Gen.Heur.ARP.1_a89a04a8b5
Gen:Heur.ARP.1 (BitDefender), PWS:Win32/Zbot!GO (Microsoft), HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.Win32.Zbot.oa (v) (VIPRE), Trojan.PWS.Panda.5676 (DrWeb), Gen:Heur.ARP.1 (B) (Emsisoft), PWSZbot-FMO!A89A04A8B520 (McAfee), Trojan.Zbot!gen71 (Symantec), Trojan-PWS.Win32.Zbot (Ikarus), Gen:Heur.ARP.1 (FSecure), PSW.Generic12.XAY (AVG), Win32:Zbot-SJD [Trj] (Avast), TROJ_UPATRE.BMC (TrendMicro), Gen:Heur.ARP.1 (AdAware), Trojan-PSW.Win32.Zbot.4.FD, GenericInjector.YR (Lavasoft MAS)
Behaviour: Trojan-PSW, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: a89a04a8b520f8e120d500f2d952e239
SHA1: 10a812ad58dbf7a42347ceed55b6413ea0caaf07
SHA256: 6c6c8d2f7cd67bd42340b4d13c032a1766fe224125ab30744ff18039aca97184
SSDeep: 6144:GFtbAo6g/RqoxtZlfPCKwpNdOG3 qa6wQq1GhtXn:GFtbGSRqstHvwpOeM X
Size: 294400 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: Remo Software
Created at: 2004-05-27 07:35:28
Analyzed on: Windows7 SP1 32-bit
Summary:
Trojan-PSW. Trojan program intended for stealing users passwords.
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
WinMail.exe:3552
ebhiax.exe:2752
%original file name%.exe:3676
The Trojan injects its code into the following process(es):
taskhost.exe:252
Explorer.EXE:284
Dwm.exe:528
TPAutoConnect.exe:2068
conhost.exe:2076
conhost.exe:3828
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process WinMail.exe:3552 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore (38848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Drafts\winmail.fol (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\temp\WindowsMail.pat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\680801A8-00000001.eml (1924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\winmail.fol (592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\temp\edb00002.log (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Sent Items\winmail.fol (592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\winmail.fol (608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\tmp.edb (1728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabF7A8.tmp (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\winmail.fol (544 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Outbox\winmail.fol (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\edb.log (21408 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\680801A8-00000001.eml:OECustomProperty (260 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\edb.chk (300 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735 (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarF7A9.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\temp\WindowsMail.MSMessageStore (99 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735 (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat (400 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\edbtmp.log (3466 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ppcrlui_3552_2 (1281 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\old\WindowsMail.pat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ppcrlui_3552_2.ui (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarF7A9.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\edb00001.log (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\old\WindowsMail.MSMessageStore (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\edbtmp.log (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ppcrlui_3552_2 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\old\edb00001.log (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabF7A8.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\old (0 bytes)
The process ebhiax.exe:2752 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\ntuser.dat.LOG1 (5272 bytes)
C:\$Directory (96 bytes)
C:\Users\"%CurrentUserName%"\NTUSER.DAT (5384 bytes)
The process %original file name%.exe:3676 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IMK214E.bat (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Ebuzs\ebhiax.exe (588 bytes)
Registry activity
The process WinMail.exe:3552 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\IdentityCRL\Dynamic Salt]
"Size" = "330"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows Mail]
"Compact Check Count" = "2"
"Settings Upgraded" = "10"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows Mail\Junk Mail\Block Senders List]
"Version" = "327680"
[HKCU\Software\Microsoft\Windows Mail]
"LastBackup" = "E2 07 02 00 00 00 0B 00 02 00 23 00 08 00 1D 03"
"Running" = "1"
"V7StoreMigDone" = "01 00 00 00"
"StoreMigratedV5" = "1"
[HKCU\Software\Microsoft\Windows Mail\Junk Mail\Safe Senders List]
"Version" = "327680"
[HKCU\Software\Microsoft\Windows Mail\Mail]
"Welcome Message" = "0"
[HKCU\Software\Microsoft\Windows Mail]
"SpoolerDlgPos" = "2C 00 00 00 00 00 00 00 01 00 00 00 FF FF FF FF"
[HKCU\Software\Microsoft\IdentityCRL\Dynamic Salt]
"Value" = "01 00 00 00 D0 8C 9D DF 01 15 D1 11 8C 7A 00 C0"
[HKCU\Identities]
"Identity Ordinal" = "2"
[HKCU\Software\Microsoft\Windows Mail\Mail]
"Secure Safe Attachments" = "1"
"Default_CodePage" = "28591"
[HKCU\Software\Microsoft\WAB]
"NamedPropCount" = "1"
[HKCU\Software\Microsoft\IAM\Accounts]
"ConnectionSettingsMigrated" = "1"
[HKCU\Software\Microsoft\Windows Mail]
"SpoolerTack" = "0"
[HKCU\Software\Microsoft\IAM]
"Default News Account" = "account{CE54EE8F-8454-4E11-A69C-0E6F9BED6C0A}.oeaccount"
[HKCU\Software\Microsoft\Windows Mail]
"lastrun" = "BF 3E 35 F2 E0 A2 D3 01"
[HKCU\Software\Microsoft\Windows Mail\Mail]
"Safe Attachments" = "1"
[HKCU\Software\Microsoft\IAM]
"Server ID" = "2"
[HKCU\Software\Microsoft\WAB]
"NamedProps" = "04 20 06 00 00 00 00 00 C0 00 00 00 00 00 00 46"
[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\WAB]
"NamedPropCount"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Identities]
"Changing"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Identities]
"IncomingID"
"OutgoingID"
[HKCU\Software\Microsoft\WAB]
"NamedProps"
The process ebhiax.exe:2752 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Xofoywkypu]
"17ghcae2" = "B3 4A A7 0B BF 33 6E EA 59 D5 87 49 EB 7B F5 F9"
Dropped PE files
MD5 | File path |
---|---|
ec36b5a253b8ccbd51e8f956825b1a8f | c:\Users\"%CurrentUserName%"\AppData\Roaming\Ebuzs\ebhiax.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
The Trojan installs the following user-mode hooks in WININET.dll:
HttpSendRequestExA
HttpSendRequestA
HttpSendRequestW
HttpQueryInfoW
InternetWriteFile
HttpSendRequestExW
InternetReadFileExA
InternetReadFileExW
InternetQueryDataAvailable
InternetReadFile
HttpQueryInfoA
InternetCloseHandle
The Trojan installs the following user-mode hooks in CRYPT32.dll:
PFXImportCertStore
The Trojan installs the following user-mode hooks in SSPICLI.DLL:
DecryptMessage
EncryptMessage
DeleteSecurityContext
The Trojan installs the following user-mode hooks in USER32.dll:
GetClipboardData
TranslateMessage
The Trojan installs the following user-mode hooks in WS2_32.dll:
gethostbyname
WSAGetOverlappedResult
WSARecv
send
recv
FreeAddrInfoW
GetAddrInfoW
WSASend
getaddrinfo
closesocket
The Trojan installs the following user-mode hooks in ntdll.dll:
LdrLoadDll
ZwCreateUserProcess
Propagation
VersionInfo
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 2052 | 2560 | 3.8708 | e076526a99e86be1b9a934a76ea9f8ac |
.data | 8192 | 142256 | 142336 | 5.11194 | 5a4b6b2bdd256f1ab2e6a45cad82ff84 |
.rdata | 151552 | 72124 | 72192 | 5.13975 | d9bcc8ce2308e419620eec20ad3ea7be |
.idata | 225280 | 3404 | 3584 | 3.278 | ac6eee8466fd012a307b10f9083a9a71 |
.rsrc | 229376 | 72240 | 72704 | 5.06559 | 96f6ca7a8deab6ab2712196ba19f0da3 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 1
fedbe2a48d3a285a1f5986511f565194
URLs
URL | IP |
---|---|
hxxp://a1363.dscg.akamai.net/pki/crl/products/CodeSignPCA.crl | ![]() |
crl.microsoft.com | ![]() |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /pki/crl/products/CodeSignPCA.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Length: 558
Content-Type: application/pkix-crl
Content-MD5: PMABL5b49EFkwY194FAj2Q==
Last-Modified: Wed, 23 Aug 2017 20:44:38 GMT
ETag: 0x8D4EA67C5E6D892
Server: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0
x-ms-request-id: a02d63f4-0001-0004-5dc6-1cb2f2000000
x-ms-version: 2009-09-19
x-ms-lease-status: unlocked
x-ms-blob-type: BlockBlob
Date: Sun, 11 Feb 2018 02:35:13 GMT
Connection: keep-alive0..*0......0...*.H........0..1.0...U....US1.0...U....Washington1.0...U
....Redmond1.0...U....Microsoft Corporation1 0)..U..."Copyright (c) 20
00 Microsoft Corp.1#0!..U....Microsoft Code Signing PCA..111110211944Z
..420416234935Z.7050...U.#..0...%. K].rT....*.....S.0... .....7.......
..0...*.H...............&..%PIu@.....\0KF....0..^.h9=.1jT,5.L....Ed ..
6.......i.6.xva....oX.^f'....s...!......O...h.1a..Ud);.?....J_...Fu...
.<v.zx..t..h.0JU%.nk;..B[4.?&Zm^..M.!.'...w.u.\T..Tr..Ch.[.z:....#.
..T.4Ct.......,...c..}F..U....:..7J...%.#..D6 . ....G..#....T..G;.....
.HTTP/1.1 200 OK..Content-Length: 558..Content-Type: application/pkix-
crl..Content-MD5: PMABL5b49EFkwY194FAj2Q==..Last-Modified: Wed, 23 Aug
2017 20:44:38 GMT..ETag: 0x8D4EA67C5E6D892..Server: Windows-Azure-Blo
b/1.0 Microsoft-HTTPAPI/2.0..x-ms-request-id: a02d63f4-0001-0004-5dc6-
1cb2f2000000..x-ms-version: 2009-09-19..x-ms-lease-status: unlocked..x
-ms-blob-type: BlockBlob..Date: Sun, 11 Feb 2018 02:35:13 GMT..Connect
ion: keep-alive..0..*0......0...*.H........0..1.0...U....US1.0...U....
Washington1.0...U....Redmond1.0...U....Microsoft Corporation1 0)..U...
"Copyright (c) 2000 Microsoft Corp.1#0!..U....Microsoft Code Signing P
CA..111110211944Z..420416234935Z.7050...U.#..0...%. K].rT....*.....S.0
... .....7.........0...*.H...............&..%PIu@.....\0KF....0..^.h9=
.1jT,5.L....Ed ..6.......i.6.xva....oX.^f'....s...!......O...h.1a..Ud)
;.?....J_...Fu....<v.zx..t..h.0JU%.nk;..B[4.?&Zm^..M.!.'...w.u.\T..
Tr..Ch.[.z:....#...T.4Ct.......,...c..}F..U....:..7J...%.#..D6 . .<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
.text
`.data
.idata
@.reloc
Invalid parameter passed to C runtime function.
>$>,>4><>
0123456789
hXXp://VVV.google.com/
hXXp://VVV.bing.com/
REPORT
HTTP/1.1
RegDeleteKeyExW
gdiplus.dll
GdiplusShutdown
.TJFZAIY]JD^"
?:527|:!;8
!1 (##!(
Kmv`jn`%fnfnzg,bt3crd~da4
1&,$=OJ-:O-
-.ynp<
'2$4>%|903
: 8? 1 !
userenv.dll
del "%s"
if exist "%s" goto d
del /F "%s"
w%fkN
t.Ht$HHt
L$$
m9.td
zcÁ
.QsE>.^
ntdll.dll
KERNEL32.dll
ExitWindowsEx
GetKeyboardState
MsgWaitForMultipleObjects
USER32.dll
CryptGetKeyParam
CryptImportKey
CryptDestroyKey
RegCreateKeyExW
RegCloseKey
RegQueryInfoKeyW
RegDeleteKeyW
RegOpenKeyExW
RegFlushKey
RegEnumKeyExW
ADVAPI32.dll
UrlUnescapeA
PathIsURLW
SHLWAPI.dll
ShellExecuteW
SHELL32.dll
Secur32.dll
ole32.dll
GDI32.dll
WS2_32.dll
CertDeleteCertificateFromStore
CertOpenSystemStoreW
CertCloseStore
CertEnumCertificatesInStore
CertDuplicateCertificateContext
PFXExportCertStoreEx
PFXImportCertStore
CRYPT32.dll
HttpSendRequestExA
HttpQueryInfoA
InternetCrackUrlA
HttpOpenRequestA
HttpEndRequestA
HttpAddRequestHeadersA
WININET.dll
OLEAUT32.dll
NETAPI32.dll
IPHLPAPI.DLL
VERSION.dll
msvcrt.dll
9 9$9(9,9094989
> >$>(>,>0>4>|>
00D0K0_0q0z0
:!:(:,:1:8:^:
\StringFileInfo\xx\%s
urlmon.dll
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\%s
kernel32.dll
launchpadshell.exe
dirclt32.exe
wtng.exe
prologue.exe
pcsws.exe
fdmaster.exe
shell32.dll
cabinet.dll
Wadvapi32.dll
"%s" %s
/c "%s"
C:\Users\"%CurrentUserName%"\AppData\Roaming
C:\Users\"%CurrentUserName%"\AppData\LocalLow
Global\{04316DD5-2E53-4089-2E56-F30E304CD013}
Explorer.EXE_284_rwx_04900000_00048000:
.text
`.data
.idata
@.reloc
Invalid parameter passed to C runtime function.
>$>,>4><>
0123456789
hXXp://VVV.google.com/
hXXp://VVV.bing.com/
REPORT
HTTP/1.1
RegDeleteKeyExW
gdiplus.dll
GdiplusShutdown
.TJFZAIY]JD^"
?:527|:!;8
!1 (##!(
Kmv`jn`%fnfnzg,bt3crd~da4
1&,$=OJ-:O-
-.ynp<
'2$4>%|903
: 8? 1 !
userenv.dll
del "%s"
if exist "%s" goto d
del /F "%s"
w%fkN
t.Ht$HHt
L$$
m9.td
zcÁ
ntdll.dll
KERNEL32.dll
ExitWindowsEx
GetKeyboardState
MsgWaitForMultipleObjects
USER32.dll
CryptGetKeyParam
CryptImportKey
CryptDestroyKey
RegCreateKeyExW
RegCloseKey
RegQueryInfoKeyW
RegDeleteKeyW
RegOpenKeyExW
RegFlushKey
RegEnumKeyExW
ADVAPI32.dll
UrlUnescapeA
PathIsURLW
SHLWAPI.dll
ShellExecuteW
SHELL32.dll
Secur32.dll
ole32.dll
GDI32.dll
WS2_32.dll
CertDeleteCertificateFromStore
CertOpenSystemStoreW
CertCloseStore
CertEnumCertificatesInStore
CertDuplicateCertificateContext
PFXExportCertStoreEx
PFXImportCertStore
CRYPT32.dll
HttpSendRequestExA
HttpQueryInfoA
InternetCrackUrlA
HttpOpenRequestA
HttpEndRequestA
HttpAddRequestHeadersA
WININET.dll
OLEAUT32.dll
NETAPI32.dll
IPHLPAPI.DLL
VERSION.dll
msvcrt.dll
9 9$9(9,9094989
> >$>(>,>0>4>|>
00D0K0_0q0z0
:!:(:,:1:8:^:
\StringFileInfo\xx\%s
urlmon.dll
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\%s
kernel32.dll
launchpadshell.exe
dirclt32.exe
wtng.exe
prologue.exe
pcsws.exe
fdmaster.exe
shell32.dll
cabinet.dll
Wadvapi32.dll
"%s" %s
/c "%s"
C:\Users\"%CurrentUserName%"\AppData\Roaming
C:\Users\"%CurrentUserName%"\AppData\LocalLow
Global\{04316DD5-2E53-4089-2E56-F30E304CD013}
Dwm.exe_528_rwx_010A0000_00048000:
.text
`.data
.idata
@.reloc
Invalid parameter passed to C runtime function.
>$>,>4><>
0123456789
hXXp://VVV.google.com/
hXXp://VVV.bing.com/
REPORT
HTTP/1.1
RegDeleteKeyExW
gdiplus.dll
GdiplusShutdown
.TJFZAIY]JD^"
?:527|:!;8
!1 (##!(
Kmv`jn`%fnfnzg,bt3crd~da4
1&,$=OJ-:O-
-.ynp<
'2$4>%|903
: 8? 1 !
userenv.dll
del "%s"
if exist "%s" goto d
del /F "%s"
w%fkN
t.Ht$HHt
L$$
m9.td
zcÁ
$ .Qg
ntdll.dll
KERNEL32.dll
ExitWindowsEx
GetKeyboardState
MsgWaitForMultipleObjects
USER32.dll
CryptGetKeyParam
CryptImportKey
CryptDestroyKey
RegCreateKeyExW
RegCloseKey
RegQueryInfoKeyW
RegDeleteKeyW
RegOpenKeyExW
RegFlushKey
RegEnumKeyExW
ADVAPI32.dll
UrlUnescapeA
PathIsURLW
SHLWAPI.dll
ShellExecuteW
SHELL32.dll
Secur32.dll
ole32.dll
GDI32.dll
WS2_32.dll
CertDeleteCertificateFromStore
CertOpenSystemStoreW
CertCloseStore
CertEnumCertificatesInStore
CertDuplicateCertificateContext
PFXExportCertStoreEx
PFXImportCertStore
CRYPT32.dll
HttpSendRequestExA
HttpQueryInfoA
InternetCrackUrlA
HttpOpenRequestA
HttpEndRequestA
HttpAddRequestHeadersA
WININET.dll
OLEAUT32.dll
NETAPI32.dll
IPHLPAPI.DLL
VERSION.dll
msvcrt.dll
9 9$9(9,9094989
> >$>(>,>0>4>|>
00D0K0_0q0z0
:!:(:,:1:8:^:
\StringFileInfo\xx\%s
urlmon.dll
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\%s
kernel32.dll
launchpadshell.exe
dirclt32.exe
wtng.exe
prologue.exe
pcsws.exe
fdmaster.exe
shell32.dll
cabinet.dll
Wadvapi32.dll
"%s" %s
/c "%s"
C:\Users\"%CurrentUserName%"\AppData\Roaming
C:\Users\"%CurrentUserName%"\AppData\LocalLow
Global\{04316DD5-2E53-4089-2E56-F30E304CD013}
TPAutoConnect.exe_2068_rwx_00550000_00048000:
.text
`.data
.idata
@.reloc
Invalid parameter passed to C runtime function.
>$>,>4><>
0123456789
hXXp://VVV.google.com/
hXXp://VVV.bing.com/
REPORT
HTTP/1.1
RegDeleteKeyExW
gdiplus.dll
GdiplusShutdown
.TJFZAIY]JD^"
?:527|:!;8
!1 (##!(
Kmv`jn`%fnfnzg,bt3crd~da4
1&,$=OJ-:O-
-.ynp<
'2$4>%|903
: 8? 1 !
userenv.dll
del "%s"
if exist "%s" goto d
del /F "%s"
w%fkN
t.Ht$HHt
L$$
m9.td
zcÁ
ntdll.dll
KERNEL32.dll
ExitWindowsEx
GetKeyboardState
MsgWaitForMultipleObjects
USER32.dll
CryptGetKeyParam
CryptImportKey
CryptDestroyKey
RegCreateKeyExW
RegCloseKey
RegQueryInfoKeyW
RegDeleteKeyW
RegOpenKeyExW
RegFlushKey
RegEnumKeyExW
ADVAPI32.dll
UrlUnescapeA
PathIsURLW
SHLWAPI.dll
ShellExecuteW
SHELL32.dll
Secur32.dll
ole32.dll
GDI32.dll
WS2_32.dll
CertDeleteCertificateFromStore
CertOpenSystemStoreW
CertCloseStore
CertEnumCertificatesInStore
CertDuplicateCertificateContext
PFXExportCertStoreEx
PFXImportCertStore
CRYPT32.dll
HttpSendRequestExA
HttpQueryInfoA
InternetCrackUrlA
HttpOpenRequestA
HttpEndRequestA
HttpAddRequestHeadersA
WININET.dll
OLEAUT32.dll
NETAPI32.dll
IPHLPAPI.DLL
VERSION.dll
msvcrt.dll
9 9$9(9,9094989
> >$>(>,>0>4>|>
00D0K0_0q0z0
:!:(:,:1:8:^:
\StringFileInfo\xx\%s
urlmon.dll
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\%s
kernel32.dll
launchpadshell.exe
dirclt32.exe
wtng.exe
prologue.exe
pcsws.exe
fdmaster.exe
shell32.dll
cabinet.dll
Wadvapi32.dll
X"%s"
"%s" %s
/c "%s"
C:\Users\"%CurrentUserName%"\AppData\Roaming
C:\Users\"%CurrentUserName%"\AppData\LocalLow
Global\{04316DD5-2E53-4089-2E56-F30E304CD013}
conhost.exe_2076_rwx_000D0000_00048000:
.text
`.data
.idata
@.reloc
Invalid parameter passed to C runtime function.
>$>,>4><>
0123456789
hXXp://VVV.google.com/
hXXp://VVV.bing.com/
REPORT
HTTP/1.1
RegDeleteKeyExW
gdiplus.dll
GdiplusShutdown
.TJFZAIY]JD^"
?:527|:!;8
!1 (##!(
Kmv`jn`%fnfnzg,bt3crd~da4
1&,$=OJ-:O-
-.ynp<
'2$4>%|903
: 8? 1 !
userenv.dll
del "%s"
if exist "%s" goto d
del /F "%s"
w%fkN
t.Ht$HHt
L$$
m9.td
zcÁ
ntdll.dll
KERNEL32.dll
ExitWindowsEx
GetKeyboardState
MsgWaitForMultipleObjects
USER32.dll
CryptGetKeyParam
CryptImportKey
CryptDestroyKey
RegCreateKeyExW
RegCloseKey
RegQueryInfoKeyW
RegDeleteKeyW
RegOpenKeyExW
RegFlushKey
RegEnumKeyExW
ADVAPI32.dll
UrlUnescapeA
PathIsURLW
SHLWAPI.dll
ShellExecuteW
SHELL32.dll
Secur32.dll
ole32.dll
GDI32.dll
WS2_32.dll
CertDeleteCertificateFromStore
CertOpenSystemStoreW
CertCloseStore
CertEnumCertificatesInStore
CertDuplicateCertificateContext
PFXExportCertStoreEx
PFXImportCertStore
CRYPT32.dll
HttpSendRequestExA
HttpQueryInfoA
InternetCrackUrlA
HttpOpenRequestA
HttpEndRequestA
HttpAddRequestHeadersA
WININET.dll
OLEAUT32.dll
NETAPI32.dll
IPHLPAPI.DLL
VERSION.dll
msvcrt.dll
9 9$9(9,9094989
> >$>(>,>0>4>|>
00D0K0_0q0z0
:!:(:,:1:8:^:
\StringFileInfo\xx\%s
urlmon.dll
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\%s
kernel32.dll
launchpadshell.exe
dirclt32.exe
wtng.exe
prologue.exe
pcsws.exe
fdmaster.exe
shell32.dll
cabinet.dll
Wadvapi32.dll
"%s" %s
/c "%s"
C:\Users\"%CurrentUserName%"\AppData\Roaming
C:\Users\"%CurrentUserName%"\AppData\LocalLow
Global\{04316DD5-2E53-4089-2E56-F30E304CD013}
conhost.exe_3828_rwx_00480000_00048000:
.text
`.data
.idata
@.reloc
Invalid parameter passed to C runtime function.
>$>,>4><>
0123456789
hXXp://VVV.google.com/
hXXp://VVV.bing.com/
REPORT
HTTP/1.1
RegDeleteKeyExW
gdiplus.dll
GdiplusShutdown
.TJFZAIY]JD^"
?:527|:!;8
!1 (##!(
Kmv`jn`%fnfnzg,bt3crd~da4
1&,$=OJ-:O-
-.ynp<
'2$4>%|903
: 8? 1 !
userenv.dll
del "%s"
if exist "%s" goto d
del /F "%s"
w%fkN
t.Ht$HHt
L$$
m9.td
zcÁ
ntdll.dll
KERNEL32.dll
ExitWindowsEx
GetKeyboardState
MsgWaitForMultipleObjects
USER32.dll
CryptGetKeyParam
CryptImportKey
CryptDestroyKey
RegCreateKeyExW
RegCloseKey
RegQueryInfoKeyW
RegDeleteKeyW
RegOpenKeyExW
RegFlushKey
RegEnumKeyExW
ADVAPI32.dll
UrlUnescapeA
PathIsURLW
SHLWAPI.dll
ShellExecuteW
SHELL32.dll
Secur32.dll
ole32.dll
GDI32.dll
WS2_32.dll
CertDeleteCertificateFromStore
CertOpenSystemStoreW
CertCloseStore
CertEnumCertificatesInStore
CertDuplicateCertificateContext
PFXExportCertStoreEx
PFXImportCertStore
CRYPT32.dll
HttpSendRequestExA
HttpQueryInfoA
InternetCrackUrlA
HttpOpenRequestA
HttpEndRequestA
HttpAddRequestHeadersA
WININET.dll
OLEAUT32.dll
NETAPI32.dll
IPHLPAPI.DLL
VERSION.dll
msvcrt.dll
9 9$9(9,9094989
> >$>(>,>0>4>|>
00D0K0_0q0z0
:!:(:,:1:8:^:
\StringFileInfo\xx\%s
urlmon.dll
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\%s
kernel32.dll
launchpadshell.exe
dirclt32.exe
wtng.exe
prologue.exe
pcsws.exe
fdmaster.exe
shell32.dll
cabinet.dll
Wadvapi32.dll
K"%s"
"%s" %s
/c "%s"
C:\Users\"%CurrentUserName%"\AppData\Roaming
C:\Users\"%CurrentUserName%"\AppData\LocalLow
Global\{04316DD5-2E53-4089-2E56-F30E304CD013}
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Scan a system with an anti-rootkit tool.
- Terminate malicious process(es) (How to End a Process With the Task Manager):
WinMail.exe:3552
ebhiax.exe:2752
%original file name%.exe:3676 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore (38848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Drafts\winmail.fol (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\temp\WindowsMail.pat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\680801A8-00000001.eml (1924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\winmail.fol (592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\temp\edb00002.log (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Sent Items\winmail.fol (592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Deleted Items\winmail.fol (608 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\tmp.edb (1728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabF7A8.tmp (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\winmail.fol (544 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Outbox\winmail.fol (560 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\edb.log (21408 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Local Folders\Inbox\680801A8-00000001.eml:OECustomProperty (260 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\edb.chk (300 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735 (558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarF7A9.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\Backup\temp\WindowsMail.MSMessageStore (99 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735 (816 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat (400 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Mail\edbtmp.log (3466 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ppcrlui_3552_2 (1281 bytes)
C:\Users\"%CurrentUserName%"\ntuser.dat.LOG1 (5272 bytes)
C:\$Directory (96 bytes)
C:\Users\"%CurrentUserName%"\NTUSER.DAT (5384 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IMK214E.bat (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Ebuzs\ebhiax.exe (588 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.