Here is the brief for R.exe (sww and gostev included)
After UPX it's crypted and packed again.
Malware has Russian origin
averi_sosut_hui
Main executable contains specific code against Kaspersky, AVG, Prevx, Avira, Windows Defender, CA HIPS.
Operates with ntvdm (also checks for presence of KB977165 - MS10-015 patch). Contains list of IP addresses and default passwords.
soccer abc123 password1 football1 fuckyou monkey iloveyou1 superman1 slipknot1 jordan23 princess1 liverpool1
monkey1 baseball1 123abc qwerty1 blink182 myspace1 pop user111 098765 qweryuiopas qw qwe qwer qwert qwerty asdfg
chort nah xak xakep 111111 12 12345 2013 2007 2207 110 5554 775 65 5 46 354 43 23 31 1982 13 123 password
123456
Detects Sandbox.
Writes to HKLM\software\microsoft\windows nt\currentversion\winlogon, under UserInit param, changes registry key security attributes.
Nanocephalous Kaspersky Lab
Injects dll (maps) into winlogon.exe, explorer.exe and performs hooking of several API's.
[428]winlogon.exe-->kernel32.dll-->CreateFileW, Type: Inline - DirectJump 0x7C8107F0-->01AF0000 [unknown_code_page]
[428]winlogon.exe-->kernel32.dll-->GetFileAttributesExW, Type: Inline - DirectJump 0x7C811185-->01B20000 [unknown_code_page]
[428]winlogon.exe-->advapi32.dll-->CryptEncrypt, Type: Inline - DirectJump 0x77DDE340-->01B50000 [unknown_code_page]
[428]winlogon.exe-->user32.dll-->GetWindowTextA, Type: Inline - DirectJump 0x7E38216B-->01E80000 [unknown_code_page]
[428]winlogon.exe-->wininet.dll-->InternetWriteFile, Type: Inline - DirectJump 0x771E8BB9-->01F10000 [unknown_code_page]
[428]winlogon.exe-->ws2_32.dll-->getaddrinfo, Type: Inline - DirectJump 0x71A92A6F-->01F40000 [unknown_code_page]
[428]winlogon.exe-->ws2_32.dll-->inet_addr, Type: Inline - DirectJump 0x71A92EE1-->01FA0000 [unknown_code_page]
[428]winlogon.exe-->ws2_32.dll-->send, Type: Inline - DirectJump 0x71A94C27-->01EB0000 [unknown_code_page]
[428]winlogon.exe-->ws2_32.dll-->gethostbyname, Type: Inline - DirectJump 0x71A95355-->01F70000 [unknown_code_page]
[428]winlogon.exe-->ws2_32.dll-->WSASend, Type: Inline - DirectJump 0x71A968FA-->01EE0000 [unknown_code_page]
[1104]explorer.exe-->kernel32.dll-->GetFileAttributesW, Type: Inline - DirectJump 0x7C80B7DC-->01D00000 [unknown_code_page]
[1104]explorer.exe-->kernel32.dll-->CreateFileW, Type: Inline - DirectJump 0x7C8107F0-->01890000 [unknown_code_page]
[1104]explorer.exe-->kernel32.dll-->GetFileAttributesExW, Type: Inline - DirectJump 0x7C811185-->019C0000 [unknown_code_page]
[1104]explorer.exe-->advapi32.dll-->CryptEncrypt, Type: Inline - DirectJump 0x77DDE340-->019F0000 [unknown_code_page]
[1104]explorer.exe-->user32.dll-->GetMessageW, Type: Inline - DirectJump 0x7E3691C6-->01C60000 [unknown_code_page]
[1104]explorer.exe-->user32.dll-->PeekMessageW, Type: Inline - DirectJump 0x7E36929B-->01C00000 [unknown_code_page]
[1104]explorer.exe-->user32.dll-->GetMessageA, Type: Inline - DirectJump 0x7E37772B-->01C30000 [unknown_code_page]
[1104]explorer.exe-->user32.dll-->PeekMessageA, Type: Inline - DirectJump 0x7E37A340-->01BD0000 [unknown_code_page]
[1104]explorer.exe-->user32.dll-->GetClipboardData, Type: Inline - DirectJump 0x7E380DBA-->01C90000 [unknown_code_page]
[1104]explorer.exe-->user32.dll-->GetWindowTextA, Type: Inline - DirectJump 0x7E38216B-->01A20000 [unknown_code_page]
[1104]explorer.exe-->wininet.dll-->InternetWriteFile, Type: Inline - DirectJump 0x771E8BB9-->01AB0000 [unknown_code_page]
[1104]explorer.exe-->ws2_32.dll-->getaddrinfo, Type: Inline - DirectJump 0x71A92A6F-->01AE0000 [unknown_code_page]
[1104]explorer.exe-->ws2_32.dll-->inet_addr, Type: Inline - DirectJump 0x71A92EE1-->01B40000 [unknown_code_page]
[1104]explorer.exe-->ws2_32.dll-->send, Type: Inline - DirectJump 0x71A94C27-->01A50000 [unknown_code_page]
[1104]explorer.exe-->ws2_32.dll-->gethostbyname, Type: Inline - DirectJump 0x71A95355-->01B10000 [unknown_code_page]
[1104]explorer.exe-->ws2_32.dll-->WSASend, Type: Inline - DirectJump 0x71A968FA-->01A80000 [unknown_code_page]
Dll also packed with UPX.
http://www.virustotal.com/file-scan/rep ... 1290745139
Unpacked dll contains another blacklist (AVZ, Kaspersky, HijackThis Anti-Malware, OSAM). Soft detected via
EnumWindows.
Антивирусная утилита AVZ random's system information tool - © random/random
ThunderRT6FormDC hijackthis AVP.MainWindow Kaspersky Virus Removal Tool 2010 Malwarebytes' Anti-Malware #32770 OSAM: Autorun Manager
In attach dump of dll strings and IDA enough friendly partially unpacked binary.