Adware.Win32.Downware.FD, Trojan.NSIS.StartPage.FD, AdwareDownware.YR (Lavasoft MAS)Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 91c32adf711b653340f27fb9f26735be
SHA1: ee94a52451a46bec408d46a85a608edb210de4e2
SHA256: 021272a9322d26453f475600456c7ecca1778b4bc7ea2394e057432fe1179337
SSDeep: 6144:ssi10xLe0bRUc9EBVE4TQ131MUlKqrXHbst Zvt:m1Sl9UCELE4mxRM Zvt
Size: 262984 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-12-06 00:50:46
Analyzed on: WindowsXP SP3 32-bit
Summary: Adware. Delivers advertising content in a manner or context that may be unexpected and unwanted by users. Many adware applications also perform tracking functions. Users may want to remove adware if they object to such tracking, do not wish to see the advertising caused by the program or are frustrated by its effects on system performance.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Adware creates the following process(es):No processes have been created.The Adware injects its code into the following process(es):
%original file name%.exe:388
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:388 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsa3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsa3.tmp\inetc3.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv2.tmp (8886 bytes)
The Adware deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsf1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsa3.tmp\gC0 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsa3.tmp (0 bytes)
Registry activity
The process %original file name%.exe:388 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\1ClickDownload]
"LastInstall0" = "30510568"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\1ClickDownload]
"UID" = "282948265"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C1 8B E4 D6 07 70 75 10 6B 10 F4 F5 CD D3 D4 22"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
MD5 | File path |
---|---|
c17103ae9072a06da581dec998343fc1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsa3.tmp\System.dll |
9d8ce05f532dc7b5742831ec8a63c2d8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsa3.tmp\inetc3.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Adware file.
- Delete or disinfect the following files created/modified by the Adware:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsa3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsa3.tmp\inetc3.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv2.tmp (8886 bytes) - Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 23130 | 23552 | 4.44841 | 0bc2ffd32265a08d72b795b18265828d |
.rdata | 28672 | 4496 | 4608 | 3.59163 | f179218a059068529bdb4637ef5fa28e |
.data | 36864 | 110488 | 1024 | 3.26405 | 975304d6dd6c4a4f076b15511e2bbbc0 |
.ndata | 147456 | 372736 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rsrc | 520192 | 16592 | 16896 | 4.13874 | 8091b1378d82973015f802c93eb88bab |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 131
69a0a458647b3436892cf9f2f126c252
f6dfcb76ad7437d92c5afb7f0df46e1e
da0bd3c1e61660738d11b8637009704c
274a292adfe75bf2ebb7ec280e41498b
5237ce96c640fe6ac6cc74c0dcbfcaa3
2f7774bf5fd92c51f79f4ba883a3688d
19e571b63f058f8639368efa0b7e7a5d
92f168a6a50962338197ed28079023e0
0c8c597eef67709d9532291efe74ce10
eb7796e86be9bedaa30b7cfffeefe81f
02970495e406b99d8bf8e992a8ee80e8
58370f3c58561f8bfb46cf3e2f91f4b3
7bf0d359dbc0f2394d811bf4ca178d0c
6595f1898fe06bd80ec59d9ccd70bda2
9f979219e6f2be6b0d69c699192e9c98
fcb0905f624625fc4839a6a4edcb6fd4
56f587e1afeb682b0688dfcce19ebed9
c63e670ed1d501559890afdc5ccb3d56
bc4b8c6d6165113c61fb4744140a49c8
9cb467ff929aa9ea250e2501ade5f077
60ba6445ca5e44ce37f9175d5b71252a
558629b6feeb66bfdcef6c99e3c570a3
70734d89308e9da071e1e5bf18547b14
ba27f4cf2fd8becf08d48c952b1e6515
854785be31dfdacde5e34c6ed71c99a6
Network Activity
URLs
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Adware connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_388:
.text
.text
`.rdata
`.rdata
@.data
@.data
.ndata
.ndata
.rsrc
.rsrc
uDSSh
uDSSh
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
GetWindowsDirectoryA
KERNEL32.dll
KERNEL32.dll
ExitWindowsEx
ExitWindowsEx
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
SHFileOperationA
SHFileOperationA
ShellExecuteA
ShellExecuteA
SHELL32.dll
SHELL32.dll
RegEnumKeyA
RegEnumKeyA
RegCreateKeyExA
RegCreateKeyExA
RegCloseKey
RegCloseKey
RegDeleteKeyA
RegDeleteKeyA
RegOpenKeyExA
RegOpenKeyExA
ADVAPI32.dll
ADVAPI32.dll
COMCTL32.dll
COMCTL32.dll
ole32.dll
ole32.dll
VERSION.dll
VERSION.dll
verifying installer: %d%%
verifying installer: %d%%
unpacking data: %d%%
unpacking data: %d%%
... %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
~nsu.tmp
%u.%u%s%s
%u.%u%s%s
RegDeleteKeyExA
RegDeleteKeyExA
%s=%s
%s=%s
*?|/":
*?|/":
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsa3.tmp\nsDialogs.dll
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsa3.tmp\nsDialogs.dll
rent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
rent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsa3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsa3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsa3.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsa3.tmp
.torrent
.torrent
0D4BBA55DB2BDF.torrent
0D4BBA55DB2BDF.torrent
AUTODESK.2013.PRODUCTS.UNIVERSAL
AUTODESK.2013.PRODUCTS.UNIVERSAL
}1.sK
}1.sK
/v%6UGN
/v%6UGN
%u#"$_
%u#"$_
lwW =).qy;
lwW =).qy;
G.Cly
G.Cly
WINDOWS
WINDOWS
skip.bmp", i 0, i 0, i 0, i 0x2000|0x0010) i.s
skip.bmp", i 0, i 0, i 0, i 0x2000|0x0010) i.s
1507576
1507576
iles\1ClickDownload\1ClickDownloader.exe
iles\1ClickDownload\1ClickDownloader.exe
13.PRODUCTS.UNIVERSAL
13.PRODUCTS.UNIVERSAL
DA754ECE00BB799CD605671E520D4BBA55DB2BDF.torrent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
DA754ECE00BB799CD605671E520D4BBA55DB2BDF.torrent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
282948265
282948265
UCTS.UNIVERSAL
UCTS.UNIVERSAL
BB799CD605671E520D4BBA55DB2BDF.torrent
BB799CD605671E520D4BBA55DB2BDF.torrent
rrent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
rrent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
32790940
32790940
711b653340f27fb9f26735be.exe
711b653340f27fb9f26735be.exe
E00BB799CD605671E520D4BBA55DB2BDF.torrent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
E00BB799CD605671E520D4BBA55DB2BDF.torrent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
2829482
2829482
06406250
06406250
1900786
1900786
235210132
235210132
DESK.2013.PRODUCTS.UNIVERSAL
DESK.2013.PRODUCTS.UNIVERSAL
ownload.sweetpacks.com/simsdm/bundle/
ownload.sweetpacks.com/simsdm/bundle/
2031950
2031950
2359552
2359552
am Files\Internet Explorer\iexplore.exe
am Files\Internet Explorer\iexplore.exe
00BB799CD605671E520D4BBA55DB2BDF.torrent
00BB799CD605671E520D4BBA55DB2BDF.torrent
E520D4BBA55DB2BDF.torrent
E520D4BBA55DB2BDF.torrent
c:\%original file name%.exe
c:\%original file name%.exe
%Documents and Settings%\%current user%\Desktop
%Documents and Settings%\%current user%\Desktop
%Program Files%\1ClickDownload
%Program Files%\1ClickDownload
a3.tmp
a3.tmp
%original file name%.exe
%original file name%.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsf1.tmp
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsf1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
hXXp://files.download1click.ws/MainPackFA2703.exe
hXXp://files.download1click.ws/MainPackFA2703.exe
hXXp://files.download1click.ws/gzip2.exe
hXXp://files.download1click.ws/gzip2.exe
hXXp://data.downloadstarter.net/
hXXp://data.downloadstarter.net/
hXXp://files.download1click.ws/ARURUSetup.exe
hXXp://files.download1click.ws/ARURUSetup.exe
hXXp://files.download1click.ws/ARUARSetup.exe
hXXp://files.download1click.ws/ARUARSetup.exe
hXXp://files.download1click.ws/BTB0612.exe
hXXp://files.download1click.ws/BTB0612.exe
hXXp://cdn.download.sweetpacks.com/simsdm/bundle/BundleSweetIMSetup.exe
hXXp://cdn.download.sweetpacks.com/simsdm/bundle/BundleSweetIMSetup.exe
hXXp://files.download1click.ws/FmoodsV21.exe
hXXp://files.download1click.ws/FmoodsV21.exe
hXXp://files.download1click.ws/IminentSetup5.exe
hXXp://files.download1click.ws/IminentSetup5.exe
hXXp://files.download1click.ws/.exe
hXXp://files.download1click.ws/.exe
hXXp://files.download1click.ws/weatherbugsetup.msi
hXXp://files.download1click.ws/weatherbugsetup.msi
hXXp://files.download1click.ws/IWantThisSetupRS.exe
hXXp://files.download1click.ws/IWantThisSetupRS.exe
hXXp://files.download1click.ws/ciuvoSetup.exe
hXXp://files.download1click.ws/ciuvoSetup.exe
hXXp://files.download1click.ws/incredibar_install3.exe
hXXp://files.download1click.ws/incredibar_install3.exe
hXXp://download.sterkly.com/DropDownDeals-S-Setup_Suite1.exe
hXXp://download.sterkly.com/DropDownDeals-S-Setup_Suite1.exe
hXXp://download.sterkly.com/FreeTwitTube-S-Setup_Suite1.exe
hXXp://download.sterkly.com/FreeTwitTube-S-Setup_Suite1.exe
hXXp://download.sterkly.com/yontoo-b2.exe
hXXp://download.sterkly.com/yontoo-b2.exe
hXXp://download.sterkly.com/ezLooker-S-Setup_Suite1.exe
hXXp://download.sterkly.com/ezLooker-S-Setup_Suite1.exe
hXXp://download.sterkly.com/BestVideoDownloader-S-Setup_Suite2.exe
hXXp://download.sterkly.com/BestVideoDownloader-S-Setup_Suite2.exe
hXXp://files.download1click.ws/GophotoExtSetup.exe
hXXp://files.download1click.ws/GophotoExtSetup.exe
hXXp://files.download1click.ws/OneClickExt1_filter03.exe
hXXp://files.download1click.ws/OneClickExt1_filter03.exe
hXXp://files.download1click.ws/OneClickExt1_filter13.exe
hXXp://files.download1click.ws/OneClickExt1_filter13.exe
Inetc3 (Mozilla; FW 4; WinNT 5.1; msi 3.1.4001.5512; dbw ie; yo ;)
Inetc3 (Mozilla; FW 4; WinNT 5.1; msi 3.1.4001.5512; dbw ie; yo ;)
Software\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Software\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
2228562
2228562
34211074
34211074
2097440
2097440
1769712
1769712
1769792
1769792
1835286
1835286
2425154
2425154
1704236
1704236
1900838
1900838
3131649
3131649
1337x,hXXp://torrage.com/torrent/DA754ECE00BB799CD605671E520D4BBA55DB2BDF.torrent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
1337x,hXXp://torrage.com/torrent/DA754ECE00BB799CD605671E520D4BBA55DB2BDF.torrent,AUTODESK.2013.PRODUCTS.UNIVERSAL.exe,ca
DA754ECE00BB799CD605671E520D4BBA55DB2BDF.torrent
DA754ECE00BB799CD605671E520D4BBA55DB2BDF.torrent
hXXp://torrage.com/torrent/DA754ECE00BB799CD605671E520D4BBA55DB2BDF.torrent
hXXp://torrage.com/torrent/DA754ECE00BB799CD605671E520D4BBA55DB2BDF.torrent
1900638
1900638
1900644
1900644
2425046
2425046
ocmainpack.exe
ocmainpack.exe
218432910
218432910
268764561
268764561
218432911
218432911
1835300
1835300
2031712
2031712
319096204
319096204
1966362
1966362
1835242
1835242
2162964
2162964
1704182
1704182
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
352978322
352978322
252315012
252315012
-1693842215
-1693842215
403309942
403309942
285869443
285869443
520750465
520750465
520750505
520750505
906626302
906626302
537527660
537527660
503973239
503973239
755631484
755631484
AUTODESK.2013.PRODUCTS.UNIVERSAL.exe
AUTODESK.2013.PRODUCTS.UNIVERSAL.exe
30510568
30510568
VVV.oneclickdownloader.com
VVV.oneclickdownloader.com
sbiectrl.exe
sbiectrl.exe
vmtoolsd.exe
vmtoolsd.exe
prl_cc.exe
prl_cc.exe
coherence.exe
coherence.exe
VirtualBox.exe
VirtualBox.exe
VBoxSVC.exe
VBoxSVC.exe
DrWeb
DrWeb
%Program Files%\1ClickDownload\AUTODESK.2013.PRODUCTS.UNIVERSAL.magnet
%Program Files%\1ClickDownload\AUTODESK.2013.PRODUCTS.UNIVERSAL.magnet
)-.Yln
)-.Yln
Nullsoft Install System v2.46
Nullsoft Install System v2.46
%original file name%.exe_388_rwx_10004000_00001000:
callback%d
callback%d