Submission Summary:

What's been foundSeverity Level
Contains characteristics of an identified security risk.


Technical Details:

Possible Security Risk

Threat CategoryDescription
A program that downloads files to the local computer that may represent security risk
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment


File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\install.bat 372 bytes MD5: 0xD4C5F9E5BDD6176A99023499DAA7E4E3
SHA-1: 0xBF1C833F0D625E860E28C2CE87696131057C0391
(not available)
2 %Temp%\MPC5.tmp 8,728 bytes MD5: 0xCC82690550C7B27A142C7A700F025715
SHA-1: 0x9C95CA02D1A6A2D020C46B4F966EA58EB802E33E
(not available)
3 %Temp%\netsf.inf
5,468 bytes MD5: 0xF3382C8AED0569D5C49EAA6BD36D2FCF
SHA-1: 0x1B891237C057EED3508867456FD354A679C355C9
(not available)
4 %Temp%\netsf_m.inf
2,624 bytes MD5: 0x5A7EEFC75B9E3FA71DFC38E3ED9B53C5
SHA-1: 0x9BD703B73DEBE7C25B5CB18560D67EED228D7858
(not available)
5 %Temp%\passthru.sys
29,184 bytes MD5: 0x81907A104908A98A4B5611614A37F6FD
SHA-1: 0x43FBD45D579805F91E64F6B078D9872B5A04AFC5
Trojan.Gen [Symantec]
Trojan-Downloader.Win32.Agent.gktv [Kaspersky Lab]
Generic Downloader.x!fyo [McAfee]
Mal/Generic-L [Sophos]
Trojan:Win32/Bumat!rts [Microsoft]
Trojan.Win32.ServStart [Ikarus]
6 %Temp%\snetcfg.exe 11,776 bytes MD5: 0xE5F0A97853D45C4753060680A5EF02BA
SHA-1: 0xF981D52614A7C9B61F841BBA47F4A7594E958089
(not available)
7 %Windir%\inf\netsf.PNF 6,976 bytes MD5: 0xB0EBFC28A2E77465F227F73FB6A368A8
SHA-1: 0xBA6553691E11B46A8CC3CFEB8E230F0CADEEC14E
(not available)
8 %Windir%\inf\netsf_m.PNF 5,348 bytes MD5: 0xECD3CB9F74F0AF0865F98E57DBDB8CA2
SHA-1: 0xC4000D1A7633D11477831AF0162D77BF873F89FE
(not available)
9 [file and pathname of the sample #1] 50,347 bytes MD5: 0x14757BEE1610969C0E7AC38EA3D04628
SHA-1: 0xAE37EA1BBA2837FAD296854DFE0488FBEE087CE8
New Win32 [McAfee]
Mal/Behav-160 [Sophos]
DDoS:Win32/Nitol.A [Microsoft]


Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]12,877,824 bytes
snetcfg.exe%Temp%\snetcfg.exe24,576 bytes

Process NameProcess FilenameAllocated Size
HelpCtr.exe%Windir%\pchealth\helpctr\binaries\helpctr.exe57,344 bytes
HelpCtr.exe%Windir%\pchealth\helpctr\binaries\helpctr.exe16,384 bytes


Registry Modifications


Other details




