Adware.Win32.Downware_eb7796e86b
Adware.Win32.Downware.FD, Trojan.NSIS.StartPage.FD, AdwareDownware.YR (Lavasoft MAS)
Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: eb7796e86be9bedaa30b7cfffeefe81f
SHA1: 0bad60c3b99ddbb995ab1444846da3091f4cdcb5
SHA256: 4b153b99322cfaa238da6b6e5752c7d7026f5c49e9013e1b26c5aeee5be065ae
SSDeep: 6144:Osi1EaCN4MS1NA4lem5pUGJLktZDCy9WK/6C5yZjbSU1ov7RXxBqVV:c1cpcNjFPUGJLkPJ9WKyNZSU1Y4VV
Size: 262960 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-12-06 00:50:46
Analyzed on: WindowsXP SP3 32-bit
Summary:
Adware. Delivers advertising content in a manner or context that may be unexpected and unwanted by users. Many adware applications also perform tracking functions. Users may want to remove adware if they object to such tracking, do not wish to see the advertising caused by the program or are frustrated by its effects on system performance.
Payload
No specific payload has been found.
Process activity
The Adware creates the following process(es):
No processes have been created.
The Adware injects its code into the following process(es):
%original file name%.exe:432
Mutexes
The following mutexes were created/opened:
ZonesLockedCacheCounterMutex
ZonesCounterMutex
ZonesCacheCounterMutex
RasPbFile
WininetProxyRegistryMutex
WininetConnectionMutex
WininetStartupMutex
c:!documents and settings!adm!local settings!history!history.ie5!
c:!documents and settings!adm!cookies!
c:!documents and settings!adm!local settings!temporary internet files!content.ie5!
_!MSFTHISTORY!_
ShimCacheMutex
File activity
The process %original file name%.exe:432 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\inetc3.dll (784 bytes)
%Program Files%\1ClickDownload\ocmainpack.exe (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\save.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\accept2.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\1clogo.bmp (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\anon.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\accept3.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\accept.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\nsDialogs.dll (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz2.tmp (14377 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\decline.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\accept1.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\MainPackFA2703[1].htm (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\skip.bmp (784 bytes)
The Adware deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\gC0 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj1.tmp (0 bytes)
Registry activity
The process %original file name%.exe:432 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\1ClickDownload]
"LastInstall0" = "30507589"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\1ClickDownload]
"UID" = "282948265"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "80 69 E6 A8 F8 A4 A2 AC 99 45 2B B7 D0 79 99 7D"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
| MD5 | File path |
|---|---|
| c17103ae9072a06da581dec998343fc1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nse3.tmp\System.dll |
| 9d8ce05f532dc7b5742831ec8a63c2d8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nse3.tmp\inetc3.dll |
| c10e04dd4ad4277d5adc951bb331c777 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nse3.tmp\nsDialogs.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 23130 | 23552 | 4.44841 | 0bc2ffd32265a08d72b795b18265828d |
| .rdata | 28672 | 4496 | 4608 | 3.59163 | f179218a059068529bdb4637ef5fa28e |
| .data | 36864 | 110488 | 1024 | 3.26405 | 975304d6dd6c4a4f076b15511e2bbbc0 |
| .ndata | 147456 | 372736 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rsrc | 520192 | 16592 | 16896 | 4.13874 | 8091b1378d82973015f802c93eb88bab |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 130
69a0a458647b3436892cf9f2f126c252
f6dfcb76ad7437d92c5afb7f0df46e1e
da0bd3c1e61660738d11b8637009704c
274a292adfe75bf2ebb7ec280e41498b
5237ce96c640fe6ac6cc74c0dcbfcaa3
2f7774bf5fd92c51f79f4ba883a3688d
19e571b63f058f8639368efa0b7e7a5d
92f168a6a50962338197ed28079023e0
0c8c597eef67709d9532291efe74ce10
02970495e406b99d8bf8e992a8ee80e8
58370f3c58561f8bfb46cf3e2f91f4b3
7bf0d359dbc0f2394d811bf4ca178d0c
6595f1898fe06bd80ec59d9ccd70bda2
9f979219e6f2be6b0d69c699192e9c98
fcb0905f624625fc4839a6a4edcb6fd4
56f587e1afeb682b0688dfcce19ebed9
c63e670ed1d501559890afdc5ccb3d56
bc4b8c6d6165113c61fb4744140a49c8
9cb467ff929aa9ea250e2501ade5f077
60ba6445ca5e44ce37f9175d5b71252a
558629b6feeb66bfdcef6c99e3c570a3
70734d89308e9da071e1e5bf18547b14
ba27f4cf2fd8becf08d48c952b1e6515
854785be31dfdacde5e34c6ed71c99a6
d9c131de8a7a673f0b3fdd82e00416d8
URLs
| URL | IP |
|---|---|
| hxxp://data.downloadstarter.net/country.asp?st=-1&uid=282948265&tuid=3131549&sref=1CD_16_37_ap180915&vmdt=|vm|&bld=16CJ | |
| hxxp://files.download1click.ws/MainPackFA2703.exe |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /MainPackFA2703.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: files.download1click.ws
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200
Server: nginx/1.6.3
Date: Sun, 20 Mar 2016 01:15:41 GMT
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 598
Connection: keep-alive<html>.<head>..<title>WEBSITE.WS - Your Internet Add
ress For Life™</title>.</head>.<frameset rows="10
0%,*" border="0" frameborder="0">..<frame src="hXXp://website.ws
/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&domain=dow
nload1click.ws" scrolling="auto">..<noframes>...<p> You
r browser does not support frames. Continue to <a href="hXXp://webs
ite.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&doma
in=download1click.ws">hXXp://website.ws/kvmlm2/index.dhtml?sponsor=
wildcardform8&template=13&chk=1&domain=download1click.ws</a>.<
;/p>..</noframes>.</frameset>.</html>HTTP/1.1 200
..Server: nginx/1.6.3..Date: Sun, 20 Mar 2016 01:15:41 GMT..Content-Ty
pe: text/html; charset=ISO-8859-1..Content-Length: 598..Connection: ke
ep-alive..<html>.<head>..<title>WEBSITE.WS - Your In
ternet Address For Life™</title>.</head>.<framese
t rows="100%,*" border="0" frameborder="0">..<frame src="hXXp://
website.ws/kvmlm2/index..
The Adware connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.ndata
.rsrc
uDSSh
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
KERNEL32.dll
ExitWindowsEx
USER32.dll
GDI32.dll
SHFileOperationA
ShellExecuteA
SHELL32.dll
RegEnumKeyA
RegCreateKeyExA
RegCloseKey
RegDeleteKeyA
RegOpenKeyExA
ADVAPI32.dll
COMCTL32.dll
ole32.dll
VERSION.dll
verifying installer: %d%%
unpacking data: %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
%u.%u%s%s
RegDeleteKeyExA
%s=%s
*?|<>/":
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse3.tmp\nsDialogs.dll
-_Mp3ViLLe.magnet
nials-_[2011]-_Mp3ViLLe.exe,us
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse3.tmp
L9.DK
.JfRt
% .WmE
WINDOWS
skip.bmp", i 0, i 0, i 0, i 0x2000|0x0010) i.s
1048780
iles\1ClickDownload\1ClickDownloader.exe
673129,Florence_and_The_Machine-_Ceremonials-_[2011]-_Mp3ViLLe.exe,us
282948265
29,Florence_and_The_Machine-_Ceremonials-_[2011]-_Mp3ViLLe.exe,us
56570424
6be9bedaa30b7cfffeefe81f.exe
2829482
06406250
1704262
470090972
ownload.sweetpacks.com/simsdm/bundle/
r.net/download.php?id=7673129
e.exe
ram Files\Internet Explorer\iexplore.exe
he_Machine-_Ceremonials-_[2011]-_Mp3ViLLe.exe,us
.php?id=7673129
_Ceremonials-_[2011]-_Mp3ViLLe.exe
001.5512
c:\%original file name%.exe
%Documents and Settings%\%current user%\Desktop
%Program Files%\1ClickDownload
e3.tmp
%original file name%.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsj1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
hXXp://files.download1click.ws/MainPackFA2703.exe
hXXp://files.download1click.ws/gzip2.exe
hXXp://data.downloadstarter.net/
hXXp://files.download1click.ws/ARURUSetup.exe
hXXp://files.download1click.ws/ARUARSetup.exe
hXXp://files.download1click.ws/BTB0612.exe
hXXp://cdn.download.sweetpacks.com/simsdm/bundle/BundleSweetIMSetup.exe
hXXp://files.download1click.ws/FmoodsV21.exe
hXXp://files.download1click.ws/IminentSetup5.exe
hXXp://files.download1click.ws/.exe
hXXp://files.download1click.ws/weatherbugsetup.msi
hXXp://files.download1click.ws/IWantThisSetupRS.exe
hXXp://files.download1click.ws/ciuvoSetup.exe
hXXp://files.download1click.ws/incredibar_install3.exe
hXXp://download.sterkly.com/yontoo-c4.exe
hXXp://download.sterkly.com/yontoo-c2.exe
hXXp://download.sterkly.com/yontoo-b2.exe
hXXp://download.sterkly.com/yontoo-c3.exe
hXXp://download.sterkly.com/yontoo-c5.exe
hXXp://files.download1click.ws/GophotoExtSetup.exe
hXXp://files.download1click.ws/OneClickExt1_filter03.exe
hXXp://files.download1click.ws/OneClickExt1_filter13.exe
Inetc3 (Mozilla; FW 4; WinNT 5.1; msi 3.1.4001.5512; dbw ie; yo ;)
Software\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
772408389
1310970
1048906
1114390
3131549
ap180915,hXXp://dl7.torrentreactor.net/download.php?id=7673129,Florence_and_The_Machine-_Ceremonials-_[2011]-_Mp3ViLLe.exe,us
ownload.php?id=7673129
hXXp://dl7.torrentreactor.net/download.php?id=7673129
1179894
1179886
ocmainpack.exe
436536543
369427459
1443169413
1704228
1573146
537199828
1507538
1507518
1835232
1507522
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
285869366
1527383151
-1106639556
956957877
-469105637
453641382
1678377744
688522315
-2079718697
1510605908
1963590739
Florence_and_The_Machine-_Ceremonials-_[2011]-_Mp3ViLLe.exe
30507589
VVV.oneclickdownloader.com
sbiectrl.exe
vmtoolsd.exe
prl_cc.exe
coherence.exe
VirtualBox.exe
VBoxSVC.exe
DrWeb
%Program Files%\1ClickDownload\Florence_and_The_Machine-_Ceremonials-_[2011]-_Mp3ViLLe.magnet
)-.Yln
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>
%original file name%.exe_432_rwx_10004000_00001000:
callback%d
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Adware file.
- Delete or disinfect the following files created/modified by the Adware:
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\inetc3.dll (784 bytes)
%Program Files%\1ClickDownload\ocmainpack.exe (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\save.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\accept2.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\1clogo.bmp (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\anon.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\accept3.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\accept.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\nsDialogs.dll (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz2.tmp (14377 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\decline.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\accept1.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\MainPackFA2703[1].htm (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\skip.bmp (784 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.