Trojan.Win32.Swrort.3_46e8356147
HEUR:Trojan-Downloader.Win32.Generic (Kaspersky), Gen:Variant.Adware.Graftor.239302 (B) (Emsisoft), Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan-Downloader, Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 46e83561472460d6a84fe146421b10e0
SHA1: 23e82d0f79119d4c5540182e1ba02747782f1517
SHA256: b23775021eaf1fba1a66435cb9b73201f1838b3ac11d92cc0184fa7f43ff6b23
SSDeep: 3072:Ky0UWtWPFxNqhFKZLkCZpgxGFcwJhqRcjMcqoSQyKIAzTxZtH2ngJtgU2Ot3R:KlntWdzkskWpgMiRcjMcRIaZdpTgVOj
Size: 178383 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2015-09-06 11:02:30
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:1756
The Trojan injects its code into the following process(es):
avg1.exe:1820
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:1756 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4XIBGTEV\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\avg1.exe (13484 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\P3LOCQI8\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TCE562QM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\FinalInstaller_dotnet4[1].exe (49345 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\desktop.ini (67 bytes)
The process avg1.exe:1820 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4XIBGTEV\installer[1].php (16760 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TCE562QM\604[1].css (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\P3LOCQI8\progress604[1].css (539 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\header[1].jpg (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TCE562QM\finish[1].png (754 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\604[1].js (180 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\P3LOCQI8\jquery-ui[1].css (12511 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TCE562QM\progress604[1].js (754 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\P3LOCQI8\next[1].png (810 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\ui-bg_flat_75_ffffff_40x100[1].htm (564 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4XIBGTEV\global[1].css (73 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4XIBGTEV\installer[1].htm (9063 bytes)
Registry activity
The process %original file name%.exe:1756 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "47 F3 01 C2 73 82 AB B0 EB 3C 8E 6E CA FA 61 9C"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process avg1.exe:1820 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012015120820151209]
"CacheRepair" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012015120820151209]
"CachePath" = "%USERPROFILE%\Local Settings\History\History.IE5\MSHist012015120820151209\"
"CachePrefix" = ":2015120820151209:"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1C 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012015120820151209]
"CacheOptions" = "11"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "11 BA C7 CF 5E 31 A3 25 80 A4 C3 38 CB D9 4E D1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012015120820151209]
"CacheLimit" = "8192"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following registry key(s):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014031720140318]
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
| MD5 | File path |
|---|---|
| 23846a403ab4e24ee76f5d33ff06d0d3 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\avg1.exe |
| 23846a403ab4e24ee76f5d33ff06d0d3 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\FinalInstaller_dotnet4[1].exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 119950 | 120320 | 4.5126 | c9c195deecb6ad78b9432c5bcaddeb75 |
| .rdata | 126976 | 29822 | 30208 | 3.3481 | e6785e888d6f30093be4da48ad7eb831 |
| .data | 159744 | 13252 | 5632 | 2.17139 | ffd7a3c79c3250eb5bdab11798d43ebc |
| .rsrc | 176128 | 3112 | 3584 | 4.6227 | b886f63c1d63f08ed6403cebe2359db8 |
| .reloc | 180224 | 11036 | 11264 | 3.45258 | ab974dd152d61c49f663fb7264caa0ec |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://d20ssor9owizgr.cloudfront.net/finalinstaller/FinalInstaller_dotnet4.exe | |
| hxxp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4 | |
| hxxp://installer.fastmediaplayer.net/css/global.css | |
| hxxp://installer.fastmediaplayer.net/css/jquery-ui.css | |
| hxxp://installer.fastmediaplayer.net/carriers/604/css/604.css | |
| hxxp://installer.fastmediaplayer.net/carriers/604/js/604.js | |
| hxxp://installer.fastmediaplayer.net/setup_pages/general/progress604/css/progress604.css | |
| hxxp://installer.fastmediaplayer.net/setup_pages/general/progress604/js/progress604.js | |
| hxxp://installer.fastmediaplayer.net/carriers/604/img/header.jpg | |
| hxxp://installer.fastmediaplayer.net/setup_pages/general/img/next.png | |
| hxxp://installer.fastmediaplayer.net/setup_pages/general/img/finish.png | |
| hxxp://installer.fastmediaplayer.net/css/images/ui-bg_flat_75_ffffff_40x100.png | |
| hxxp://installer.fastmediaplayer.net/?pageNumber=0&event=document_ready&description=window_of_setup_loaded&pub_id=433&setup_id=604 | |
| hxxp://bi.fastmediaplayer.net/?pageNumber=0&event=document_ready&description=window_of_setup_loaded&pub_id=433&setup_id=604 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET POLICY Executable served from Amazon S3
Traffic
GET /?pageNumber=0&event=document_ready&description=window_of_setup_loaded&pub_id=433&setup_id=604 HTTP/1.1
Host: bi.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:01 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive0..HTTP/1.1 200 OK..Server: nginx..Date: Tue, 08 Dec 2015 17:28:01 GMT
..Content-Type: text/html; charset=UTF-8..
GET /css/global.css HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:27:59 GMT
Content-Type: text/css
Content-Length: 2778
Last-Modified: Mon, 25 May 2015 16:05:43 GMT
Connection: keep-alive
ETag: "55634857-ada"
Accept-Ranges: bytes* {. margin: 0;. padding: 0;. border: 0;.}...body.{. float: left
;. clear: both;. height: 299px;. width: 498px;.}...footer.{.
float: left;. clear: both;. height: 60px;. width: 498px;.}
...ButtonsRightSide.{. float: right;. margin-right: 25px;.}...bo
ttomHrDiv .{. margin-left: 16px;. width: 462px;. border: 1px;
. color: black;.}...bottomHr .{. border: 1px;. background-col
or: #b8b8b8;. height: 2px;.}...Accept.{. background: url('../set
up_pages/general/img/accept.png') no-repeat center center;. height:
23px;. width: 90px;. cursor: pointer;.}...Finish.{. backgrou
nd: url('../setup_pages/general/img/finish.png') no-repeat center cent
er;. height: 23px;. width: 90px;. cursor: pointer;.}...Exit.{
. background: url('../setup_pages/general/img/exit.png') no-repeat
center center;. height: 23px;. width: 90px;. cursor: pointer;
.}...Cancel.{. background: url('../setup_pages/general/img/cancel.p
ng') no-repeat center center;. height: 23px;. float: left;. m
argin-left: 20px;. width: 90px;. cursor: pointer;.}...Decline.{.
background: url('../setup_pages/general/img/decline.png') no-repea
t center center;. height: 23px;. float: left;. margin-left: 2
0px;. width: 90px;. cursor: pointer;.}...DeclineRight.{. back
ground: url('../setup_pages/general/img/decline.png') no-repeat center
center;. height: 23px;. float: right;. margin-right: 20px;.
width: 90px;. cursor: pointer;.}...Back.{. background: ur<<< skipped >>>
GET /css/jquery-ui.css HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:00 GMT
Content-Type: text/css
Content-Length: 31344
Last-Modified: Mon, 25 May 2015 16:05:43 GMT
Connection: keep-alive
ETag: "55634857-7a70"
Accept-Ranges: bytes/*! jQuery UI - v1.8.24 - 2012-09-28.* hXXps://github.com/jquery/jquer
y-ui.* Includes: jquery.ui.core.css, jquery.ui.accordion.css, jquery.u
i.autocomplete.css, jquery.ui.button.css, jquery.ui.datepicker.css, jq
uery.ui.dialog.css, jquery.ui.progressbar.css, jquery.ui.resizable.css
, jquery.ui.selectable.css, jquery.ui.slider.css, jquery.ui.tabs.css,
jquery.ui.theme.css.* Copyright (c) 2012 AUTHORS.txt; Licensed MIT, GP
L */../* Layout helpers.----------------------------------*/..ui-helpe
r-hidden { display: none; }..ui-helper-hidden-accessible { position: a
bsolute !important; clip: rect(1px 1px 1px 1px); clip: rect(1px,1px,1p
x,1px); }..ui-helper-reset { margin: 0; padding: 0; border: 0; outline
: 0; line-height: 1.3; text-decoration: none; font-size: 100%; list-st
yle: none; }..ui-helper-clearfix:before, .ui-helper-clearfix:after { c
ontent: ""; display: table; }..ui-helper-clearfix:after { clear: both;
}..ui-helper-clearfix { zoom: 1; }..ui-helper-zfix { width: 100%; hei
ght: 100%; top: 0; left: 0; position: absolute; opacity: 0; filter:Alp
ha(Opacity=0); }.../* Interaction Cues.-------------------------------
---*/..ui-state-disabled { cursor: default !important; }.../* Icons.--
--------------------------------*/../* states and images */..ui-icon {
display: block; text-indent: -99999px; overflow: hidden; background-r
epeat: no-repeat; }.../* Misc visuals.--------------------------------
--*/../* Overlays */..ui-widget-overlay { position: absolute; top: 0;
left: 0; width: 100%; height: 100%; }../* IE/Win - Fix animation b<<< skipped >>>
GET /carriers/604/js/604.js HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:00 GMT
Content-Type: application/javascript
Content-Length: 180
Last-Modified: Thu, 03 Sep 2015 14:54:04 GMT
Connection: keep-alive
ETag: "55e85f0c-b4"
Accept-Ranges: byteswindow.external.SetCarrierSuccessRegCheck("CurrentUser\\Software\\Micr
osoft\\Windows\\CurrentVersion\\Uninstall\\InternetQuickAccess");.wind
ow.external.SetCarrierCheckDelay(15000);....
GET /setup_pages/general/progress604/js/progress604.js HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:00 GMT
Content-Type: application/javascript
Content-Length: 754
Last-Modified: Mon, 31 Aug 2015 10:38:14 GMT
Connection: keep-alive
ETag: "55e42e96-2f2"
Accept-Ranges: bytes...$(document).ready(function () {. $("#progressbar").progressbar({
value: 0 });. $("#progressbar > div").css({ 'background': '#b1e
882' });.});..function StartDownload(url) {. PostUserActionsOnSetup
Page($('#hiPageNum').val(), 'MainSetupStarted', "the_download_of_the_m
ain_setup_started");. window.external.DownloadMainSetup(url, 'Downl
oadSetupFinished', 'ProgressBarProgChanged');.}..function ProgressBarP
rogChanged(progress) {. $("#progressbar").progressbar({ value: prog
ress });.}..function DownloadSetupFinished() {. PostUserActionsOnSe
tupPage($('#hiPageNum').val(), 'MainSetupFinished', "the_download_of_t
he_main_setup_finished");. $("#DownloadingText").text("Download Com
pleted Successfully");. $("#FinishDownload").show();.}....
GET /setup_pages/general/img/next.png HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:00 GMT
Content-Type: image/png
Content-Length: 810
Last-Modified: Mon, 25 May 2015 16:05:43 GMT
Connection: keep-alive
ETag: "55634857-32a"
Accept-Ranges: bytes.PNG........IHDR...Z.................tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx..W.KbQ..0..J.6".1..]......AW......Z...r.).1..P.BBP.@7....
........k4.f......gv....<.....w.|.;....t:ggg.f...y.....R...........
u.\...................uoO$..z=..!.H.nw2...(..~.?.a.. .T..x.a......7&.f
. ..#..m..e...S.._I...-X..!9...F&..F..J|..v.].T.....2.......l.^...noo.
.`....B..........o.8..h.......B.4..1.:??.A:X..AO.N...hd..P(.s^__.Z-(..
..yzz.-........b.lz<..l..///.n...pG...j.....\.f.a9.....//...X,....j
.V.U.F.g"....KKK..$....&..P.S.Cb`....].8'.7.V...F..h........`0...$...u
.}...y0rpp....V........X,..N.R.....dsss|.6.R...V..p8VWW.......qr....D"
:....T*.Bagg.........r.._.U.{.v..x..Q...&.iyy.V...g,.3..N........^....
Z[[#.=.......k........>.U.........e..}S.....e.L....\.F......B.TB.T.
T...Y.$...R}>..7.Eq....o..........f..2.L....IEND.B`.....
GET /css/images/ui-bg_flat_75_ffffff_40x100.png HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Server: nginx
Date: Tue, 08 Dec 2015 17:28:01 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Content-Encoding: gzipb6.................1.D{..X..Q.2....m......bVbD..M..........*.OAO'..A..
..t;oa..6|...KT..)..q....8-.......)fJZ..7.(J.v.UB.....OOVz..w...`.l.}.
..._L..v...LDX..'.c..1.@)q*..@...#~...5...4.....0..HTTP/1.1 404 Not Fo
und..Server: nginx..Date: Tue, 08 Dec 2015 17:28:01 GMT..Content-Type:
text/html..Transfer-Encoding: chunked..Connection: keep-alive..Conten
t-Encoding: gzip..b6.................1.D{..X..Q.2....m......bVbD..M...
.......*.OAO'..A....t;oa..6|...KT..)..q....8-.......)fJZ..7.(J.v.UB...
..OOVz..w...`.l.}...._L..v...LDX..'.c..1.@)q*..@...#~...5...4.....0..
GET /installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:27:59 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Content-Encoding: gzip600a..............k..F.......8Y...[.sv.P<..l.....I....MB...PH..#j_.
......$.d.......6.}..{U....../.....eu5................?.......w.......
......lQTE9.M.......\V.u.....7{o.. .../...U[..8<.V..{.j.9..G....t..
lh..........R.:.].:..s....hr.....U^......"......d..i..}4-f?o.......N..
e.W....u>.T.m.?^,:[...|..q.bZ..M.TZ.......|.v.........X...u.v.....K
;[......$......................[.qo.....3.=|?.....MF..l...x..>L..i1
.g..O...gkQ........bv..o>..zW.l.jt..........j..gU...h.5..Y1....[UV.
..i9..G......|Ve.....|.[...>....w....>....e,....M..{.rF..%..7...
...F.].T.&..W....x.*_Tsf.....h.......:.Wo.W..=^^e...L.yu3.m..7[.{.3.,*
.1....7......aw.?.<>.[.N';.8.....~.{.{.............`.......'.?..
......r..;T..jjz........o.v.{'?..=^..K....^....g.}.=}.........>:.?=
<^..s..,.......S.b.O....e...NOz...FxJ.I...t...l^.-oNN'...'....}p...
O......3?..=.,..M.<.M..rv3..w}Iv.\.......Z..g...w..}.zF.E...=....\.
_OG.........uG{[email protected]..|.\v..h....!A"....z.W..G{s.......{..u....[/
.........z.C...W....k..../..3.P}N......m...|su..W..is.N._Z..N9.1.4F...
".55.R 4.........yY........3N....W.........sd...YyT.w..^....X..l.#....
...(....|..J.T....s.*......r..w.......@&.3.9.......n.....r.89<{.h..
.=[.g{>.a.....9g..}.Q. ..;..i.j..:....j.fca.......?c....E.U;...I...
/........%`4...o..g..1..(.>......|Qyo.........b.....q..z...[0..YOo?
.xS...g.ax....g5.*>...(..{.U...y....o?...{g..|...,../..... &...U...
.........3......O:.....F.~o.O.V9.......7 e.Y...... Bg.~k=..p..".......
.Y..6...}`q.y.Z..j.s.d>....g.:...~......YUZ..h..."\..G..u...{S.<<< skipped >>>
GET /carriers/604/css/604.css HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:00 GMT
Content-Type: text/css
Content-Length: 601
Last-Modified: Mon, 31 Aug 2015 10:38:14 GMT
Connection: keep-alive
ETag: "55e42e96-259"
Accept-Ranges: bytesbody .{. background-color: #f0f0f0;.}...topInstallerImage.{. flo
at: left;. clear: both;. background: url('../img/header.jpg') no
-repeat center center;. height: 67px;. width: 498px;.}..#diS1Mai
nTextTop.{. font-size: 20px;. margin-left: 30px;. margin-top:
40px;. height: 50px;. width: 447px;. float: left;. clear:
both; .}..#diS1MainTextBottom.{. font-size: 13px;. font-weight:
bold;. margin-left: 30px;. width: 447px;. height: 122px;.
float: left;.}..#di604desc.{. font-size: 13px;. margin-left: 30p
x;. width: 447px;. height: 117px;.}....
GET /setup_pages/general/progress604/css/progress604.css HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:00 GMT
Content-Type: text/css
Content-Length: 539
Last-Modified: Mon, 31 Aug 2015 10:38:14 GMT
Connection: keep-alive
ETag: "55e42e96-21b"
Accept-Ranges: bytes...#DownloadingText.{. font-size: 13px;. font-weight:bold;. m
argin-left: 45px;. width: 447px;. margin-top: 40px;. height:
30px;. float: left;. clear: both;.}..#progressbarContainer.{.
float: left;. clear: both;. width: 400px;. margin-left: 45px
;.}..#progressbar.{. float: left;. clear: both;. width: 400px
;. height: 20px;.}...#diS5Hr .{. margin-left: 16px;. width: 4
62px;. border: 1px;. color: black;.}..#hrS5 .{. border: 1px;.
background-color: #b8b8b8;. height: 2px;.}....
GET /carriers/604/img/header.jpg HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:00 GMT
Content-Type: image/jpeg
Content-Length: 7657
Last-Modified: Mon, 31 Aug 2015 10:38:14 GMT
Connection: keep-alive
ETag: "55e42e96-1de9"
Accept-Ranges: bytes......JFIF.....H.H.....C..............................................
......................C...............................................
........................C.............................................
........................................H>. .....$....I.H .A.......
...}[email protected].. .............}nj........................Ys..U
A.9.nt .....f...x..Bi....2..7.......8,...4.....H......<...f..p.8a..
..g8\8..0..6{...MY.*...S...l.k.H..L.w...0........l.h...........>.5T
.P..3..c3...l....c$.A\.s...f,..^1...S..Y .0.[1..E.....................
I.................yu...U...$.@....................?.&.................
.............'............................45.P.0!$@.............>.V
.V.V.V.V.V.V...........V.V.V.V.V.V.V.V.V.V.V.V.V.V.V.V.V.V.V.V...V.V.V
.V.V.V.V.V.V.V.V.V.V.V.V.V.V.V.V.V.............V.Q.....?....~O.l~....`
k ......[{./B...... n..(.,.'..... ?xG.......&;.gH..t....(....b........
\V....[u.U.#N...g..XF...l."x.....w.V?`O....3.D.=.;"f....m..8... .|....
..R.m... ...@..........! ...c....|.Afi66.........k.=.UJQ...fm%.l.U....
.2.... ......8....<..SM..".. o...._-......d.......)...-.R.gW.0.1qYB
WE...ee.^E,...g9.....'...OR,...s.WX...?.tt.<`...WZk.......x...OORT.
G..u]k.c....#.....:..f.ACl!.3.Uz.GK.m.`".IT.q...5..I..8.d.t...K.0 ..5.
..Zz.......R...C.*.....(..2W..G<.l.......At>..\[email protected].....{c
..........9...4%..sB\..4%..sB\..4%..sB\..4%..sB\..4%..sB\..4%..sB\..4%
..sB\..4%..sB\..4%..sB\..4%..sB\..4%..sB\..4%..sB\..4%..sB\..4%..sB\..
4%..sB\...q...............................?.......................<<< skipped >>>
GET /setup_pages/general/img/finish.png HTTP/1.1
Accept: */*
Referer: hXXp://installer.fastmediaplayer.net/installer.php?id=604&env=2&setup_version=42.4&srcid=565a68b1-39f6-4c10-8ee4-2211e2f8b0f1&sub_id=wR2RQOIKMSAVNEBOGCL9AVF4&pub_id=433&os=5.1&dotnet=4
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: installer.fastmediaplayer.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 08 Dec 2015 17:28:01 GMT
Content-Type: image/png
Content-Length: 754
Last-Modified: Mon, 25 May 2015 16:05:43 GMT
Connection: keep-alive
ETag: "55634857-2f2"
Accept-Ranges: bytes.PNG........IHDR...Z.................tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx..W..aQ..BdV......f.tB&...LP.ll."1..Id'.(u2.F....Q...D.d..
..1....N.b.V.f'.W..{......s.;......d:..l6;b*x<.B..z....._...N.\.g,.
.^/..O^_9?.....b.x2.0...T.v....{>.c0.N....>H.....V8b6......l...a
.........B...h..www;[email protected]. <.'.r..7.<.O2.....}<?...V...3Y.
...{..t...(....v6.....e ..v2.2L....b2...O..j.`[email protected]../:r..|.[4.M..n
:.....b....Z.V.T..&:.h4JLP...b.Z.....c.X,.......C.....(...6o<.....p
@i2. 7..r..pW..777..J..Y..q~~...![..x<N...>...GK{)..'.$z.@@M..$.
>..t.e.....D.V.I(..9;....A..v.. ..P...:...s.^.rH..7j..84.#.......d"
D"........1..P*..u.[...FW..........$..&..lw..F...`x...V8..KW...p.:6.,.
..{tp.\..'''.....B.R..P..-.P(\\\h.Z..1..A..`..L.R.f>.3....D".......
.CW5M.qp....IEND.B`.HTTP/1.1 200 OK..Server: nginx..Date: Tue, 08 Dec
2015 17:28:01 GMT..Content-Type: image/png..Content-Length: 754..Last-
Modified: Mon, 25 May 2015 16:05:43 GMT..Connection: keep-alive..ETag:
"55634857-2f2"..Accept-Ranges: bytes...PNG........IHDR...Z...........
......tEXtSoftware.Adobe ImageReadyq.e<....IDATx..W..aQ..BdV......f
.tB&...LP.ll."1..Id'.(u2.F....Q...D.d....1....N.b.V.f'.W..{......s.;..
....d:..l6;b*x<.B..z....._...N.\.g,..^/..O^_9?.....b.x2.0...T.v....
{>.c0.N....>H.....V8b6......l...a.........B...h..www;[email protected]. &
lt;.'.r..7.<.O2.....}<?...V...3Y....{..t...(....v6.....e ..v2.2L
....b2...O..j.`[email protected]../:r..|.[4.M..n:.....b....Z.V.T..&:.h4JLP...b.
Z.....c.X,.......C.....(...6o<.....p@i2. 7..r..pW..777..J..Y..q<<< skipped >>>
GET /finalinstaller/FinalInstaller_dotnet4.exe HTTP/1.1
Host: d20ssor9owizgr.cloudfront.net
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 108544
Connection: keep-alive
Date: Tue, 08 Dec 2015 17:22:32 GMT
Last-Modified: Sun, 06 Sep 2015 12:47:03 GMT
ETag: "23846a403ab4e24ee76f5d33ff06d0d3"
Accept-Ranges: bytes
Server: AmazonS3
X-Cache: Miss from cloudfront
Via: 1.1 297739e3d74d139e546f90d2ef5a6887.cloudfront.net (CloudFront)
X-Amz-Cf-Id: GN8C1IB9aI1WsXy-xN_ondR_DJRxbBLvfy9r74Jhi9U6CsADBFDHdw==MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......PE..L...p4.U
................................. ........@.. ........................
[email protected].... ..............
................................................................. ....
........... ..H............text........ ...................... ..`.rsr
c........ ......................@[email protected]............................
[email protected]..........
.................................(....*.r.(......}......}......}....*.
...0..r............(....(.......(....,W.r...po.......(....,B.rc..p (..
.........o......,&.rs..p.$o.......(....,.........o.....*.*...0..'.....
...(..........r...p(....(....-.r...p(.........~....(....-...r...p(....
(....-.r...p(.........r...p~....(..........:....r...p.H..........(....
....r...p....((.......(&.......(C.......r...p....(0.......r...p....(..
.......(A........r...p.....(%........(9........(.........(.........(1.
.......(.........(A........((........(#........(=........(A........r..
.p.....(*........(.........(1........(0........(#........(.........(/.
.......(0........()....... (D.......!r...p...."(7.......#(........$(6.
......%(/.......&r...p....'( .......((........)r...p....*(8....... ( .
......,(........-(.........(......../(;.......0(C.......1(B.......2(4.
......3(........4(........5(A.......6(@.......7r...p....8(D.......9(B.
......:(3.......;r...p....<(4.......=r...p....>(<.......?<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
@.reloc
xSSSh
FTPjKS
FtPj;S
C.PjRV
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
portuguese-brazilian
operator
GetProcessWindowStation
Software\Microsoft\NET Framework Setup\NDP\v2.0.50727
KERNEL32.dll
USER32.dll
RegCloseKey
ADVAPI32.dll
GetCPInfo
GetProcessHeap
c:\%original file name%.exe
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="hXXp://VVV.w3.org/2001/XMLSchema-instance"><assemblyIdentity version="1.0.0.0" name="hello.world"></assemblyIdentity><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS>*0004080<0
nKERNEL32.DLL
mscoree.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
hXXp://d20ssor9owizgr.cloudfront.net/finalinstaller/FinalInstaller_dotnet
fastmediaplayer.net
avg1.exe_1820_rwx_00950000_00014000:
S.HW#r']%%y8
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1756
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4XIBGTEV\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\avg1.exe (13484 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\P3LOCQI8\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TCE562QM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\FinalInstaller_dotnet4[1].exe (49345 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4XIBGTEV\installer[1].php (16760 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TCE562QM\604[1].css (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\P3LOCQI8\progress604[1].css (539 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\header[1].jpg (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TCE562QM\finish[1].png (754 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\604[1].js (180 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\P3LOCQI8\jquery-ui[1].css (12511 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TCE562QM\progress604[1].js (754 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\P3LOCQI8\next[1].png (810 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WPUZ41YV\ui-bg_flat_75_ffffff_40x100[1].htm (564 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4XIBGTEV\global[1].css (73 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4XIBGTEV\installer[1].htm (9063 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.