Submission Summary:

What's been foundSeverity Level
Sets the drive to autoplay by creating autorun.inf file in its root directory. If the drive is shared across the network then other remote computers can be infected any time they try to access this share.
Downloads/requests other files from Internet.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 c:\autorun.inf 542 bytes MD5: 0x3DD5872F54137B3516559A611BC31481
SHA-1: 0xE6390986F13C75FE7D625E094D074733C5424D95
Trojan.Autorun!ct [PCTools]
Generic!atr [McAfee]
Mal/AutoInf-B, Mal/AutoInf-A [Sophos]
Worm.Win32.AutoRun [Ikarus]
2 %Temp%\pd7crtpf.dll 29,799 bytes MD5: 0x909D15EF5E241B8B83A09D91DE475E07
SHA-1: 0x20C50BE5D63804EA7440D8DE7B1EC5877EB32595
Trojan-PWS.OnlineGames.generic.A!ct [PCTools]
Trojan.Packed.NsAnti [Symantec]
PWS-Gamania.gen.a [McAfee]
Mal/Generic-A [Sophos]
VirTool:Win32/Vanti.gen!C [Microsoft]
Win-Trojan/Xema.variant [AhnLab]
3 c:\qa8sywva.cmd
%System%\amvo.exe
[file and pathname of the sample #1]
107,966 bytes MD5: 0x26810AD5AF0933B7E68A118E9A2DAAB3
SHA-1: 0x766E607F2B590B865044CBFBE439D7DA09864B66
Trojan-PWS.OnlineGames.generic.A!ct [PCTools]
Trojan.Packed.NsAnti [Symantec]
PWS-Gamania.gen.a [McAfee]
Mal_NSAnti-1 [Trend Micro]
Mal/EncPk-CE, Mal/EncPk-DH [Sophos]
Worm:Win32/Taterf.AA [Microsoft]
Win-Trojan/OnlineGameHack.107966 [AhnLab]
4 %System%\amvo0.dll
%System%\amvo1.dll
74,240 bytes MD5: 0x496C007AB8F55FDE9FEB5ACF3BA6EFC9
SHA-1: 0x84AF83F03245C664DCDA990C73E23D2C6185EB99
Trojan.Lineage.Gen!Pac.3 [PCTools]
Trojan.Packed.NsAnti [Symantec]
PWS-Gamania.gen.a [McAfee]
Mal/EncPk-CE, Mal/EncPk-DH [Sophos]
Worm:Win32/Taterf.A.dll [Microsoft]
Win-Trojan/Xema.variant [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
amvo.exe%System%\amvo.exe204,800 bytes
iexplore.exe%ProgramFiles%\Internet Explorer\iexplore.exe102,400 bytes
[filename of the sample #1][file and pathname of the sample #1]204,800 bytes

Process NameProcess FilenameAllocated Size
explorer.exe%Windir%\explorer.exe131,072 bytes

Module NameModule FilenameAddress Space Details
amvo0.dll%System%\amvo0.dllProcess name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0x2160000 - 0x2184000

 

Registry Modifications

 

Other details

URL to be downloadedFilename for the downloaded bits
http://www.om7890.com/fm4/help.rar%Temp%\help.rar

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.