Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00468FC0 FindFirstFileA,FindFirstFileA,FindClose, |
0_2_00468FC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_0046DB90 lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcpynA,FindFirstFileA,lstrcpynA,lstrcpynA,FindClose, |
0_2_0046DB90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004E3A20 FindFirstFileA,FindNextFileA,FindClose, |
0_2_004E3A20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00469980 FindFirstFileA, |
0_2_00469980 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_0047C0D0 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState, |
0_2_0047C0D0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004C9B00 GetCursorPos,ScreenToClient,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState, |
0_2_004C9B00 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004DD080 GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState, |
0_2_004DD080 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004A9170 GetDeviceCaps,GetDC,GetDC,CreateCompatibleBitmap,CreateCompatibleBitmap,CreateCompatibleDC,SelectObject,BitBlt,SelectObject,DeleteDC,DeleteObject,ReleaseDC, |
0_2_004A9170 |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: No import functions for PE file found |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Section loaded: qtim32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
File deleted: C:\Windows\A6W_DATA\SecuriteInfo.com.Trojan.BrowseBan.32054.rec |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00435DA0 DestroyWindow,GetCurrentProcess,OpenProcessToken,GetLastError,GetLastError,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,ExitWindowsEx, |
0_2_00435DA0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
File created: C:\Windows\A6W_DATA |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004EC150 |
0_2_004EC150 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004A4280 |
0_2_004A4280 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_0045C400 |
0_2_0045C400 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004A4650 |
0_2_004A4650 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004F87B0 |
0_2_004F87B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004C8980 |
0_2_004C8980 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00498B6C |
0_2_00498B6C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004ECF90 |
0_2_004ECF90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004A5380 |
0_2_004A5380 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004F5430 |
0_2_004F5430 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00489550 |
0_2_00489550 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004A55E0 |
0_2_004A55E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004E9640 |
0_2_004E9640 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
File read: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Jump to behavior |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00435DA0 DestroyWindow,GetCurrentProcess,OpenProcessToken,GetLastError,GetLastError,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,ExitWindowsEx, |
0_2_00435DA0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00401280 DefDlgProcA,LockResource,GetDC,SetMapMode,GetClientRect,GetClientRect,SetWindowExtEx,SetWindowExtEx,SetViewportExtEx,SetViewportExtEx,LPtoDP,ReleaseDC,ReleaseDC,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,MoveWindow,SetTimer,SetTimer,GetTickCount,FreeResource,KillTimer,BeginPaint,BeginPaint,GetClientRect,LockResource,SelectPalette,RealizePalette,SetRect,GetStockObject,FillRect,StretchDIBits,SelectPalette,DeleteObject,FreeResource,SetBkMode,SetTextAlign,lstrlenA,lstrlenA,TextOutA,TextOutA,lstrlenA,TextOutA,lstrlenA,lstrlenA,DrawTextA,EndPaint,GetClientRect,GetClientRect,GetStockObject,FillRect,EndDialog, |
0_2_00401280 |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
String found in binary or memory: Failure occured while loading Xtras. Please remove some Xtras from the Xtras directory and try to re-launch application again. |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
String found in binary or memory: Continue%mA duplicate Xtra has been encountered in your Xtras folder(s). Please quit and remove the duplicate to avoid a possible conflict.Failure occured while loading Xtras. Please remove some Xtras from the Xtras directory and try to re-launch application again. |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
File written: C:\Windows\A6W.INI |
Jump to behavior |
Source: classification engine |
Classification label: clean8.winEXE@1/2@0/0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
File read: C:\Windows\A6W.INI |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_0046C520 GetSystemDirectoryA,GetSystemDirectoryA,CharPrevA,CharPrevA,lstrcpyA,GetDiskFreeSpaceExA,GetDiskFreeSpaceA,GetLastError,GetDriveTypeA, |
0_2_0046C520 |
Source: SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Static file information: File size 1570477 > 1048576 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004FB570 LoadLibraryA,GetProcAddress, |
0_2_004FB570 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004828B0 DefWindowProcA,PostQuitMessage,DefWindowProcA,GetLastActivePopup,IsWindowVisible,SetActiveWindow,SendMessageA,SendMessageA,SendMessageA,PostMessageA,IsIconic,DefWindowProcA,DefWindowProcA,DefWindowProcA,GlobalGetAtomNameA,IsIconic, |
0_2_004828B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004828B0 DefWindowProcA,PostQuitMessage,DefWindowProcA,GetLastActivePopup,IsWindowVisible,SetActiveWindow,SendMessageA,SendMessageA,SendMessageA,PostMessageA,IsIconic,DefWindowProcA,DefWindowProcA,DefWindowProcA,GlobalGetAtomNameA,IsIconic, |
0_2_004828B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004D9960 IsWindow,RemovePropA,GetWindow,IsIconic,GetPropA,ShowWindow,IsWindowVisible,ShowWindow,SendMessageA,SetPropA,RemovePropA,RemovePropA,ShowWindow,DefWindowProcA, |
0_2_004D9960 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004EFE90 GetSystemTime followed by cmp: cmp word ptr [esp+0eh], cx and CTI: jne 004EFEF7h |
0_2_004EFE90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004EFE90 GetSystemTime followed by cmp: cmp word ptr [esp+0ch], ax and CTI: jne 004EFEF7h |
0_2_004EFE90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004EFE90 GetSystemTime followed by cmp: cmp word ptr [esp+0ah], ax and CTI: jne 004EFEF7h |
0_2_004EFE90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004EFE90 GetSystemTime followed by cmp: cmp word ptr [esp+06h], ax and CTI: jne 004EFEF7h |
0_2_004EFE90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004EFE90 GetSystemTime followed by cmp: cmp word ptr [esp+04h], ax and CTI: jne 004EFEF7h |
0_2_004EFE90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004A9540 GetSystemInfo, |
0_2_004A9540 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00468FC0 FindFirstFileA,FindFirstFileA,FindClose, |
0_2_00468FC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_0046DB90 lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcpynA,FindFirstFileA,lstrcpynA,lstrcpynA,FindClose, |
0_2_0046DB90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004E3A20 FindFirstFileA,FindNextFileA,FindClose, |
0_2_004E3A20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_00469980 FindFirstFileA, |
0_2_00469980 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
File Volume queried: C:\Users\user\Desktop FullSizeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
File Volume queried: C:\Windows\A6W_DATA FullSizeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
File Volume queried: C:\Windows FullSizeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004FB570 LoadLibraryA,GetProcAddress, |
0_2_004FB570 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004A9540 cpuid |
0_2_004A9540 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004F4520 GetTimeZoneInformation, |
0_2_004F4520 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004F1340 EntryPoint,GetVersion,GetCommandLineA,GetStartupInfoA,GetModuleHandleA, |
0_2_004F1340 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.BrowseBan.32054.exe |
Code function: 0_2_004EFE90 GetLocalTime,GetSystemTime,GetTimeZoneInformation, |
0_2_004EFE90 |