Adware.Win32.Downware.FD, Trojan.NSIS.StartPage.FD, AdwareDownware.YR (Lavasoft MAS)Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 0c8c597eef67709d9532291efe74ce10
SHA1: d547fb0b824aed8814f310cdbb8c0de8474241a1
SHA256: 6938dc442a2bc2ade6527afb0d194f7aba7d68868db4234b27fcc03e3b333749
SSDeep: 3072:YQIURTXJ445 JNw JxTP7NFvHFI8GXphv9C2CBJI/vI3EjfCSfF1wCGtE6f8bOBB:Ysi1jvZYXkdJIohSfLwj8b8nZCYGB95y
Size: 263224 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-12-06 00:50:46
Analyzed on: WindowsXP SP3 32-bit
Summary: Adware. Delivers advertising content in a manner or context that may be unexpected and unwanted by users. Many adware applications also perform tracking functions. Users may want to remove adware if they object to such tracking, do not wish to see the advertising caused by the program or are frustrated by its effects on system performance.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Adware creates the following process(es):No processes have been created.The Adware injects its code into the following process(es):
%original file name%.exe:772
Mutexes
The following mutexes were created/opened:
ZonesLockedCacheCounterMutexZonesCounterMutexZonesCacheCounterMutexRasPbFileWininetProxyRegistryMutexWininetConnectionMutexWininetStartupMutexc:!documents and settings!adm!local settings!history!history.ie5!c:!documents and settings!adm!cookies!c:!documents and settings!adm!local settings!temporary internet files!content.ie5!_!MSFTHISTORY!_ShimCacheMutex
File activity
The process %original file name%.exe:772 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Program Files%\1ClickDownload\ocmainpack.exe (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept3.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\skip.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\inetc3.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept1.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\save.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\decline.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept2.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\MainPackFA2703[1].htm (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\1clogo.bmp (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\anon.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse2.tmp (13665 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\nsDialogs.dll (9 bytes)
The Adware deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\gC0 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nso1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp (0 bytes)
Registry activity
The process %original file name%.exe:772 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\1ClickDownload]
"LastInstall0" = "30508063"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\1ClickDownload]
"UID" = "282948265"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "99 E0 DA A7 3E 93 4D 90 E9 F0 A3 5D 68 EE 65 DD"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
MD5 | File path |
---|---|
c17103ae9072a06da581dec998343fc1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsu3.tmp\System.dll |
9d8ce05f532dc7b5742831ec8a63c2d8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsu3.tmp\inetc3.dll |
c10e04dd4ad4277d5adc951bb331c777 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsu3.tmp\nsDialogs.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Adware file.
- Delete or disinfect the following files created/modified by the Adware:
%Program Files%\1ClickDownload\ocmainpack.exe (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept3.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\skip.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\inetc3.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept1.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\save.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\decline.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept2.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\MainPackFA2703[1].htm (598 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\1clogo.bmp (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\anon.bmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse2.tmp (13665 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\accept.bmp (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu3.tmp\nsDialogs.dll (9 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 23130 | 23552 | 4.44841 | 0bc2ffd32265a08d72b795b18265828d |
.rdata | 28672 | 4496 | 4608 | 3.59163 | f179218a059068529bdb4637ef5fa28e |
.data | 36864 | 110488 | 1024 | 3.26405 | 975304d6dd6c4a4f076b15511e2bbbc0 |
.ndata | 147456 | 372736 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rsrc | 520192 | 16592 | 16896 | 4.13874 | 8091b1378d82973015f802c93eb88bab |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 130
69a0a458647b3436892cf9f2f126c252
f6dfcb76ad7437d92c5afb7f0df46e1e
da0bd3c1e61660738d11b8637009704c
274a292adfe75bf2ebb7ec280e41498b
5237ce96c640fe6ac6cc74c0dcbfcaa3
2f7774bf5fd92c51f79f4ba883a3688d
19e571b63f058f8639368efa0b7e7a5d
92f168a6a50962338197ed28079023e0
eb7796e86be9bedaa30b7cfffeefe81f
02970495e406b99d8bf8e992a8ee80e8
58370f3c58561f8bfb46cf3e2f91f4b3
7bf0d359dbc0f2394d811bf4ca178d0c
6595f1898fe06bd80ec59d9ccd70bda2
9f979219e6f2be6b0d69c699192e9c98
fcb0905f624625fc4839a6a4edcb6fd4
56f587e1afeb682b0688dfcce19ebed9
c63e670ed1d501559890afdc5ccb3d56
bc4b8c6d6165113c61fb4744140a49c8
9cb467ff929aa9ea250e2501ade5f077
60ba6445ca5e44ce37f9175d5b71252a
558629b6feeb66bfdcef6c99e3c570a3
70734d89308e9da071e1e5bf18547b14
ba27f4cf2fd8becf08d48c952b1e6515
854785be31dfdacde5e34c6ed71c99a6
d9c131de8a7a673f0b3fdd82e00416d8
Network Activity
URLs
URL | IP |
---|---|
hxxp://data.downloadstarter.net/country.asp?st=-1&uid=282948265&tuid=3131549&sref=1CD_16_36_trze7&vmdt=|vm|&bld=16CJ | 88.80.188.52 |
hxxp://files.download1click.ws/MainPackFA2703.exe | 64.70.19.202 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /MainPackFA2703.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: files.download1click.ws
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200
Server: nginx/1.6.3
Date: Tue, 22 Mar 2016 09:47:26 GMT
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 598
Connection: keep-alive
<html>.<head>..<title>WEBSITE.WS - Your Internet Address For Life™</title>.</head>.<frameset rows="100%,*" border="0" frameborder="0">..<frame src="hXXp://website.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&domain=download1click.ws" scrolling="auto">..<noframes>...<p> Your browser does not support frames. Continue to <a href="hXXp://website.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&domain=download1click.ws">hXXp://website.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&domain=download1click.ws</a>.</p>..</noframes>.</frameset>.</html>HTTP/1.1 200..Server: nginx/1.6.3..Date: Tue, 22 Mar 2016 09:47:26 GMT..Content-Type: text/html; charset=ISO-8859-1..Content-Length: 598..Connection: keep-alive..<html>.<head>..<title>WEBSITE.WS - Your Internet Address For Life™</title>.</head>.<frameset rows="100%,*" border="0" frameborder="0">..<frame src="hXXp://website.ws/kvmlm2/index.dhtml?sponsor=wildcardform8&template=13&chk=1&d..
Map
The Adware connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_772:
.text
.text
`.rdata
`.rdata
@.data
@.data
.ndata
.ndata
.rsrc
.rsrc
uDSSh
uDSSh
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
GetWindowsDirectoryA
KERNEL32.dll
KERNEL32.dll
ExitWindowsEx
ExitWindowsEx
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
SHFileOperationA
SHFileOperationA
ShellExecuteA
ShellExecuteA
SHELL32.dll
SHELL32.dll
RegEnumKeyA
RegEnumKeyA
RegCreateKeyExA
RegCreateKeyExA
RegCloseKey
RegCloseKey
RegDeleteKeyA
RegDeleteKeyA
RegOpenKeyExA
RegOpenKeyExA
ADVAPI32.dll
ADVAPI32.dll
COMCTL32.dll
COMCTL32.dll
ole32.dll
ole32.dll
VERSION.dll
VERSION.dll
verifying installer: %d%%
verifying installer: %d%%
unpacking data: %d%%
unpacking data: %d%%
... %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
~nsu.tmp
%u.%u%s%s
%u.%u%s%s
RegDeleteKeyExA
RegDeleteKeyExA
%s=%s
%s=%s
*?|/":
*?|/":
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp\nsDialogs.dll
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp\nsDialogs.dll
ectly,15_Eboeken_Karin_Slaughter.exe,nl
ectly,15_Eboeken_Karin_Slaughter.exe,nl
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp\nsDialogs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsu3.tmp
zbX
zbX
=I}.Du7
=I}.Du7
i.PpB
i.PpB
"M%dN
"M%dN
Vh.vN
Vh.vN
Keym
Keym
WINDOWS
WINDOWS
skip.bmp", i 0, i 0, i 0, i 0x2000|0x0010) i.s
skip.bmp", i 0, i 0, i 0, i 0x2000|0x0010) i.s
,15_Eboeken_Karin_Slaughter.exe,nl
,15_Eboeken_Karin_Slaughter.exe,nl
1048780
1048780
iles\1ClickDownload\1ClickDownloader.exe
iles\1ClickDownload\1ClickDownloader.exe
ZWJZLMJKI4FSJNC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
ZWJZLMJKI4FSJNC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
282948265
282948265
19759910
19759910
ef67709d9532291efe74ce10.exe
ef67709d9532291efe74ce10.exe
NC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
NC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
2829482
2829482
06406250
06406250
1704262
1704262
1342506070
1342506070
ownload.sweetpacks.com/simsdm/bundle/
ownload.sweetpacks.com/simsdm/bundle/
ram Files\Internet Explorer\iexplore.exe
ram Files\Internet Explorer\iexplore.exe
n_Karin_Slaughter.exe
n_Karin_Slaughter.exe
001.5512
001.5512
c:\%original file name%.exe
c:\%original file name%.exe
%Documents and Settings%\%current user%\Desktop
%Documents and Settings%\%current user%\Desktop
%Program Files%\1ClickDownload
%Program Files%\1ClickDownload
u3.tmp
u3.tmp
%original file name%.exe
%original file name%.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nso1.tmp
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nso1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
hXXp://files.download1click.ws/MainPackFA2703.exe
hXXp://files.download1click.ws/MainPackFA2703.exe
hXXp://files.download1click.ws/gzip2.exe
hXXp://files.download1click.ws/gzip2.exe
hXXp://data.downloadstarter.net/
hXXp://data.downloadstarter.net/
hXXp://files.download1click.ws/ARURUSetup.exe
hXXp://files.download1click.ws/ARURUSetup.exe
hXXp://files.download1click.ws/ARUARSetup.exe
hXXp://files.download1click.ws/ARUARSetup.exe
hXXp://files.download1click.ws/BTB0612.exe
hXXp://files.download1click.ws/BTB0612.exe
hXXp://cdn.download.sweetpacks.com/simsdm/bundle/BundleSweetIMSetup.exe
hXXp://cdn.download.sweetpacks.com/simsdm/bundle/BundleSweetIMSetup.exe
hXXp://files.download1click.ws/FmoodsV21.exe
hXXp://files.download1click.ws/FmoodsV21.exe
hXXp://files.download1click.ws/IminentSetup5.exe
hXXp://files.download1click.ws/IminentSetup5.exe
hXXp://files.download1click.ws/.exe
hXXp://files.download1click.ws/.exe
hXXp://files.download1click.ws/weatherbugsetup.msi
hXXp://files.download1click.ws/weatherbugsetup.msi
hXXp://files.download1click.ws/IWantThisSetupRS.exe
hXXp://files.download1click.ws/IWantThisSetupRS.exe
hXXp://files.download1click.ws/ciuvoSetup.exe
hXXp://files.download1click.ws/ciuvoSetup.exe
hXXp://files.download1click.ws/incredibar_install3.exe
hXXp://files.download1click.ws/incredibar_install3.exe
hXXp://download.sterkly.com/yontoo-c4.exe
hXXp://download.sterkly.com/yontoo-c4.exe
hXXp://download.sterkly.com/yontoo-c2.exe
hXXp://download.sterkly.com/yontoo-c2.exe
hXXp://download.sterkly.com/yontoo-b2.exe
hXXp://download.sterkly.com/yontoo-b2.exe
hXXp://download.sterkly.com/yontoo-c3.exe
hXXp://download.sterkly.com/yontoo-c3.exe
hXXp://download.sterkly.com/yontoo-c5.exe
hXXp://download.sterkly.com/yontoo-c5.exe
hXXp://files.download1click.ws/GophotoExtSetup.exe
hXXp://files.download1click.ws/GophotoExtSetup.exe
hXXp://files.download1click.ws/OneClickExt1_filter03.exe
hXXp://files.download1click.ws/OneClickExt1_filter03.exe
hXXp://files.download1click.ws/OneClickExt1_filter13.exe
hXXp://files.download1click.ws/OneClickExt1_filter13.exe
ocmainpack.exe
ocmainpack.exe
Inetc3 (Mozilla; FW 4; WinNT 5.1; msi 3.1.4001.5512; dbw ie; yo ;)
Inetc3 (Mozilla; FW 4; WinNT 5.1; msi 3.1.4001.5512; dbw ie; yo ;)
Software\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
Software\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload
873071679
873071679
1310970
1310970
1048906
1048906
1114390
1114390
3131549
3131549
trze7,magnet:?xt=urn:btih:RZWJZLMJKI4FSJNC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
trze7,magnet:?xt=urn:btih:RZWJZLMJKI4FSJNC2PHRAQYH6W4R4ZVX¬e=1clickdownloader_is_NOT_downloading_any_file_directly,15_Eboeken_Karin_Slaughter.exe,nl
1179894
1179894
1179886
1179886
-1845164791
-1845164791
-2012937513
-2012937513
-435878885
-435878885
1704228
1704228
1573146
1573146
537199696
537199696
1507538
1507538
1507518
1507518
1835232
1835232
1507522
1507522
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
2030698948
2030698948
1477051454
1477051454
1275724832
1275724832
2114585872
2114585872
453641394
453641394
1762264094
1762264094
-385219891
-385219891
252314312
252314312
-1626733924
-1626733924
1225393333
1225393333
-2012609457
-2012609457
15_Eboeken_Karin_Slaughter.exe
15_Eboeken_Karin_Slaughter.exe
30508063
30508063
VVV.oneclickdownloader.com
VVV.oneclickdownloader.com
sbiectrl.exe
sbiectrl.exe
vmtoolsd.exe
vmtoolsd.exe
prl_cc.exe
prl_cc.exe
coherence.exe
coherence.exe
VirtualBox.exe
VirtualBox.exe
VBoxSVC.exe
VBoxSVC.exe
DrWeb
DrWeb
%Program Files%\1ClickDownload\15_Eboeken_Karin_Slaughter.magnet
%Program Files%\1ClickDownload\15_Eboeken_Karin_Slaughter.magnet
)-.Yln
)-.Yln
Nullsoft Install System v2.46
Nullsoft Install System v2.46
%original file name%.exe_772_rwx_10004000_00001000:
callback%d
callback%d