Trojan-PSW.Win32.Fareit_1424df189c
Trojan.Win32.Cutwail.cex (Kaspersky), Trojan.Win32.Generic!BT (VIPRE), Trojan-PSW.Win32.Fareit.FD, TrojanPSWFareit.YR, GenericInjector.YR (Lavasoft MAS)
Behaviour: Trojan-PSW, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
MD5: 1424df189cf82cd21e6929eefb0da760
SHA1: b6074ec4d83da36da521931c917fbe844c3ed511
SHA256: 2c49b300b7b6a69f897f1b0bbc0ae894035c4367aa6149a894687da203b2f53a
SSDeep: 768:iIdb VltyLTE9gDNgpvfxyRpigLVhKtXaXo4CK9:iIsRcIeDNgLyKgLVhKtl4b9
Size: 38400 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2008-11-02 19:13:23
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan-PSW. Trojan program intended for stealing users passwords.
Payload
No specific payload has been found.
Process activity
The Trojan-PSW creates the following process(es):
Reader_sl.exe:1064
wuauclt.exe:344
jusched.exe:1056
The Trojan-PSW injects its code into the following process(es):
%original file name%.exe:1572
File activity
The process wuauclt.exe:344 makes changes in the file system.
The Trojan-PSW creates and/or writes to the following file(s):
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.chk (100 bytes)
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.log (3576 bytes)
%WinDir%\SoftwareDistribution\DataStore\DataStore.edb (100 bytes)
The Trojan-PSW deletes the following file(s):
%WinDir%\SoftwareDistribution\DataStore\Logs\tmp.edb (0 bytes)
The process %original file name%.exe:1572 makes changes in the file system.
The Trojan-PSW creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\teasing-video[1].htm (1542 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\vandeks[1].htm (257 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\sydney[1].htm (357 bytes)
%Documents and Settings%\%current user%\jyrvicewyxmu.exe (38 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\urantiaproject[1].htm (756 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\hostphd.com[1].htm (24 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (1085 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\theprintinghouseltd.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\empordalia[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\trinity-works[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@bigtopmultimedia[1].txt (239 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (241 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\403[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@sdlp[1].txt (214 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (251 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\unitedearthgroup[1].htm (1 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@starmedia[1].txt (223 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@goodvaluecenter[1].txt (237 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\sortedorganizing[1].htm (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\aciuba.com[1].htm (73 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\sun-ele.co[1].htm (12 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@plus[1].txt (214 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@appelfarm[1].txt (225 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (235 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1844237615-1960408961-1801674531-1003\c5b88721db08c824db69d0bbc702beb8_75ed9567-aa58-4c8e-a8ea-3cad7c47ab03 (881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\solutioncorp[1].htm (4184 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\robertmcintyre.com[1].htm (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\cath4choice[1].htm (33 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\shipeliteexpress[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\combine.or[1].htm (1 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@altonhousehotel[1].txt (237 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@glmghotels[1].txt (227 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@ctr4process[1].txt (230 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (214 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@traderush[1].txt (268 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@agence-des-druides[1].txt (175 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\coketh[1].htm (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\sarpy[1].htm (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (317 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\cksglobal[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\enzoyrodrigo.com[1].htm (586 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (20720 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\lexjuridica[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\index[1].htm (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\wkhk[1].htm (1832 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@agence-des-druides[2].txt (358 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (239 bytes)
The Trojan-PSW deletes the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\theprintinghouseltd.co[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\vandeks[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\robertmcintyre.com[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\cath4choice[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\aciuba.com[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\unitedearthgroup[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\cksglobal[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\combine.or[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\hostphd.com[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\shs-sales.co[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\sarpy[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\lexjuridica[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\trinity-works[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@agence-des-druides[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\sun-ele.co[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\enzoyrodrigo.com[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\index[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\empordalia[1].htm (0 bytes)
The process jusched.exe:1056 makes changes in the file system.
The Trojan-PSW creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\jusched.log (347 bytes)
Registry activity
The process Reader_sl.exe:1064 makes changes in the system registry.
The Trojan-PSW creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process %original file name%.exe:1572 makes changes in the system registry.
The Trojan-PSW creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"2312304364" = "DD 07 0C 00 00 00 16 00 08 00 0B 00 2B 00 6A 03"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"jyrvicewyxmuzap" = "C2 9A 72 4A 22 F9 D1 A9 F4 CC A4 7C 54 2C 04 DB"
"AppManagement" = "23 FA D2 AA 82 5A 32 7D 55 2D 05 DC B4 8C 64 3C"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B9 88 78 14 FC 13 C1 23 DD 77 1C 75 6F 73 B2 79"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
To automatically run itself each time Windows is booted, the Trojan-PSW adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"jyrvicewyxmu" = "%Documents and Settings%\%current user%\jyrvicewyxmu.exe"
The Trojan-PSW modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan-PSW modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan-PSW modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan-PSW deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Network activity (URLs)
| URL | IP |
|---|---|
| hxxp://upsilon89.com/ | |
| hxxp://myfilecenter.com/ | |
| hxxp://mattiussiecologia.com/ | |
| hxxp://cabooseonline.com/ | |
| hxxp://totalearthcare.com.au/ | |
| hxxp://agence-des-druides.com/ | |
| hxxp://saios.net/ | |
| hxxp://mandi-man.com/ | |
| hxxp://denville.ca/ | |
| hxxp://shs-sales.co.uk/ | |
| hxxp://solutioncorp.com/ | |
| hxxp://brookfarm.com.au/ | |
| hxxp://nuritech.com/ | |
| hxxp://combine.or.id/ | |
| hxxp://servico-ind.com/ | |
| hxxp://xing-group.com/ | |
| hxxp://trinity-works.com/ | |
| hxxp://servico-ind.com/index.asp | |
| hxxp://vandeks.com/ | |
| hxxp://skaner.com.pl/ | |
| hxxp://teasing-video.com/ | |
| hxxp://churchsupplies.net/ | |
| hxxp://naijagurus.com/ | |
| hxxp://areafor.com/ | |
| hxxp://sortedorganizing.com/ | |
| hxxp://digpro.se/ | |
| hxxp://cbsprinting.com.au/ | |
| hxxp://sspackaginggroup.com/ | |
| hxxp://cath4choice.org/ | |
| hxxp://urantiaproject.com/ | |
| hxxp://glmghotels.com/ | |
| hxxp://y8k6h.x.incapdns.net/ | |
| hxxp://optiver.com.au/ | |
| hxxp://cksglobal.net/ | |
| hxxp://aciuba.com.br/ | |
| hxxp://wkhk.net/ | |
| hxxp://www.optiver.com/sydney/ | |
| hxxp://starmedia.ca/ | |
| hxxp://agrarno.ru/ | |
| hxxp://bigtopmultimedia.com/ | |
| hxxp://plus.ba/ | |
| hxxp://altonhousehotel.com/ | |
| hxxp://lognetic.com/ | |
| hxxp://geodecisions.com/ | |
| hxxp://penavision.co.in/ | |
| hxxp://stop-ddos.me/ | |
| hxxp://merceorti.com/ | |
| hxxp://christybarry.com/ | |
| hxxp://christybarry.com/cgi-sys/suspendedpage.cgi | |
| hxxp://tessera.co.jp/ | |
| hxxp://sdlp.ie/ | |
| hxxp://goodvaluecenter.com/ | |
| hxxp://buzzkillmedia.com/ | |
| hxxp://asterisk.com.sg/ | |
| hxxp://hostphd.com.br/ | |
| hxxp://beechwoodmetalworks.com/ | |
| hxxp://ctr4process.org/ | |
| hxxp://acicinvestor.ca/ | |
| hxxp://s2s.fr/ | |
| hxxp://asj.co.jp/ | |
| hxxp://istanbultarim.com.tr/ | |
| hxxp://fleshercorp.com/ | |
| hxxp://rea-soft.ru/ | |
| hxxp://ctr4process.org/403.shtml | |
| hxxp://tvndra.net/ | |
| hxxp://ryumachi-jp.com/ | |
| hxxp://toddpipe.com/ | |
| hxxp://shakeyspizza.ph/ | |
| hxxp://marcusgrimes.co.uk/ | |
| hxxp://sun-ele.co.jp/ | |
| hxxp://unslp.edu.bo/ | |
| hxxp://coketh.com/ | |
| hxxp://sarpy.com/ | |
| hxxp://youjoomla.com/ | |
| hxxp://victoria.com.pl/ | |
| hxxp://robertmcintyre.com.au/ | |
| hxxp://nasz-sklep.pl/ | |
| hxxp://vanguardpkg.com/ | |
| hxxp://authentica-travel.com/ | |
| hxxp://shipeliteexpress.com/ | |
| hxxp://avant-ime.com/ | |
| hxxp://empordalia.com/ | |
| hxxp://racknstackwarehouse.com.au/ | |
| hxxp://appelfarm.org/ | |
| hxxp://tutuji-saitama.com/ | |
| hxxp://link-list-uk.com/ | |
| hxxp://sztartufi.com/ | |
| hxxp://theprintinghouseltd.co.uk/ | |
| hxxp://unitedearthgroup.com/ | |
| hxxp://mastechn.com/ | |
| hxxp://automa.it/ | |
| hxxp://enzoyrodrigo.com.br/ | |
| hxxp://etcycles.com/ | |
| hxxp://hinnenwiese.de/ | |
| hxxp://isle-karnataka.org/ | |
| hxxp://careerstodaycanada.com/ | |
| hxxp://ezmedi.com/ | |
| hxxp://calvarycemeterydayton.org/ | |
| hxxp://csmbc.org/ | |
| hxxp://caeweb.com/ | |
| hxxp://lexjuridica.com/ | |
| hxxp://rt-printing.com/ | |
| hxxp://cromwellharbor.com/ | |
| hxxp://cfgreaterjackson.org/ | |
| hxxp://trivax.com/ | |
| hxxp://arpeges.org/ | |
| hxxp://coe.pku.edu.cn/ | |
| hxxp://constancehotels.com/ | |
| hxxp://e-ciencia.com/ | |
| hxxp://syntrinsic.com/ | |
| hxxp://easytrip.net/ | |
| hxxp://ask-romein.com/ | |
| hxxp://dataweave.com.au/ | |
| hxxp://moshk.com/ | |
| hxxp://vivawebinternet.com.br/ | |
| hxxp://5-market.com/ | |
| hxxp://mojos.com/ | |
| hxxp://mtrx.net/ | |
| hxxp://mediadevelopment.com/ | |
| hxxp://omikrondokk.hu/ | |
| hxxp://lavozdelared.net/ | |
| hxxp://dicre.com/ | |
| hxxp://gocommunications.ch/ | |
| hxxp://cabv.com/ | |
| hxxp://imperiumhomes.com/ | |
| hxxp://392430.com/ | |
| hxxp://solutiodesign.com/ | |
| hxxp://petairusa.com/ | |
| hxxp://dialadinner.com.hk/ | |
| hxxp://slow-db.com/ | |
| hxxp://atlantis-shisui.com/ | |
| hxxp://cvswl.org/ | |
| hxxp://bangertcomputer.com/ | |
| hxxp://aedsrl.it/ | |
| hxxp://bedfordlaw.com/ | |
| hxxp://ans-service.com/ | |
| hxxp://3moulins.com/ | |
| hxxp://olganon.org/ | |
| hxxp://roselani.com/ | |
| hxxp://mail.kanglin.com.tw/ | |
| hxxp://toyotafound.or.jp/ | |
| hxxp://alpes-campings.com/ | |
| hxxp://atlasztravel.hu/ | |
| hxxp://putujemouevropu.org/ | |
| hxxp://jidoucenter.com/ | |
| hxxp://poyrazoto.com.tr/ | |
| hxxp://ramybrook.com/ | |
| hxxp://searrp.org/ | |
| hxxp://palmbeachbeaute.com/ | |
| hxxp://camphillscotland.org.uk/ | |
| hxxp://thlabel.com/ | |
| hxxp://capacitacionypnd.com/ | |
| hxxp://aschroofing.com/ | |
| hxxp://slakes.net/ | |
| hxxp://bradleybray.com.au/ | |
| hxxp://reflex.com.pl/ | |
| hxxp://watermaticcoolers.com/ | |
| hxxp://kitchencollage.com/ | |
| hxxp://schuster-treppen.de/ | |
| hxxp://worldtourism.com.au/ | |
| hxxp://maybellecarter.com/ | |
| hxxp://cimtech.ca/ | |
| hxxp://saweightlosscenter.com/ | |
| hxxp://mjfdesigns.com/ | |
| hxxp://hotelkunlun.com/ | |
| hxxp://acuprint.com/ | |
| hxxp://aandporchids.com/ | |
| hxxp://koeppl.com/ | |
| hxxp://rokayfloral.com/ | |
| hxxp://technicorp.co.cr/ | |
| hxxp://earthworks-j.com/ | |
| hxxp://rabinco.com.my/ | |
| hxxp://iberclean.com/ | |
| hxxp://saudireadymix.com.sa/ | |
| hxxp://invertek.co.uk/ | |
| hxxp://minority-inc.com/ | |
| hxxp://norm-fasteners.com.tr/ | |
| hxxp://peralesaguiar.com.ar/ | |
| hxxp://exo2.co.uk/ | |
| hxxp://internationalcabinets.com.au/ | |
| hxxp://rentinmarin.com/ | |
| hxxp://uwlowcountry.org/ | |
| hxxp://dpmsystems.com/ | |
| hxxp://insulationaustralia.com.au/ | |
| hxxp://uhren-schmuckhaus-moeckel.de/ | |
| hxxp://easy-networx.de/ | |
| hxxp://chicanofederation.org/ | |
| hxxp://imsa.com.ar/ | |
| hxxp://solustan.com/ | |
| hxxp://agro-trans.biz/ | |
| hxxp://luksus.net.pl/ | |
| hxxp://monsoybenet.com/ | |
| hxxp://provang.com/ | |
| hxxp://gvcustomsoftware.com.au/ | |
| hxxp://telemkting.com/ | |
| hxxp://isisgroup.co.uk/ | |
| hxxp://adaptworkforce.com/ | |
| hxxp://businessengineers.de/ | |
| hxxp://admik.ru/ | |
| hxxp://autocidade.com.br/ | |
| hxxp://alshares.com/ | |
| hxxp://thevelvetstore.com/ | |
| hxxp://diving-bg.com/ | |
| hxxp://tinnitus.se/ | |
| hxxp://rokyu.net/ | |
| hxxp://newfocas.co.uk/ | |
| hxxp://ohnosha.co.jp/ | |
| hxxp://progir.com/ | |
| hxxp://cpi.com.ar/ | |
| hxxp://waco-cccc.com/ | |
| hxxp://inglett-stubbs.com/ | |
| hxxp://sankalpplacement.com/ | |
| hxxp://ekahosting.com/ | |
| hxxp://marinescape.co.nz/ | |
| hxxp://mc-integ.co.uk/ | |
| hxxp://afsservice.com/ | |
| hxxp://rdidiamonds.com/ | |
| hxxp://ipoaonline.org/ | |
| hxxp://littleblue.com/ | |
| hxxp://computerlogicdirect.com/ | |
| hxxp://plubiz.com/ | |
| hxxp://oremc.com/ | |
| hxxp://rmslive.com/ | |
| hxxp://ibntel.com/ | |
| hxxp://roulottesdecampagne.com/ | |
| hxxp://sps-jia.cz/ | |
| hxxp://snowboardweb.net/ | |
| hxxp://dtc-telecom.co.uk/ | |
| hxxp://musawa.ps/ | |
| hxxp://marcanthony.com/ | |
| hxxp://pluto.com.au/ | |
| hxxp://unitrix.sk/ | |
| hxxp://narsaria.com/ | |
| hxxp://korsil.ru/ | |
| hxxp://ray-jp.com/ | |
| hxxp://gazdic.com/ | |
| hxxp://zanyhost.com/ | |
| hxxp://dominos.co.id/ | |
| hxxp://goodwins-removals.com/ | |
| hxxp://3int.net/ | |
| hxxp://tacsa.ws/ | |
| hxxp://aozoramame.com/ | |
| hxxp://mortgageleads.com/ | |
| hxxp://247petreturn.com/ | |
| hxxp://safedoormatic.com/ | |
| hxxp://casino-top.net/ | |
| hxxp://tomgegax.com/ | |
| hxxp://fsesudmuntenia.ro/ | |
| hxxp://efoa.org/ | |
| hxxp://sagsheriff.com/ | |
| hxxp://carteluz.com.ar/ | |
| hxxp://the-marketing-company.at/ | |
| hxxp://lelund.com/ | |
| hxxp://locbem.com.br/ | |
| hxxp://nnppd.com/ | |
| hxxp://neaco.co.uk/ | |
| hxxp://werta.net/ | |
| hxxp://magnatekenterprises.com/ | |
| hxxp://hwplan.org/ | |
| hxxp://ashleyquinncpas.com/ | |
| maki-hs.com | |
| counsellingpsychotherapytoronto.com | |
| alt1.aspmx.l.google.com | |
| authoritative.net | |
| ns10.worldnic.com | |
| kurecci.or.jp | |
| dns.other-world.com | |
| in1.smtp.messagingengine.com | |
| www.traderush.com | |
| bluecolash.com | |
| s-style.co.jp | |
| www.myfilecenter.com | |
| ibcd.com.br | |
| pekachemie.com | |
| limaingenieriayconstruccion.com | |
| vitalur.by | |
| mxs.mail.ru | |
| www.avant-ime.com | |
| norakuroya.com | |
| alt4.gmail-smtp-in.l.google.com | |
| audio-direkt.net | |
| www.servico-ind.com | |
| natvideo.com | |
| doggybag.org | |
| atanor.ru | |
| allaroundbouncing.com | |
| gmail-smtp-in.l.google.com | |
| ecotechsystem.com | |
| hpp-services.com | |
| born-club.com | |
| aethora.com | |
| www.trinity-works.com | |
| craigrichards.com | |
| iwantsex.org | |
| nataliecurtiss.com | |
| konishi-hp.com | |
| ns-fra.proofpoint.com | |
| tenpole.com | |
| pro-networks.co.uk | |
| mxa-00105401.gslb.pphosted.com | |
| vivare.nl | |
| gjk.com.pl | |
| ns87.hostia.name | |
| www.cbsprinting.com.au | |
| www.solutioncorp.com | |
| www.beechwoodmetalworks.com | |
| tokushima-med.jrc.or.jp | |
| www.ctr4process.org | |
| theartofhair.com | |
| agrohorizonte.com.ar | |
| www.wkhk.net | |
| mx.directgroup.org | |
| bredainternet.nl | |
| blagotvoritel.org | |
| www.saios.net | |
| iaiglobal.or.id | |
| fineartsassociation.org | |
| mail7.digitalwaves.co.nz | |
| iwamoto-hiroyoshi.com | |
| aspmx4.googlemail.com | |
| smtp.live.com | |
| www.vanguardpkg.com | |
| bospianoservice.nl | |
| trenpalau.com | |
| aspmx3googlemail.com | |
| pointopines.com | |
| nichedictionary.com | |
| aspmx2.googlemail.com | |
| aspmx.l.google.com | |
| meubles-jacquelin.com | |
| meridies.org | |
| manuyantralaya.com | |
| alt2.aspmx.l.google.com | |
| toutenmeuse.com | |
| hoyuu.com | |
| aspmx5.googlemail.com | |
| hifuken.com | |
| mxb-00105401.gslb.pphosted.com |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
wuauclt.exe:344
- Delete the original Trojan-PSW file.
- Delete or disinfect the following files created/modified by the Trojan-PSW:
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.chk (100 bytes)
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.log (3576 bytes)
%WinDir%\SoftwareDistribution\DataStore\DataStore.edb (100 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\teasing-video[1].htm (1542 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\vandeks[1].htm (257 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\sydney[1].htm (357 bytes)
%Documents and Settings%\%current user%\jyrvicewyxmu.exe (38 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\urantiaproject[1].htm (756 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\hostphd.com[1].htm (24 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[1].txt (1085 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\theprintinghouseltd.co[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\empordalia[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\trinity-works[1].htm (16 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@bigtopmultimedia[1].txt (239 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (241 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\403[1].htm (4 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@sdlp[1].txt (214 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (251 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\suspendedpage[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\unitedearthgroup[1].htm (1 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@starmedia[1].txt (223 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@goodvaluecenter[1].txt (237 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\sortedorganizing[1].htm (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\aciuba.com[1].htm (73 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\sun-ele.co[1].htm (12 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@plus[1].txt (214 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@appelfarm[1].txt (225 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (235 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1844237615-1960408961-1801674531-1003\c5b88721db08c824db69d0bbc702beb8_75ed9567-aa58-4c8e-a8ea-3cad7c47ab03 (881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\solutioncorp[1].htm (4184 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\robertmcintyre.com[1].htm (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHCTSNI3\cath4choice[1].htm (33 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IFWNIZW9\shipeliteexpress[1].htm (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\combine.or[1].htm (1 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@altonhousehotel[1].txt (237 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@glmghotels[1].txt (227 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@ctr4process[1].txt (230 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (214 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@traderush[1].txt (268 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@agence-des-druides[1].txt (175 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\coketh[1].htm (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\shs-sales.co[1].htm (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\sarpy[1].htm (20 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@shipeliteexpress[2].txt (317 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\cksglobal[1].htm (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2J4LCDS9\enzoyrodrigo.com[1].htm (586 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (20720 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\lexjuridica[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\index[1].htm (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\GZWRQVUZ\wkhk[1].htm (1832 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@agence-des-druides[2].txt (358 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (239 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\jusched.log (347 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"jyrvicewyxmu" = "%Documents and Settings%\%current user%\jyrvicewyxmu.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.