| Visit ThreatExpert web site | | | Close Report |
[Symantec]
[McAfee]
[Microsoft]
[Ikarus]| What's been found | Severity Level |
| Contains characteristics of an identified security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
Worm.AutoRun.GEN![]() |
Worm.AutoRun.GEN is a threat that spreads through available drives and is able to automatically execute itself. It also attempts to disable security-related applications based on their filenames |
| Threat Category | Description |
![]() |
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %Temp%\E_4\krnln.fnr | 1,097,728 bytes | MD5: 0x199E87EA6B03E907316560A58F7B51AF SHA-1: 0x8515B7D54E11BA32C52240044164B60B2F112341 |
Trojan-PWS.SuspectCRC [Ikarus] |
| 2 | %Temp%\E_4\mp3.run | 188,416 bytes | MD5: 0xAE6D39C6AE6D8D83506C177417750FDB SHA-1: 0x4C75A3A3C7F4C7257AC4F1A09E11943EFF43BE27 |
(not available) |
| 3 | %Temp%\E_4\shell.fne | 40,960 bytes | MD5: 0xD54753E7FC3EA03AEC0181447969C0E8 SHA-1: 0x824E7007B6569AE36F174C146AE1B7242F98F734 |
W32/Emerleox.worm [McAfee]W32/AutoRun-MO [Sophos]Win-Trojan/Startpage.40960.EX [AhnLab] |
| 4 | %Temp%\E_4\spec.fne | 69,632 bytes | MD5: 0x1518651C682109E9B9C304C9C109D777 SHA-1: 0x6C440810BF11907FC16DBCA17A9494377C0BDCF1 |
Tool-EPLLib [McAfee]W32/AutoRun-MO [Sophos]Trojan.Win32.AutoRun [Ikarus] |
| 5 | %Temp%\good.mp3 | 240,093 bytes | MD5: 0xF323CDC160337A86405565824D430E5B SHA-1: 0x98FF05FF2FC4E6F31BC8547F580C65C948D7B1FD |
(not available) |
| 6 | [file and pathname of the sample #1] | 962,932 bytes | MD5: 0x1A1FED402C6663AE74709F958FD4CF35 SHA-1: 0xEC2EB5B48D067EFD4DFC13542C6F771AC5489803 |
Backdoor.Trojan [Symantec]Hoax.Win32.Agent.agj [Kaspersky Lab] BackDoor-DRV.gen.c [McAfee]Worm:Win32/Orbina!rts [Microsoft]Hoax.Win32.Agent [Ikarus]Win32/Flystudio.worm.Gen [AhnLab] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 319,488 bytes |
![]() | Other details |
![]() |
China |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.