Submission Summary:

What's been foundSeverity Level
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Worm.AutoRun.GEN Worm.AutoRun.GEN is a threat that spreads through available drives and is able to automatically execute itself. It also attempts to disable security-related applications based on their filenames

Threat CategoryDescription
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\E_4\krnln.fnr 1,097,728 bytes MD5: 0x199E87EA6B03E907316560A58F7B51AF
SHA-1: 0x8515B7D54E11BA32C52240044164B60B2F112341
Trojan-PWS.SuspectCRC [Ikarus]
2 %Temp%\E_4\mp3.run 188,416 bytes MD5: 0xAE6D39C6AE6D8D83506C177417750FDB
SHA-1: 0x4C75A3A3C7F4C7257AC4F1A09E11943EFF43BE27
(not available)
3 %Temp%\E_4\shell.fne 40,960 bytes MD5: 0xD54753E7FC3EA03AEC0181447969C0E8
SHA-1: 0x824E7007B6569AE36F174C146AE1B7242F98F734
W32/Emerleox.worm [McAfee]
W32/AutoRun-MO [Sophos]
Win-Trojan/Startpage.40960.EX [AhnLab]
4 %Temp%\E_4\spec.fne 69,632 bytes MD5: 0x1518651C682109E9B9C304C9C109D777
SHA-1: 0x6C440810BF11907FC16DBCA17A9494377C0BDCF1
Tool-EPLLib [McAfee]
W32/AutoRun-MO [Sophos]
Trojan.Win32.AutoRun [Ikarus]
5 %Temp%\good.mp3 240,093 bytes MD5: 0xF323CDC160337A86405565824D430E5B
SHA-1: 0x98FF05FF2FC4E6F31BC8547F580C65C948D7B1FD
(not available)
6 [file and pathname of the sample #1] 962,932 bytes MD5: 0x1A1FED402C6663AE74709F958FD4CF35
SHA-1: 0xEC2EB5B48D067EFD4DFC13542C6F771AC5489803
Backdoor.Trojan [Symantec]
Hoax.Win32.Agent.agj [Kaspersky Lab]
BackDoor-DRV.gen.c [McAfee]
Worm:Win32/Orbina!rts [Microsoft]
Hoax.Win32.Agent [Ikarus]
Win32/Flystudio.worm.Gen [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]319,488 bytes

 

Other details

China

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.