Submission Summary:

What's been foundSeverity Level
Sets the drive to autoplay by creating autorun.inf file in its root directory. If the drive is shared across the network then other remote computers can be infected any time they try to access this share.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 c:\autorun.inf 618 bytes MD5: 0x3EE014B2107300F5F14B3B3E6A3F7BD0
SHA-1: 0x1F05CF787E6C6DE83B3C907C971F50D890B7138F
Trojan-PWS.OnlineGames.generic.A!ct [PCTools]
Trojan-GameThief.Win32.OnLineGames.ssx [Kaspersky Lab]
Generic!atr [McAfee]
Mal/AutoInf-B, Mal/AutoInf-A [Sophos]
Trojan-GameThief.Win32.OnLineGames [Ikarus]
BAT/OnlineGameHack [AhnLab]
2 %Temp%\zamxy7il.dll 30,091 bytes MD5: 0x46A4A48A46CA1A611A22DE81DD33EBB8
SHA-1: 0x025CD0A7795E71EC8852DED2F0DF48DF33B8FA84
Trojan.Lineage.Gen!Pac.3 [PCTools]
Infostealer.Gampass [Symantec]
Trojan-GameThief.Win32.OnLineGames.ssx [Kaspersky Lab]
PWS-Gamania.gen.a [McAfee]
Mal/EncPk-CE [Sophos]
VirTool:Win32/Vanti.gen!D [Microsoft]
Trojan-GameThief.Win32.OnLineGames [Ikarus]
3 %System%\amvo.exe
[file and pathname of the sample #1]
c:\y82td3td.com
108,450 bytes MD5: 0x33AE3E85A03E02F5600BFB79A1EF8E6A
SHA-1: 0xE1BCAB50067CFFD37C7C18394E57CDE766D3BD44
Trojan-PWS.OnlineGames.ARUN [PCTools]
Infostealer.Gampass [Symantec]
Trojan-GameThief.Win32.OnLineGames.ssx [Kaspersky Lab]
PWS-Gamania.gen.a [McAfee]
Mal_NSAnti-1 [Trend Micro]
Mal/EncPk-CE [Sophos]
Worm:Win32/Taterf.AA [Microsoft]
4 %System%\amvo0.dll
%System%\amvo1.dll
71,680 bytes MD5: 0xCF5E004B43C08214D5FAF14630ECFEAB
SHA-1: 0xD7C1D826B1BF5D4B6F8B791459D8DDDE60C695A6
Trojan.Lineage.Gen!Pac.3 [PCTools]
Trojan.Packed.NsAnti [Symantec]
Trojan-GameThief.Win32.OnLineGames.ssx [Kaspersky Lab]
PWS-Gamania.gen.a [McAfee]
Mal_NSAnti-1 [Trend Micro]
Mal/EncPk-CE, Mal/Krap-K, Mal/Krap-K [Sophos]
Worm:Win32/Taterf.A.dll [Microsoft]
Trojan-GameThief.Win32.OnLineGames [Ikarus]

 

Memory Modifications

Module NameModule FilenameAddress Space Details
amvo0.dll%System%\amvo0.dllProcess name: explorer.exe
Process filename: %Windir%\explorer.exe
Address space: 0x1FF0000 - 0x2013000

Driver NameDriver Filename
wincab.sys%System%\wincab.sys

 

Registry Modifications

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.