Adware.Win32.Downware.FD, Trojan.NSIS.StartPage.FD, AdwareDownware.YR (Lavasoft MAS)Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 19e571b63f058f8639368efa0b7e7a5d
SHA1: 3604e22d9137d1fe7bd38d3754f3f0987cabb0d9
SHA256: 78adbe42f3e7971567a0f80096eb5f5bc998763a5754c5c96579bb63aa50e020
SSDeep: 3072:tQIURTXJ445 JNw JxTP7NFvHFI8GXphv9C2CBJI/vI3EjfCSfF1wCGtE6f8bOB7:tsi1jvZYXkdJIohSfLwj8b8nZCYGB95s
Size: 263160 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-12-06 00:50:46
Analyzed on: WindowsXP SP3 32-bit
Summary: Adware. Delivers advertising content in a manner or context that may be unexpected and unwanted by users. Many adware applications also perform tracking functions. Users may want to remove adware if they object to such tracking, do not wish to see the advertising caused by the program or are frustrated by its effects on system performance.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Adware creates the following process(es):No processes have been created.The Adware injects its code into the following process(es):
%original file name%.exe:228
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:228 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\S2IV0BEO\desktop.ini (67 bytes)
%Program Files%\1ClickDownload\ocmainpack.exe (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\decline.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\anon.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\accept.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\B2GLU1UR\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi2.tmp (13665 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\save.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\skip.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\nsDialogs.dll (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\inetc3.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\accept1.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\1clogo.bmp (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\accept2.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\H8C3IHQC\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\accept3.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\0S2LFIL8\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\H8C3IHQC\MainPackFA2703[1].htm (598 bytes)
The Adware deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\gC0 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss1.tmp (0 bytes)
Registry activity
The process %original file name%.exe:228 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\1ClickDownload]
"LastInstall0" = "30509785"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\1ClickDownload]
"UID" = "282948265"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1A A2 C5 DB C7 89 5D 47 8E 31 F4 6D 27 80 E3 EC"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
MD5 | File path |
---|---|
c17103ae9072a06da581dec998343fc1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsy3.tmp\System.dll |
9d8ce05f532dc7b5742831ec8a63c2d8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsy3.tmp\inetc3.dll |
c10e04dd4ad4277d5adc951bb331c777 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsy3.tmp\nsDialogs.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Adware file.
- Delete or disinfect the following files created/modified by the Adware:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\S2IV0BEO\desktop.ini (67 bytes)
%Program Files%\1ClickDownload\ocmainpack.exe (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\decline.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\anon.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\accept.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\B2GLU1UR\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi2.tmp (13665 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\save.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\skip.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\nsDialogs.dll (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\inetc3.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\accept1.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\1clogo.bmp (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\accept2.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\H8C3IHQC\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy3.tmp\accept3.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\0S2LFIL8\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\H8C3IHQC\MainPackFA2703[1].htm (598 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 23130 | 23552 | 4.44841 | 0bc2ffd32265a08d72b795b18265828d |
.rdata | 28672 | 4496 | 4608 | 3.59163 | f179218a059068529bdb4637ef5fa28e |
.data | 36864 | 110488 | 1024 | 3.26405 | 975304d6dd6c4a4f076b15511e2bbbc0 |
.ndata | 147456 | 372736 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rsrc | 520192 | 16592 | 16896 | 4.13874 | 8091b1378d82973015f802c93eb88bab |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 130
69a0a458647b3436892cf9f2f126c252
f6dfcb76ad7437d92c5afb7f0df46e1e
da0bd3c1e61660738d11b8637009704c
274a292adfe75bf2ebb7ec280e41498b
5237ce96c640fe6ac6cc74c0dcbfcaa3
2f7774bf5fd92c51f79f4ba883a3688d
92f168a6a50962338197ed28079023e0
0c8c597eef67709d9532291efe74ce10
eb7796e86be9bedaa30b7cfffeefe81f
02970495e406b99d8bf8e992a8ee80e8
58370f3c58561f8bfb46cf3e2f91f4b3
7bf0d359dbc0f2394d811bf4ca178d0c
6595f1898fe06bd80ec59d9ccd70bda2
9f979219e6f2be6b0d69c699192e9c98
fcb0905f624625fc4839a6a4edcb6fd4
56f587e1afeb682b0688dfcce19ebed9
c63e670ed1d501559890afdc5ccb3d56
bc4b8c6d6165113c61fb4744140a49c8
9cb467ff929aa9ea250e2501ade5f077
60ba6445ca5e44ce37f9175d5b71252a
558629b6feeb66bfdcef6c99e3c570a3
70734d89308e9da071e1e5bf18547b14
ba27f4cf2fd8becf08d48c952b1e6515
854785be31dfdacde5e34c6ed71c99a6
d9c131de8a7a673f0b3fdd82e00416d8
Network Activity
URLs
URL | IP |
---|---|
hxxp://data.downloadstarter.net/country.asp?st=-1&uid=282948265&tuid=3131649&sref=1CD_16_36_ap180915&vmdt=|vm|&bld=16CJ | 88.80.188.52 |
hxxp://files.download1click.ws/MainPackFA2703.exe | 64.70.19.202 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /MainPackFA2703.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: files.download1click.ws
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.6.3
Date: Wed, 30 Mar 2016 23:11:52 GMT
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 598
Connection: keep-alive
<html>.<head>..<title>WEBSITE.WS - Your Internet Address For Life™</title>.</head>.<frameset rows="100%,*" border="0" frameborder="0">..<frame src="hXXp://website.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&domain=download1click.ws" scrolling="auto">..<noframes>...<p> Your browser does not support frames. Continue to <a href="hXXp://website.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&domain=download1click.ws">hXXp://website.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&domain=download1click.ws</a>.</p>..</noframes>.</frameset>.</html>HTTP/1.1 200 OK..Server: nginx/1.6.3..Date: Wed, 30 Mar 2016 23:11:52 GMT..Content-Type: text/html; charset=ISO-8859-1..Content-Length: 598..Connection: keep-alive..<html>.<head>..<title>WEBSITE.WS - Your Internet Address For Life™</title>.</head>.<frameset rows="100%,*" border="..
Map
The Adware connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_228:
.text
.text
`.rdata
`.rdata
@.data
@.data
.ndata
.ndata
.rsrc
.rsrc
uDSSh
uDSSh
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
GetWindowsDirectoryA
KERNEL32.dll
KERNEL32.dll
ExitWindowsEx
ExitWindowsEx
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
SHFileOperationA
SHFileOperationA
ShellExecuteA
ShellExecuteA
SHELL32.dll
SHELL32.dll
RegEnumKeyA
RegEnumKeyA
RegCreateKeyExA
RegCreateKeyExA
RegCloseKey
RegCloseKey
RegDeleteKeyA
RegDeleteKeyA
RegOpenKeyExA
RegOpenKeyExA
ADVAPI32.dll
ADVAPI32.dll
COMCTL32.dll
COMCTL32.dll
ole32.dll
ole32.dll
VERSION.dll
VERSION.dll
verifying installer: %d%%
verifying installer: %d%%
unpacking data: %d%%
unpacking data: %d%%
... %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
~nsu.tmp
%u.%u%s%s
%u.%u%s%s
RegDeleteKeyExA
RegDeleteKeyExA
%s=%s
%s=%s
*?|/":
*?|/":
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy3.tmp\nsDialogs.dll
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy3.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy3.tmp
zbX
zbX
=I}.Du7
=I}.Du7
i.PpB
i.PpB
"M%dN
"M%dN
Vh.vN
Vh.vN
Keym
Keym
WINDOWS
WINDOWS
skip.bmp", i 0, i 0, i 0, i 0x2000|0x0010) i.s
skip.bmp", i 0, i 0, i 0, i 0x2000|0x0010) i.s
iles\1ClickDownload\1ClickDownloader.exe
iles\1ClickDownload\1ClickDownloader.exe
p://dl7.torrentreactor.net/download.php?id=7907579,VBR]_effone.exe,au
p://dl7.torrentreactor.net/download.php?id=7907579,VBR]_effone.exe,au
282948265
282948265
reactor.net/download.php?id=7907579
reactor.net/download.php?id=7907579
=7907579,VBR]_effone.exe,au
=7907579,VBR]_effone.exe,au
79344566
79344566
3f058f8639368efa0b7e7a5d.exe
3f058f8639368efa0b7e7a5d.exe
ownload.php?id=7907579,VBR]_effone.exe,au
ownload.php?id=7907579,VBR]_effone.exe,au
2829482
2829482
06406250
06406250
1376518
1376518
-2113600547
-2113600547
ownload.sweetpacks.com/simsdm/bundle/
ownload.sweetpacks.com/simsdm/bundle/
ram Files\Internet Explorer\iexplore.exe
ram Files\Internet Explorer\iexplore.exe
.php?id=7907579
.php?id=7907579
.net/download.php?id=7907579
.net/download.php?id=7907579
001.5512
001.5512
c:\%original file name%.exe
c:\%original file name%.exe
%Documents and Settings%\%current user%\Desktop
%Documents and Settings%\%current user%\Desktop
%Program Files%\1ClickDownload
%Program Files%\1ClickDownload
y3.tmp
y3.tmp
%original file name%.exe
%original file name%.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss1.tmp
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
hXXp://files.download1click.ws/MainPackFA2703.exe
hXXp://files.download1click.ws/MainPackFA2703.exe
hXXp://files.download1click.ws/gzip2.exe
hXXp://files.download1click.ws/gzip2.exe
hXXp://data.downloadstarter.net/
hXXp://data.downloadstarter.net/
hXXp://files.download1click.ws/ARURUSetup.exe
hXXp://files.download1click.ws/ARURUSetup.exe
hXXp://files.download1click.ws/ARUARSetup.exe
hXXp://files.download1click.ws/ARUARSetup.exe
hXXp://files.download1click.ws/BTB0612.exe
hXXp://files.download1click.ws/BTB0612.exe
hXXp://cdn.download.sweetpacks.com/simsdm/bundle/BundleSweetIMSetup.exe
hXXp://cdn.download.sweetpacks.com/simsdm/bundle/BundleSweetIMSetup.exe
hXXp://files.download1click.ws/FmoodsV21.exe
hXXp://files.download1click.ws/FmoodsV21.exe
hXXp://files.download1click.ws/IminentSetup5.exe
hXXp://files.download1click.ws/IminentSetup5.exe
hXXp://files.download1click.ws/.exe
hXXp://files.download1click.ws/.exe
hXXp://files.download1click.ws/weatherbugsetup.msi
hXXp://files.download1click.ws/weatherbugsetup.msi
hXXp://files.download1click.ws/IWantThisSetupRS.exe
hXXp://files.download1click.ws/IWantThisSetupRS.exe
hXXp://files.download1click.ws/ciuvoSetup.exe
hXXp://files.download1click.ws/ciuvoSetup.exe
hXXp://files.download1click.ws/incredibar_install3.exe
hXXp://files.download1click.ws/incredibar_install3.exe
hXXp://download.sterkly.com/yontoo-c4.exe
hXXp://download.sterkly.com/yontoo-c4.exe
hXXp://download.sterkly.com/yontoo-c2.exe
hXXp://download.sterkly.com/yontoo-c2.exe
hXXp://download.sterkly.com/yontoo-b2.exe
hXXp://download.sterkly.com/yontoo-b2.exe
hXXp://download.sterkly.com/yontoo-c3.exe
hXXp://download.sterkly.com/yontoo-c3.exe
hXXp://download.sterkly.com/yontoo-c5.exe
hXXp://download.sterkly.com/yontoo-c5.exe
hXXp://files.download1click.ws/GophotoExtSetup.exe
hXXp://files.download1click.ws/GophotoExtSetup.exe
hXXp://files.download1click.ws/OneClickExt1_filter03.exe
hXXp://files.download1click.ws/OneClickExt1_filter03.exe
hXXp://files.download1click.ws/OneClickExt1_filter13.exe
hXXp://files.download1click.ws/OneClickExt1_filter13.exe
ocmainpack.exe
ocmainpack.exe
Inetc3 (Mozilla; FW 4; WinNT 5.1; msi 3.1.4001.5512; dbw ie; yo ;)
Inetc3 (Mozilla; FW 4; WinNT 5.1; msi 3.1.4001.5512; dbw ie; yo ;)
Software\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Software\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
839516909
839516909
3131649
3131649
ap180915,hXXp://dl7.torrentreactor.net/download.php?id=7907579,VBR]_effone.exe,au
ap180915,hXXp://dl7.torrentreactor.net/download.php?id=7907579,VBR]_effone.exe,au
ownload.php?id=7907579
ownload.php?id=7907579
hXXp://dl7.torrentreactor.net/download.php?id=7907579
hXXp://dl7.torrentreactor.net/download.php?id=7907579
-955973120
-955973120
1292173680
1292173680
1912930796
1912930796
520421749
520421749
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
1393165003
1393165003
1930036140
1930036140
-2130050342
-2130050342
-49675331
-49675331
1762263513
1762263513
1745486535
1745486535
-1458961880
-1458961880
1258947043
1258947043
-2096495843
-2096495843
1208615462
1208615462
-905313816
-905313816
VBR]_effone.exe
VBR]_effone.exe
30509785
30509785
VVV.oneclickdownloader.com
VVV.oneclickdownloader.com
sbiectrl.exe
sbiectrl.exe
vmtoolsd.exe
vmtoolsd.exe
prl_cc.exe
prl_cc.exe
coherence.exe
coherence.exe
VirtualBox.exe
VirtualBox.exe
VBoxSVC.exe
VBoxSVC.exe
DrWeb
DrWeb
%Program Files%\1ClickDownload\VBR]_effone.magnet
%Program Files%\1ClickDownload\VBR]_effone.magnet
)-.Yln
)-.Yln
Nullsoft Install System v2.46
Nullsoft Install System v2.46
%original file name%.exe_228_rwx_10004000_00001000:
callback%d
callback%d