executing new one in temp dir...|
BTERRORDownload File| Error on downloading file check if you type the correct url...|
notepad.exe
KEYNAME
%ShortCut#
RELATEDCMD
ping 127.0.0.1 -n 4 > NUL && "
DRKey
CRKey
DelMSKey
InstallHKEY
ActiveOnlineKeylogger
UnActiveOnlineKeylogger
KeylogOn
ActiveOfflineKeylogger
UnActiveOfflineKeylogger
ActiveOnlineKeyStrokes
UnActiveOnlineKeyStrokes
OpenWebPage
tmpprint.txt
URLUpdate
MSGBOX
#BOT#VisitUrl
#BOT#OpenUrl
HTTP://
hXXp://
BTRESULTOpen URL|
Command successfully executed!|
#BOT#URLUpdate
BTERRORUpdate from URL| Error on downloading file check if you type the correct url...|
BTRESULTUpdate from URL|Update : File Downloaded , Executing new one in temp dir...|
#BOT#URLDownload
GetActivePorts
DDOSHTTPFLOOD
DDOSUDPFLOOD
%IPPORTSCAN
SAPI.SpVoice
WEBCAMLIVE
WEBCAMSTOP
FTPFILEUPLOAD
URLDOWNLOADTOFILE
FAKEMSG
MSGICON
MSGTITLE
MSGCORE
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
C:\Users\"%CurrentUserName%"\AppData\Roaming\dclogs\2016-12-03-7.dc
advapi32.dll
RegOpenKeyExA
RegCloseKey
GetKeyboardType
keybd_event
VkKeyScanA
UnhookWindowsHookEx
SetWindowsHookExA
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MapVirtualKeyA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
ExitWindowsEx
EnumWindows
EnumThreadWindows
EnumChildWindows
ActivateKeyboardLayout
gdi32.dll
SetViewportOrgEx
version.dll
WinExec
PeekNamedPipe
GetWindowsDirectoryA
GetProcessHeap
GetCPInfo
CreatePipe
RegQueryInfoKeyA
RegOpenKeyA
RegFlushKey
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyA
netapi32.dll
shell32.dll
ShellExecuteExA
ShellExecuteA
SHFileOperationA
gdiplus.dll
GdiplusShutdown
winmm.dll
URLMON.DLL
URLDownloadToFileA
wininet.dll
InternetOpenUrlA
HttpQueryInfoA
FtpPutFileA
wsock32.dll
msacm32.dll
SHFolder.dll
WS2_32.DLL
ntdll.dll
SHELL32.DLL
AVICAP32.DLL
1!1,1=1|1
=#='= =/=3=7=;=?=
3 3$3(3,3034383
<#<'< <8=\=
:":-:2:=:
3 3$3(3,3
1)161`1}1
= =$=(=,=0=4=8=
UntKeylogger
KWindows
UntActivePorts
UntControlKey
UntCaptureWebcam
UntWebCam
UrlMon
(UntUploadFTPThread
UntFTP
_UntUDPFlood
YUntScanPorts
0UntPasswordAndData
XUntHTTPFlood
UntCPU
66006666
No help found for %s#No context-sensitive help installed
No help found for context$No topic-based help system installedNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard/Menu '%s' is already being used by another form
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Not enough timers available@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)
Unsupported clipboard format
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
External exception %x
Interface not supported
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
No argument for format '%s'"Variant method calls not supported
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
!'%s' is not a valid integer value('%s' is not a valid floating point value!'%s' is not a valid date and time
'%s' is not a valid GUID value
I/O error %d
1, 0, 0, 1
MSRSAAP.EXE
4, 0, 0, 0
notepad.exe_3144:
.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
msvcrt.dll
COMDLG32.dll
SHELL32.dll
WINSPOOL.DRV
ole32.dll
SHLWAPI.dll
COMCTL32.dll
OLEAUT32.dll
VERSION.dll
ntdll.dll
RegCloseKey
RegCreateKeyW
RegOpenKeyExW
GetProcessHeap
SetViewportExtEx
GetKeyboardLayout
_amsg_exit
_acmdln
ShellExecuteExW
notepad.pdb
name="Microsoft.Windows.Shell.notepad"
version="5.1.0.0"
<description>Windows Shell</description>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
<windowsSettings>
<dpiAware xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
===111*!
'141133!/!(!(!""/""
;;;;4;3423332
keYM
,k<.KQ
.WF"hB
dx.Rl
V.xOx_T
<'<.<9<_<
/.SETUP
%s%c*.txt%c%s%c*.*%c
*.txt
mshelp://windows/?id=5d18d5fb-e737-4a73-b6cc-dccc63720231
\StringFileInfo\xx\OriginalFilename
\sppsvc.exe
\slui.exe
\sppuinotify.dll
Text Documents (*.txt)
6.1.7600.16385 (win7_rtm.090713-1255)
NOTEPAD.EXE
Windows
Operating System
6.1.7600.16385
notepad.exe_3144_rwx_00060000_00001000:
kernel32.dll
notepad.exe_3144_rwx_00070000_00001000:
user32.dll
notepad.exe_3144_rwx_001A0000_00001000:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:3668
434ÃÂ6.exe:3676 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\434ÃÂ6.exe (1414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kophack-70.exe (489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe (4545 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"windows.exe" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe" - Remove the references to the Trojan by modifying the following registry value(s) (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "C:\Windows\system32\userinit.exe,C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.