Technical Details
Payload
Removal instructions
Technical Details
This Trojan is designed to install and launch other programs on the victim machine without the knowledge or consent of the user. It is a Windows application (PE EXE file). It is 556 544 bytes in size. It is packed using ASProtect. The unpacked file is approximately 915 KB in size. It is written in Delphi.
Payload
Once launched, the Trojan extracts the following files from its body to the current user's temporary directory:
%Temp%\Blocked dealers.xls
%Temp%\tmp.exe
This file is 349 184 bytes in size. It is detected by Kaspersky Anti-Virus as Trojan-Dropper.Win32.Delf.grq.
The Trojan then launches the extracted "Blocked dealers.xls" file using the application associated with this file type and launches for execution the extracted "tmp.exe" file, which steals access keys to the "CyberPlat" payment processing system. It has the following payload:
The Trojan checks for the presence of the following registry key:
[HKCU\Software\IprivCom\Keys]
If the key is missing, the Trojan creates a command interpreter file in its working directory and uses it to delete its body:
%WorkDir%\<rnd1>.bat
where <rnd1> is a random set of numbers.
If the registry key exists, the Trojan creates a copy of its body in the Windows system directory under the name:
%System%\iprivcom2.exe
It also extracts a file from its body and injects it into the Windows system directory as:
%System%\iprivcom.dll
This file is 11 776 bytes in size. It is detected by Kaspersky Anti-Virus as Backdoor.Win32.Poison.bxbv.
For the following files:
%System%\iprivcom2.exe
%System%\iprivcom.dll
It applies the "hidden" attribute and sets the same creation date as the Windows directory creation date.
The Trojan calls the "SetStartUp" function from the extracted "iprivcom.dll" file to register its body in the Windows autorun key.
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"Authorization Interface"="%System%\iprivcom2.exe"
The Trojan calls the "HideProcess" function from the extracted "iprivcom.dll" file to hide its process in the system.
It determines the language installed in the system, and on the basis of this it either searches for Russian-language strings (if the system language is set to Russian), or English-language strings (in all other cases).
It searches for and terminates the application with the following window header:
User identification
User authorization
It then creates a window similar to the closed one. This allows the Trojan to obtain the passphrase for the private key.

It uses the system registry key to determine the private key storage location:
[HKCU\Software\IprivCom\Keys]
It creates a copy of the private key in the current user's temporary directory named:
%Temp%\<rnd2>.key
where <rnd2> is a random set of numbers.
The Trojan then encodes it, using the following intermediary file:
%Temp%\<rnd2>.tmp
where <rnd2> is a random set of numbers.
It then uses the POST method to send the created file to the following address:
http://m***er.am/gates/cgr-gate_2/in_key.php
It creates a file in the current user's temporary directory to which it saves information about the infected system, such as the user ID, system version, local time, time zone, installed keys, and passphrase to the private key:
%Temp%\<rnd2>.cgr
where <rnd2> is a random set of numbers.
It uses the POST method to send the created file to the following address:
http://m***er.am/gates/cgr-gate_2/in_rep.php
The Trojan then ceases running.
Removal instructions
If your computer does not have antivirus protection and has been infected by this malicious program, follow the instructions below to delete it:
- Delete the following system registry key (see What is a system registry and how do I use it?):
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"Authorization Interface"="%System%\iprivcom2.exe"
- Reboot the system.
- Delete the original Trojan file (its location will depend on how the program originally penetrated the infected computer).
- Delete the following files:
%WorkDir%\<rnd1>.bat
%System%\iprivcom2.exe
%System%\iprivcom.dll
%Temp%\Blocked dealers.xls
%Temp%\tmp.exe
%Temp%\<rnd2>.key
%Temp%\<rnd2>.tmp
%Temp%\<rnd2>.cgr
where <rnd1> and <rnd2> are random sets of numbers.
- Perform a full scan of the computer using Kaspersky Anti-Virus with up-to-date antivirus databases (download a trial version).
MD5: 20F6CE58A8F06D3AC4D15C894487E973
SHA1: 181FF4592E0325C685BDFB90AA10053E336C2BA9
Summary
Technical details
File size of 556544 bytes.
Installation
Creates the following files on an infected computer:
-
Directory of users' settings%Documents and Settings%\ALLUSE~1\APPLIC~1\MICROS~1\OFFICE\DATA\opa11.dat
Malicious activity
Steals confidential user information from
A malicious program designed to steal user information related to banking and electronic payment systems and bank cards. The information is sent to a cybercriminal via email, ftp, the web or other methods.
Read more details here: http://www.viruslist.com/en/analysis?pubid=204792037the following banks, financial institutions, payment systems:
Creates the following files:
-
Directory for storage of temporary files on Windows OS (usually, C:\Documents and Settings\\Local Settings\Temp)%Temp%\tmp.exe
(Kaspersky Anti-Virus detects as Trojan-Dropper.Win32.Delf.grq)
-
Directory for storage of temporary files on Windows OS (usually, C:\Documents and Settings\\Local Settings\Temp)%Temp%\Заблокированные дилеры.xls
Launches files shown below for execution:
-
Directory for storage of temporary files on Windows OS (usually, C:\Documents and Settings\\Local Settings\Temp)%Temp%\tmp.exe
-
Directory for storage of temporary files on Windows OS (usually, C:\Documents and Settings\\Local Settings\Temp)%Temp%\Заблокированные дилеры.xls
Creates unique identifiers to flag its presence in the system
- Local\Mutex_MSOSharedMem
- Local\Mso97SharedDg19211105606Mutex
- Local\Mso97SharedDg20321105606Mutex
- Local\Mso97SharedDg19521105606Mutex
- Local\Mso97SharedDg19531105606Mutex
- OfficeAssistantStateMutex
- Global\MTX_MSO_Formal1_S-1-5-21-1715567821-1757981266-839522115-1003
- Global\MTX_MSO_AdHoc1_S-1-5-21-1715567821-1757981266-839522115-1003
- Local\SqmSysTray
Uses the masks shown below to search for files on the victim machine:
Other activities
Modifies the system registry keys:
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Shared Tools\Outlook\Journaling\Microsoft Excel ]
"Enabled" = "0x0"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\Common\Assistant ]
"CurrAsstState" = "0x26"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Excel\Options ]
"Asst In Wizard" = "0x0"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Excel\Options ]
"Wizard Timestamp" = "2010,6,18,17,59,1,6"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN ]
"FriendlyName" = "Microsoft Excel"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Common\ReviewCycle ]
"ReviewToken" = "{BB520B4C-27F8-4187-A5BB-887470796CD7}"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Common\BaseSuite ]
"A2B280D420FB472099F740C09FBCE10A" = "0x1"
Deletes the following system registry keys:
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Excel\Resiliency ]
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems ]
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Excel\Resiliency\DocumentRecovery ]
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Excel\Resiliency\DocumentRecovery\1FCCB ]
Deletes the following parameters of the system registry keys:
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems\]y ]
"01" = ""
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN ]
"LabelText" = ""
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN ]
"Save" = ""
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN ]
"NoLabelOption" = ""
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN ]
"NoSaveOption" = ""
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN ]
"NoButtonOption" = ""
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\Common\Smart Tag\Applications\XLMAIN ]
"NoIndicatorOption" = ""
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Office\11.0\Excel\Resiliency\DocumentRecovery\1FCCB ]
"1FCDA" = ""
Deletes the following files on an infected computer:
- c:\aspr_keys.ini
-
Directory for storage of temporary files on Windows OS (usually, C:\Documents and Settings\\Local Settings\Temp)%Temp%\tmp.exe
-
Directory for storage of temporary files on Windows OS (usually, C:\Documents and Settings\\Local Settings\Temp)%Temp%\aspr_keys.ini
-
Current user directory (usually, C:\Documents and Settings\) %UserDir%\Local Settings\Application Data\Microsoft\Schemas\MS Excel_restart.xml
-
Current user directory (usually, C:\Documents and Settings\) %UserDir%\Application Data\Microsoft\Office\Recent\Temp.LNK
-
Current user directory (usually, C:\Documents and Settings\) %UserDir%\Application Data\Microsoft\Office\Recent\Заблокированные дилеры.xls.LNK