Adware.Win32.Downware_0c8c597eef

by malwarelabrobot on March 23rd, 2016 in Malware Descriptions.

Adware.Win32.Downware.FD, Trojan.NSIS.StartPage.FD, AdwareDownware.YR (Lavasoft MAS)
Behaviour: Trojan, Adware


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 0c8c597eef67709d9532291efe74ce10
SHA1: d547fb0b824aed8814f310cdbb8c0de8474241a1
SHA256: 6938dc442a2bc2ade6527afb0d194f7aba7d68868db4234b27fcc03e3b333749
SSDeep: 3072:YQIURTXJ445 JNw JxTP7NFvHFI8GXphv9C2CBJI/vI3EjfCSfF1wCGtE6f8bOBB:Ysi1jvZYXkdJIohSfLwj8b8nZCYGB95y
Size: 263224 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-12-06 00:50:46
Analyzed on: WindowsXP SP3 32-bit


Summary:

Adware. Delivers advertising content in a manner or context that may be unexpected and unwanted by users. Many adware applications also perform tracking functions. Users may want to remove adware if they object to such tracking, do not wish to see the advertising caused by the program or are frustrated by its effects on system performance.

Payload

No specific payload has been found.

Process activity

The Adware creates the following process(es):
No processes have been created.
The Adware injects its code into the following process(es):

%original file name%.exe:772

Mutexes

The following mutexes were created/opened:

ZonesLockedCacheCounterMutex
ZonesCounterMutex
ZonesCacheCounterMutex
RasPbFile
WininetProxyRegistryMutex
WininetConnectionMutex
WininetStartupMutex
c:!documents and settings!adm!local settings!history!history.ie5!
c:!documents and settings!adm!cookies!
c:!documents and settings!adm!local settings!temporary internet files!content.ie5!
_!MSFTHISTORY!_
ShimCacheMutex

File activity

The process %original file name%.exe:772 makes changes in the file system.
The Adware creates and/or writes to the following file(s):

%Program Files%\1ClickDownload\ocmainpack.exe (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept3.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\skip.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\inetc3.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept1.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\save.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\decline.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept2.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\MainPackFA2703[1].htm (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\1clogo.bmp (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\anon.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse2.tmp (13665 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\nsDialogs.dll (9 bytes)

The Adware deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\gC0 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nso1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp (0 bytes)

Registry activity

The process %original file name%.exe:772 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\1ClickDownload]
"LastInstall0" = "30508063"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\1ClickDownload]
"UID" = "282948265"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "99 E0 DA A7 3E 93 4D 90 E9 F0 A3 5D 68 EE 65 DD"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Adware deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

Dropped PE files

MD5 File path
c17103ae9072a06da581dec998343fc1 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsu3.tmp\System.dll
9d8ce05f532dc7b5742831ec8a63c2d8 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsu3.tmp\inetc3.dll
c10e04dd4ad4277d5adc951bb331c777 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsu3.tmp\nsDialogs.dll

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

No information is available.

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 23130 23552 4.44841 0bc2ffd32265a08d72b795b18265828d
.rdata 28672 4496 4608 3.59163 f179218a059068529bdb4637ef5fa28e
.data 36864 110488 1024 3.26405 975304d6dd6c4a4f076b15511e2bbbc0
.ndata 147456 372736 0 0 d41d8cd98f00b204e9800998ecf8427e
.rsrc 520192 16592 16896 4.13874 8091b1378d82973015f802c93eb88bab

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

Total found: 130
69a0a458647b3436892cf9f2f126c252
f6dfcb76ad7437d92c5afb7f0df46e1e
da0bd3c1e61660738d11b8637009704c
274a292adfe75bf2ebb7ec280e41498b
5237ce96c640fe6ac6cc74c0dcbfcaa3
2f7774bf5fd92c51f79f4ba883a3688d
19e571b63f058f8639368efa0b7e7a5d
92f168a6a50962338197ed28079023e0
eb7796e86be9bedaa30b7cfffeefe81f
02970495e406b99d8bf8e992a8ee80e8
58370f3c58561f8bfb46cf3e2f91f4b3
7bf0d359dbc0f2394d811bf4ca178d0c
6595f1898fe06bd80ec59d9ccd70bda2
9f979219e6f2be6b0d69c699192e9c98
fcb0905f624625fc4839a6a4edcb6fd4
56f587e1afeb682b0688dfcce19ebed9
c63e670ed1d501559890afdc5ccb3d56
bc4b8c6d6165113c61fb4744140a49c8
9cb467ff929aa9ea250e2501ade5f077
60ba6445ca5e44ce37f9175d5b71252a
558629b6feeb66bfdcef6c99e3c570a3
70734d89308e9da071e1e5bf18547b14
ba27f4cf2fd8becf08d48c952b1e6515
854785be31dfdacde5e34c6ed71c99a6
d9c131de8a7a673f0b3fdd82e00416d8

URLs

URL IP
hxxp://data.downloadstarter.net/country.asp?st=-1&uid=282948265&tuid=3131549&sref=1CD_16_36_trze7&vmdt=|vm|&bld=16CJ 88.80.188.52
hxxp://files.download1click.ws/MainPackFA2703.exe 64.70.19.202


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

GET /MainPackFA2703.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: files.download1click.ws
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200
Server: nginx/1.6.3
Date: Tue, 22 Mar 2016 09:47:26 GMT
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 598
Connection: keep-alive
<html>.<head>..<title>WEBSITE.WS - Your Internet Add
ress For Life™</title>.</head>.<frameset rows="10
0%,*" border="0" frameborder="0">..<frame src="hXXp://website.ws
/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&domain=dow
nload1click.ws" scrolling="auto">..<noframes>...<p> You
r browser does not support frames. Continue to <a href="hXXp://webs
ite.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&doma
in=download1click.ws">hXXp://website.ws/kvmlm2/index.dhtml?sponsor=
wildcardform8&template=13&chk=1&domain=download1click.ws</a>.<
;/p>..</noframes>.</frameset>.</html>HTTP/1.1 200
..Server: nginx/1.6.3..Date: Tue, 22 Mar 2016 09:47:26 GMT..Content-Ty
pe: text/html; charset=ISO-8859-1..Content-Length: 598..Connection: ke
ep-alive..<html>.<head>..<title>WEBSITE.WS - Your In
ternet Address For Life™</title>.</head>.<framese
t rows="100%,*" border="0" frameborder="0">..<frame src="hXXp://
website.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&
d..


The Adware connects to the servers at the folowing location(s):

%original file name%.exe_772:

.text
`.rdata
@.data
.ndata
.rsrc
uDSSh
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
KERNEL32.dll
ExitWindowsEx
USER32.dll
GDI32.dll
SHFileOperationA
ShellExecuteA
SHELL32.dll
RegEnumKeyA
RegCreateKeyExA
RegCloseKey
RegDeleteKeyA
RegOpenKeyExA
ADVAPI32.dll
COMCTL32.dll
ole32.dll
VERSION.dll
verifying installer: %d%%
unpacking data: %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
%u.%u%s%s
RegDeleteKeyExA
%s=%s
*?|<>/":
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp\nsDialogs.dll
ectly,15_Eboeken_Karin_Slaughter.exe,nl
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp
zbX<u%FVl\<
=I}.Du7
i.PpB
"M%dN
Vh.vN
Keym
WINDOWS
skip.bmp", i 0, i 0, i 0, i 0x2000|0x0010) i.s
,15_Eboeken_Karin_Slaughter.exe,nl
1048780
iles\1ClickDownload\1ClickDownloader.exe
ZWJZLMJKI4FSJNC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
282948265
19759910
ef67709d9532291efe74ce10.exe
NC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
2829482
06406250
1704262
1342506070
ownload.sweetpacks.com/simsdm/bundle/
ram Files\Internet Explorer\iexplore.exe
n_Karin_Slaughter.exe
001.5512
c:\%original file name%.exe
%Documents and Settings%\%current user%\Desktop
%Program Files%\1ClickDownload
u3.tmp
%original file name%.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nso1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
hXXp://files.download1click.ws/MainPackFA2703.exe
hXXp://files.download1click.ws/gzip2.exe
hXXp://data.downloadstarter.net/
hXXp://files.download1click.ws/ARURUSetup.exe
hXXp://files.download1click.ws/ARUARSetup.exe
hXXp://files.download1click.ws/BTB0612.exe
hXXp://cdn.download.sweetpacks.com/simsdm/bundle/BundleSweetIMSetup.exe
hXXp://files.download1click.ws/FmoodsV21.exe
hXXp://files.download1click.ws/IminentSetup5.exe
hXXp://files.download1click.ws/.exe
hXXp://files.download1click.ws/weatherbugsetup.msi
hXXp://files.download1click.ws/IWantThisSetupRS.exe
hXXp://files.download1click.ws/ciuvoSetup.exe
hXXp://files.download1click.ws/incredibar_install3.exe
hXXp://download.sterkly.com/yontoo-c4.exe
hXXp://download.sterkly.com/yontoo-c2.exe
hXXp://download.sterkly.com/yontoo-b2.exe
hXXp://download.sterkly.com/yontoo-c3.exe
hXXp://download.sterkly.com/yontoo-c5.exe
hXXp://files.download1click.ws/GophotoExtSetup.exe
hXXp://files.download1click.ws/OneClickExt1_filter03.exe
hXXp://files.download1click.ws/OneClickExt1_filter13.exe
ocmainpack.exe
Inetc3 (Mozilla; FW 4; WinNT 5.1; msi 3.1.4001.5512; dbw ie; yo ;)
Software\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
873071679
1310970
1048906
1114390
3131549
trze7,magnet:?xt=urn:btih:RZWJZLMJKI4FSJNC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
1179894
1179886
-1845164791
-2012937513
-435878885
1704228
1573146
537199696
1507538
1507518
1835232
1507522
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
2030698948
1477051454
1275724832
2114585872
453641394
1762264094
-385219891
252314312
-1626733924
1225393333
-2012609457
15_Eboeken_Karin_Slaughter.exe
30508063
VVV.oneclickdownloader.com
sbiectrl.exe
vmtoolsd.exe
prl_cc.exe
coherence.exe
VirtualBox.exe
VBoxSVC.exe
DrWeb
%Program Files%\1ClickDownload\15_Eboeken_Karin_Slaughter.magnet
)-.Yln
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>

%original file name%.exe_772_rwx_10004000_00001000:

callback%d


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
  2. Delete the original Adware file.
  3. Delete or disinfect the following files created/modified by the Adware:

    %Program Files%\1ClickDownload\ocmainpack.exe (598 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept3.bmp (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\System.dll (11 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\skip.bmp (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\inetc3.dll (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept1.bmp (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\save.bmp (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\decline.bmp (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept2.bmp (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\MainPackFA2703[1].htm (598 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\1clogo.bmp (4992 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\anon.bmp (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse2.tmp (13665 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept.bmp (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\nsDialogs.dll (9 bytes)

  4. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  5. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now