Gen:Variant.Jaik.8318 (B) (Emsisoft), Trojan-Downloader.Win32.Moure.FD (Lavasoft MAS)Behaviour: Trojan-Downloader, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 87ae92de9f19ec34b3b2ef86ec7b1ca1
SHA1: 91fdf66d291d5397669d32b3ae957a9028e22759
SHA256: 9b911f4ef4aa7ac8daad4ff2fba408b864e86dd357513e24ca67a2851b7584c1
SSDeep: 12288:HqtXGW/RqUM96PjuBRoTot 875pe38G49tRabK1ZT0Qt:7W/FMwPeaTai38GgrabYZTDt
Size: 402432 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2015-11-24 09:15:30
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan-Downloader. Trojan program, which downloads files from the Internet without user's notice and executes them.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan-Downloader creates the following process(es):
%original file name%.exe:1896
cscript.exe:344
cscript.exe:1864
7za.exe:216
7za.exe:604
7za.exe:584
7za.exe:592
7za.exe:2040
7za.exe:128
wmic.exe:1056
schtasks.exe:1268
schtasks.exe:544
schtasks.exe:1232
schtasks.exe:1996
schtasks.exe:1620
schtasks.exe:1980
schtasks.exe:276
schtasks.exe:1884
schtasks.exe:1280
The Trojan-Downloader injects its code into the following process(es):No processes have been created.
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:1896 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\7za.exe (26212 bytes)
%System%\GroupPolicy\Machine\Registry.pol (273762 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\{E1237C01-A4EE-41B9-8B2A-73BFD7C79229}\7z.r (278 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\7za[1].exe (244426 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\L4t5f6M.vbs (722 bytes)
%System%\GroupPolicy\gpt.ini (543 bytes)
The Trojan-Downloader deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\{E1237C01-A4EE-41B9-8B2A-73BFD7C79229} (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\{E1237C01-A4EE-41B9-8B2A-73BFD7C79229}\7z.r (0 bytes)
The process cscript.exe:344 makes changes in the file system.
The Trojan-Downloader deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\L4t5f6M.vbs (0 bytes)
C:\%original file name%.exe (0 bytes)
The process 7za.exe:216 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%Documents and Settings%\All Users\Application Data\npp\gup.xml (2 bytes)
The process 7za.exe:584 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Notepader\gup.xml (2 bytes)
The process 7za.exe:592 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\VolIE\IE\Shopify_32.dll (2151 bytes)
The process 7za.exe:2040 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Flasher\job.exe (1654 bytes)
The process 7za.exe:128 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Notepader\GUP.exe (1137 bytes)
The process wmic.exe:1056 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
The Trojan-Downloader deletes the following file(s):
The process schtasks.exe:1268 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%WinDir%\Tasks\SystemTask.job (418 bytes)
The process schtasks.exe:1980 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%WinDir%\Tasks\ScheduledScan.job (386 bytes)
The process schtasks.exe:276 makes changes in the file system.
The Trojan-Downloader creates and/or writes to the following file(s):
%WinDir%\Tasks\Scheduled Update.job (418 bytes)
Registry activity
The process %original file name%.exe:1896 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
"UsePolicySearchProvidersOnly" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
"ShowSearchSuggestionsInAddressGlobal" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1F 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageIsNewTabPage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.alarabeyes.com/"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID]
"{2ED35963-FCC9-4698-B619-787FE1C75079}" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\Recommended]
"RestoreOnStartup" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
"NoChangeDefaultSearchProvider" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderKeyword" = "arabyonline"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
"1" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1A10" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\Recommended]
"ShowHomeButton" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderName" = "arabyonline"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageLocation" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageIsNewTabPage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"DisplayName" = "Searcher"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderKeyword" = "arabyonline"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
"UsePolicySearchProvidersOnly" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"DisplayName" = "Searcher"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
"1" = "http://www.alarabeyes.com/"
[HKCU\Software\Vonteera Safe ads]
"Path" = "%Documents and Settings%\%current user%\Application Data\NoVooITAddon"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderEnabled" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderName" = "arabyonline"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderEnabled" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageLocation" = "http://www.alarabeyes.com/"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "ADEF3E17-71F9-4526-B033-B7CB738F050C"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderSearchURL" = "http://www.arabyonline.com/search.php?src=1000&q={searchTerms}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\ExtensionInstallForcelist]
"1" = "floipahigmmkfhkoapmnijnlnboniglg;https://clients2.google.com/service/update2/crx"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
"ShowSearchSuggestionsInAddressGlobal" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\active_permissions]
"{2ED35963-FCC9-4698-B619-787FE1C75079}" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google\Chrome\Recommended]
"ShowHomeButton" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageLocation" = "http://www.alarabeyes.com/"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"DisplayName" = "Searcher"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google\Chrome\Recommended]
"RestoreOnStartup" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
"NoChangeDefaultSearchProvider" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderSearchURL" = "http://www.arabyonline.com/search.php?src=1000&q={searchTerms}"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
"1" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"{AEBA21FA-782A-4A90-978D-B72164C80120}" = "1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "ADEF3E17-71F9-4526-B033-B7CB738F050C"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "33 4F 1C AE 7A D9 FF 1C B5 C6 3F 55 FB A3 34 ED"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"ShowSearchSuggestions" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"ShowSearchSuggestions" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google\Chrome\Recommended]
"ShowHomeButton" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
"1" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageLocation" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderEnabled" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome\Recommended]
"RestoreOnStartup" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\Recommended]
"RestoreOnStartup" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageIsNewTabPage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageIsNewTabPage" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]
"{437B9306-2FDE-4054-A3C9-6B49507C12D0}" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderName" = "arabyonline"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google\Chrome\Recommended]
"ShowHomeButton" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"ShowSearchSuggestions" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"DisplayName" = "Searcher"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google\Chrome\Recommended]
"RestoreOnStartup" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"PrivacyAdvanced" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Chromium\ExtensionInstallForcelist]
"1" = "floipahigmmkfhkoapmnijnlnboniglg;https://clients2.google.com/service/update2/crx"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "ADEF3E17-71F9-4526-B033-B7CB738F050C"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\Recommended]
"ShowHomeButton" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]
"{437B9306-2FDE-4054-A3C9-6B49507C12D0}" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"URL" = "http://www.arabyonline.com/search.php?src=1000&q={searchTerms}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderSearchURL" = "http://www.arabyonline.com/search.php?src=1000&q={searchTerms}"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\NoVooITSet]
"Default" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageIsNewTabPage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"ShowSearchSuggestions" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\ExtensionInstallForcelist]
"1" = "floipahigmmkfhkoapmnijnlnboniglg;https://clients2.google.com/service/update2/crx"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"{A8A88C49-5EB2-4990-A1A2-0876022C854F}" = "1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\Local Settings\Application Data]
"7za.exe" = "7-Zip Standalone Console"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google\Chrome\Recommended]
"RestoreOnStartup" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
"UsePolicySearchProvidersOnly" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageIsNewTabPage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%\wbem]
"wmic.exe" = "wmi command line"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
"1" = "http://www.alarabeyes.com/"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"URL" = "http://www.arabyonline.com/search.php?src=1000&q={searchTerms}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome]
"DefaultSearchProviderKeyword" = "arabyonline"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageLocation" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
"NoChangeDefaultSearchProvider" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
"UsePolicySearchProvidersOnly" = "1"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
"cscript.exe" = "Microsoft (R) Console Based Script Host"
"schtasks.exe" = "Schedule Tasks"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome\Recommended]
"ShowHomeButton" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"URL" = "http://www.arabyonline.com/search.php?src=1000&q={searchTerms}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
"URL" = "http://www.arabyonline.com/search.php?src=1000&q={searchTerms}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
"ShowSearchSuggestionsInAddressGlobal" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
"NoChangeDefaultSearchProvider" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google\Chrome\Recommended]
"HomepageLocation" = "http://www.alarabeyes.com/"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
"1" = "http://www.alarabeyes.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]
"{2ED35963-FCC9-4698-B619-787FE1C75079}" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "ADEF3E17-71F9-4526-B033-B7CB738F050C"
"ShowSearchSuggestionsInAddressGlobal" = "0"
The Trojan-Downloader modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan-Downloader modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan-Downloader modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan-Downloader deletes the following registry key(s):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome\Recommended]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}User]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}User]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\Recommended]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Microsoft\Internet Explorer]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google\Chrome]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Chromium]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google\Chrome]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\Recommended]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Microsoft]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}User]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\RestoreOnStartupURLs]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Microsoft\Internet Explorer]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine\Software]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google\Chrome]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}User]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}User]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Microsoft]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes\ADEF3E17-71F9-4526-B033-B7CB738F050C]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine\Software\Policies]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}User]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Chromium\ExtensionInstallForcelist]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google\Chrome\Recommended]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{86E7E0E6-DAD1-4073-943F-DEC3B2C0CE95}Machine\Software\Policies\Google]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft\Internet Explorer]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine\Software\Policies\Microsoft\Internet Explorer\Control Panel]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Microsoft\Internet Explorer\SearchScopes]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Microsoft]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\Main]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google\Chrome\ExtensionInstallForcelist]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine\Software\Policies\Microsoft\Internet Explorer]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{DA18203D-B63F-471E-9402-AEE1150E0319}Machine\Software\Policies\Google\Chrome\Recommended]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Google]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}User]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{2E465565-B908-4F9A-A429-32411C877E0B}Machine\Software\Policies\Microsoft\Internet Explorer\Infodelivery]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{4B7C3E03-DC08-48CD-9724-2AAFFD5B1099}Machine\Software\Policies\Google\Chrome\Recommended]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{933EE516-6941-4A7F-A015-895DB45C5435}Machine\Software\Policies\Google\Chrome]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{45DA1337-6D95-40A8-8B9F-48D80D54C850}Machine\Software\Policies\Microsoft]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{A17266D2-4FA0-4A36-ABB0-D9D9E6DD537A}Machine\Software\Policies\Google\Chrome\ExtensionInstallForcelist]
The Trojan-Downloader deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process cscript.exe:344 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C0 0B 16 F9 13 2C FF 7B 3F 8B E9 AB BD 12 D9 37"
The process cscript.exe:1864 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5B AB 50 D5 06 F1 87 E5 A2 13 2F C4 C4 02 25 80"
The process 7za.exe:216 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B7 28 9F 4C B3 5E B4 F5 A8 35 37 92 49 17 AD 04"
The process 7za.exe:604 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BB AD 01 27 30 03 74 29 0A FD 5A 1F 8C 3C 93 53"
The process 7za.exe:584 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FE F3 2E 35 99 0B 37 33 A8 A5 63 38 EB 73 BB A9"
The process 7za.exe:592 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A5 F4 62 FA BE B7 92 FC E0 3F F7 DE C4 37 04 0A"
The process 7za.exe:2040 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "05 30 B0 DF 50 C9 90 C2 EC EE AD FB 92 44 A1 7A"
The process 7za.exe:128 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "27 5B 58 69 2F B1 E4 1B 30 B6 75 39 C7 A9 E1 70"
The process wmic.exe:1056 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D5 6A 9E 0F 21 AD 59 0A 28 DF B5 EE 18 3A A3 0F"
The process schtasks.exe:1268 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "72 D2 0E 1F CD CC F8 39 5E E3 C8 ED A2 C8 C0 E7"
The process schtasks.exe:544 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B3 DF E5 E3 DE 38 5C 0F 52 FA FC 8A FB 6F FA 10"
The process schtasks.exe:1232 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F9 DF 8D 53 82 7F FB 94 DA 11 B8 42 AB C4 D7 C9"
The process schtasks.exe:1996 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3E D2 EB C9 EA C5 04 04 66 54 6B EE 59 5F D6 6B"
The process schtasks.exe:1620 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "06 C4 09 C8 6E B8 08 A3 DA 91 4C 3E 79 F9 DC 99"
The process schtasks.exe:1980 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "09 AA E0 DF 8F C5 DB 8F 91 2E 8E 3D 6F 02 22 3A"
The process schtasks.exe:276 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "54 09 DE 8E 63 C8 CF 57 EE 20 CC 68 FD 13 B5 5C"
The process schtasks.exe:1884 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "64 B2 F2 F9 8E 64 B6 9B 87 DF F1 F0 7C B4 04 15"
The process schtasks.exe:1280 makes changes in the system registry.
The Trojan-Downloader creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4D C1 9C 89 26 0A 42 B4 A1 AF 35 DD CA A1 8B 30"
Dropped PE files
MD5 | File path |
---|---|
5234298760e4fbdbd1df935edec19d42 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Flasher\job.exe |
f19cdb9073d777f4d77ab7a4049fad4f | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Notepader\GUP.exe |
24dd6033ef9fc7507e34bf5ef36cda56 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\VolIE\IE\Shopify_32.dll |
42badc1d2f03a8b1e4875740d3d49336 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Application Data\7za.exe |
42badc1d2f03a8b1e4875740d3d49336 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\7za[1].exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1896
cscript.exe:344
cscript.exe:1864
7za.exe:216
7za.exe:604
7za.exe:584
7za.exe:592
7za.exe:2040
7za.exe:128
wmic.exe:1056
schtasks.exe:1268
schtasks.exe:544
schtasks.exe:1232
schtasks.exe:1996
schtasks.exe:1620
schtasks.exe:1980
schtasks.exe:276
schtasks.exe:1884
schtasks.exe:1280 - Delete the original Trojan-Downloader file.
- Delete or disinfect the following files created/modified by the Trojan-Downloader:
%Documents and Settings%\%current user%\Local Settings\Application Data\7za.exe (26212 bytes)
%System%\GroupPolicy\Machine\Registry.pol (273762 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\{E1237C01-A4EE-41B9-8B2A-73BFD7C79229}\7z.r (278 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\7za[1].exe (244426 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\L4t5f6M.vbs (722 bytes)
%System%\GroupPolicy\gpt.ini (543 bytes)
%Documents and Settings%\All Users\Application Data\npp\gup.xml (2 bytes)
%Documents and Settings%\%current user%\Application Data\Notepader\gup.xml (2 bytes)
%Documents and Settings%\%current user%\Application Data\VolIE\IE\Shopify_32.dll (2151 bytes)
%Documents and Settings%\%current user%\Application Data\Flasher\job.exe (1654 bytes)
%Documents and Settings%\%current user%\Application Data\Notepader\GUP.exe (1137 bytes)
%WinDir%\Tasks\SystemTask.job (418 bytes)
%WinDir%\Tasks\ScheduledScan.job (386 bytes)
%WinDir%\Tasks\Scheduled Update.job (418 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
Static Analysis
VersionInfo
Company Name: Igor Pavlov
Product Name: 7-Zip
Product Version: 9.22
Legal Copyright: Copyright (C) 2015
Legal Trademarks:
Original Filename: 7zFM.exe
Internal Name: 7zFM.exe
File Version: 9.22
File Description: 7-Zip File Manager
Comments:
Language: English (United States)
Company Name: Igor PavlovProduct Name: 7-ZipProduct Version: 9.22Legal Copyright: Copyright (C) 2015Legal Trademarks: Original Filename: 7zFM.exeInternal Name: 7zFM.exeFile Version: 9.22File Description: 7-Zip File ManagerComments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.MPRESS1 | 4096 | 667648 | 117760 | 5.54422 | e11a1fa2d027548ba59fba0677ec7b41 |
.MPRESS2 | 671744 | 3460 | 3584 | 4.10625 | fc5a058897be10c6b1363b7343f41c77 |
.rsrc | 675840 | 280360 | 280576 | 5.54298 | d9eda3901a2d2ebf2b81c6454b0fac46 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://curl.haxx.se/gknw.net/7.40.0/dist-w32/curl-7.40.0-devel-mingw32.zip | 80.67.6.50 |
www.acdcads.com | 178.63.60.80 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /gknw.net/7.40.0/dist-w32/curl-7.40.0-devel-mingw32.zip HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: curl.haxx.se
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Mon, 14 Dec 2015 23:21:00 GMT
Server: Apache
Content-Length: 314
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL /gknw.net/7.40.0/dist-w32/curl-7.40.0-devel-mingw32.zip was not found on this server.</p>.<hr>.<address>Apache Server at curl.haxx.se Port 80</address>.</body></html>.HTTP/1.1 404 Not Found..Date: Mon, 14 Dec 2015 23:21:00 GMT..Server: Apache..Content-Length: 314..Keep-Alive: timeout=15, max=100..Connection: Keep-Alive..Content-Type: text/html; charset=iso-8859-1..<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL /gknw.net/7.40.0/dist-w32/curl-7.40.0-devel-mingw32.zip was not found on this server.</p>.<hr>.<address>Apache Server at curl.haxx.se Port 80</address>.</body></html>...
Map
The Trojan-Downloader connects to the servers at the folowing location(s):
Strings from Dumps
wuauclt.exe_1312:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
wuauclt.pdb
wuauclt.pdb
GetProcessHeap
GetProcessHeap
KERNEL32.dll
KERNEL32.dll
_wcmdln
_wcmdln
_amsg_exit
_amsg_exit
msvcrt.dll
msvcrt.dll
ntdll.dll
ntdll.dll
ole32.dll
ole32.dll
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegCreateKeyExW
ADVAPI32.dll
ADVAPI32.dll
USER32.dll
USER32.dll
OLEAUT32.dll
OLEAUT32.dll
SHLWAPI.dll
SHLWAPI.dll
zcÃ
zcÃ
version="6.0.0.0"
version="6.0.0.0"
name="Microsoft.Windows.windowsupdate.wuauclt"
name="Microsoft.Windows.windowsupdate.wuauclt"
true
true
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
wuaueng.dll
wuaueng.dll
Error: 0xx. wuauclt handler: failed to spawn COM server
Error: 0xx. wuauclt handler: failed to spawn COM server
Error: 0xx. wuauclt handler: failed to load wuaueng
Error: 0xx. wuauclt handler: failed to load wuaueng
/ReportNow
/ReportNow
/ShowWindowsUpdate
/ShowWindowsUpdate
/CloseWindowsUpdate
/CloseWindowsUpdate
wuauclt.exe failed to get proc address for UI export object with error %#lx
wuauclt.exe failed to get proc address for UI export object with error %#lx
Failed to load %s with error %X
Failed to load %s with error %X
wucltui.dll
wucltui.dll
wucltux.dll
wucltux.dll
call RunAUClientUI on wucltui.dll/wucltux.dll
call RunAUClientUI on wucltui.dll/wucltux.dll
Ntdll.dll
Ntdll.dll
WuSqm %ls session datapoint (id:%d) is incremented with dword %d.
WuSqm %ls session datapoint (id:%d) is incremented with dword %d.
wuauclt.exe is exiting with code 0xX
wuauclt.exe is exiting with code 0xX
wuauclt.exe launched with command line %s
wuauclt.exe launched with command line %s
kernel32.dll
kernel32.dll
WUWeb
WUWeb
Report
Report
7.6.7600.256
7.6.7600.256
Global\WindowsUpdateTracingMutex
Global\WindowsUpdateTracingMutex
WindowsUpdate.log
WindowsUpdate.log
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Trace
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Trace
Windows
Windows
shell32.dll
shell32.dll
%s: %s [
%s: %s [
%s: %s
%s: %s
%s\%s
%s\%s
= Module: %s
= Module: %s
= Module:
= Module:
= Process: %s
= Process: %s
= Process:
= Process:
=========== Logging initialized (build: %s, tz: %s) ===========
=========== Logging initialized (build: %s, tz: %s) ===========
wups2.dll
wups2.dll
wups.dll
wups.dll
Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Setup\ServiceStartup\
Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Setup\ServiceStartup\
%hs %ls page "%ls", hr=%X
%hs %ls page "%ls", hr=%X
Microsoft.WindowsUpdate
Microsoft.WindowsUpdate
wupdmgr.exe
wupdmgr.exe
Failed to cocreate IShellWindows, error = 0xlX
Failed to cocreate IShellWindows, error = 0xlX
Failed to obtain window doc for window %d, error = 0xlX
Failed to obtain window doc for window %d, error = 0xlX
Failed to obtain folder view for window %d, error = 0xlX
Failed to obtain folder view for window %d, error = 0xlX
Failed to obtain folder IPersist for window %d, error = 0xlX
Failed to obtain folder IPersist for window %d, error = 0xlX
Window %d is NOT a WU window
Window %d is NOT a WU window
Done enumerating windows
Done enumerating windows
Quit for window %d failed: 0xlX
Quit for window %d failed: 0xlX
Window %d is a WU window. Attempting to close
Window %d is a WU window. Attempting to close
Failed to obtain class ID for window %d, error = 0xlX
Failed to obtain class ID for window %d, error = 0xlX
Got NULL disp interface for window %d
Got NULL disp interface for window %d
Got %d instead of VT_DISPATCH for window %d
Got %d instead of VT_DISPATCH for window %d
Failed to obtain IWebBrowserApp for window %d, error = 0xlX
Failed to obtain IWebBrowserApp for window %d, error = 0xlX
Failed to enumerate window %d, error = 0xlX
Failed to enumerate window %d, error = 0xlX
Found %d explorer windows
Found %d explorer windows
Closing WU explorer windows
Closing WU explorer windows
Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\VolatileData
Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\VolatileData
WUAppNotificationWindows
WUAppNotificationWindows
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired\Mandatory
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired\Mandatory
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\PostRebootReporting
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\PostRebootReporting
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Services\Pending\
SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Services\Pending\
%chdhd
%chdhd
hd-hd-hd%chd:hd:hd:hd
hd-hd-hd%chd:hd:hd:hd
%WinDir%
%WinDir%
Windows Update
Windows Update
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459)
7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459)
wuauclt.exe
wuauclt.exe
Windows
Windows
Operating System
Operating System