Analysis Date2018-05-10 21:58:27
MD51fe672d70f691a2e40e373e0ce54e2b8
SHA16c2b3989beccaaf4c511e73475cf18eb044f7bb4

Static Details:

AVArcabit (arcavir)Win32.VJadtre.3
AVAuthentiumW32/PatchLoad.E
AVGrisoft (avg)Win32/Wapomi.I
AVAvira (antivir)W32/Jadtre.B
AVAlwil (avast)Error Scanning File
AVAd-AwareWin32.VJadtre.3
AVBitDefenderWin32.VJadtre.3
AVBullGuardWin32.VJadtre.3
AVClamAVError Scanning File
AVDr. WebBackDoor.Darkshell.246
AVEmsisoftWin32.VJadtre.3
AVMicroWorld (escan)Win32.VJadtre.3
AVCA (E-Trust Ino)Error Scanning File
AVFortinetW32/Wapomi.BA!tr
AVFrisk (f-prot)W32/PatchLoad.E
AVF-SecureWin32.VJadtre.3
AVIkarusError Scanning File
AVK7Virus ( 0040f7441 )
AVKasperskyError Scanning File
AVMalwareBytesNo Virus
AVMcafeeW32/Kudj
AVMicrosoft Security EssentialsVirus:Win32/Mikcer.B
AVNANOTrojan.Win32.Banload.cstqaj
AVEset (nod32)Win32/Wapomi.BA virus
AVPadvishNo Virus
AVCAT (quickheal)W32.Nimnul.F1
AVRisingWin32.Roue.a
AV360 SafeVirus.Win32.Agent.P
AVSUPERAntiSpywareNo Virus
AVSymantecTrojan.Gen.6
AVTrend MicroPE_WAPOMI.BM
AVTwisterVirus.558BEC81EC@120000#.mg
AVVirusBlokAda (vba32)Virus.Nimnul.19209
AVWindows DefenderVirus:Win32/Mikcer.B
AVZillya!Virus.Nimnul.Win32.5

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\6c2b3989beccaaf4c511e73475cf18eb044f7bb4.exe

Creates FileC:\Users\Phil\AppData\Local\Temp\QuqNCSrw.exe
Creates FileC:\Users\Phil\AppData\Local\Temp\Resources\en\HelpViewerStrings.dat
Creates FileC:\Windows\Globalization\Sorting\sortdefault.nls
Creates FileC:\Windows\System32\ieframe.dll
Creates FileC:\Windows\System32\stdole2.tlb
Creates FileC:\
Creates FileC:\Users\Phil\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
Creates FileC:\Users\Phil\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db
Creates FileC:\Users\desktop.ini
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\AppData
Creates FileC:\Users\Phil\AppData\Local
Creates FileC:\Users\Phil\AppData\Local\Temp
Creates FileC:\Users\Phil\AppData\Local\Temp\help.html
Creates FileC:\
Creates Mutex
Creates Mutex
Creates Mutex

Process
↳ C:\Users\Phil\AppData\Local\Temp\QuqNCSrw.exe

Creates FileC:\Users\Phil\AppData\Local\Temp\QuqNCSrw.exe
Creates FileC:\Windows\Globalization\Sorting\sortdefault.nls
Creates FileC:\Program Files\DVD Maker\DVDMaker.exe
Creates FileC:\Program Files\Java\jre6\bin\java-rmi.exe
Creates FileC:\Program Files\Java\jre6\bin\java.exe
Creates FileC:\Program Files\Java\jre6\bin\javacpl.exe
Creates FileC:\Program Files\Java\jre6\bin\javaw.exe
Creates FileC:\Program Files\Java\jre6\bin\javaws.exe
Creates FileC:\Program Files\Java\jre6\bin\jbroker.exe
Creates FileC:\Program Files\Java\jre6\bin\jp2launcher.exe
Creates FileC:\Program Files\Java\jre6\bin\keytool.exe
Creates FileC:\Program Files\Java\jre6\bin\kinit.exe
Creates FileC:\Program Files\Java\jre6\bin\klist.exe
Creates FileC:\Program Files\Java\jre6\bin\ktab.exe
Creates FileC:\Program Files\Java\jre6\bin\orbd.exe
Creates FileC:\Program Files\Java\jre6\bin\pack200.exe
Creates FileC:\Program Files\Java\jre6\bin\policytool.exe
Creates FileC:\Program Files\Java\jre6\bin\rmid.exe
Creates FileC:\Program Files\Java\jre6\bin\rmiregistry.exe
Creates FileC:\Program Files\Java\jre6\bin\servertool.exe
Creates FileC:\Program Files\Java\jre6\bin\ssvagent.exe
Creates FileC:\Program Files\Java\jre6\bin\tnameserv.exe
Creates FileC:\Program Files\Java\jre6\bin\unpack200.exe
Creates FileC:\Program Files\Windows Defender\MpCmdRun.exe
Creates FileC:\Program Files\Windows Defender\MSASCui.exe
Creates FileC:\Program Files\Windows Journal\Journal.exe
Creates FileC:\Program Files\Windows Journal\PDIALOG.exe
Creates FileC:\Program Files\Windows Mail\wab.exe
Creates FileC:\Program Files\Windows Mail\wabmig.exe
Creates FileC:\Program Files\Windows Mail\WinMail.exe
Creates FileC:\Program Files\Windows Photo Viewer\ImagingDevices.exe
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\QuqNCSrw_RASMANCS\EnableFileTracing ➝
0
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\QuqNCSrw_RASMANCS\EnableConsoleTracing ➝
0
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\QuqNCSrw_RASMANCS\FileTracingMask ➝
4294901760
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\QuqNCSrw_RASMANCS\ConsoleTracingMask ➝
4294901760
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\QuqNCSrw_RASMANCS\MaxFileSize ➝
1048576
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\QuqNCSrw_RASMANCS\FileDirectory ➝
%windir%\tracing

Network Details:


Raw Pcap

Strings