Modifies some system settings that may have negative impact on overall system security state.
Creates a startup registry entry.
Contains characteristics of an identified security risk.


Technical Details:


Possible Security Risk

Security RiskDescription
Adware.Agent.ZO Adware.Agent.ZO lowers some IE security settings and downloads RogueAntiSpyware without user's permission.

Threat CategoryDescription
A program that downloads files to the local computer that may represent security risk
A potentially unwanted adware program designed to deliver various advertisements to the users' systems
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A hacktool that could be used by attackers to break into a system


File System Modifications

#Filename(s)File SizeFile HashAlias
1 %CommonAppData%\11159064\11159064 56 bytes MD5: 0xB81C9FF6C4C6D4A21CFDA7C5AFCAAEBC
SHA-1: 0xF37DDC57E8578C1428558FBCF7238FEFA7524301
(not available)
2 %CommonAppData%\11159064\pc11159064ins 0 bytes MD5: 0xD41D8CD98F00B204E9800998ECF8427E
SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709
(not available)
3 %Temp%\avyb.exe 19,480 bytes MD5: 0x3110FA2BBCB3C6EC4A6C72BB76E1DBA7
SHA-1: 0xD0AEFA4DD5362046C43E3523142EE9C70AA4E3D3
(not available)
4 %Temp%\merunime.dll 52,736 bytes MD5: 0xFBC3A4E3509E0C556BB6D53AB41634CC
SHA-1: 0x69F55B5FB43FCED93C8B4BBFEB63A566A771DEAE
Trojan-Downloader.Win32.Agent.bqxc [Kaspersky Lab]
Trojan.Vundo [Ikarus]
5 %Temp%\metitalu.dll 50,176 bytes MD5: 0xF819CBE2250C9AE6B1C9A109AFF4AFC1
SHA-1: 0x29794BC167C106C1235881FF743E25024E47BEBE
not-a-virus:AdWare.Win32.Virtumonde.balk [Kaspersky Lab]
Vundo.gen.bp [McAfee]
TROJ_VUNDO.HGO [Trend Micro]
6 %Temp%\udptrn32.dll 45,056 bytes MD5: 0xA13640BDCFD960FC30DB7947FB09804E
SHA-1: 0x15BF3569D119CC50B4638EE670F6F0E42A8F291C
(not available)
7 %Windir%\braviax.exe
10,752 bytes MD5: 0x9CC2F1040B4037654B183800CFB91665
SHA-1: 0x7E128B2AAD943FFA4F4917D5D455272CD458F74D
Packed.Generic.233 [Symantec]
Trojan-Downloader.Win32.FraudLoad.wsia [Kaspersky Lab]
Generic Downloader.x!bhm [McAfee]
Mal/EncPk-IF [Sophos]
Trojan-Downloader.Win32.FraudLoad [Ikarus]
8 %Windir%\cru629.dat
6,144 bytes MD5: 0x209E4034E37991495580CF4F2BDFA5F8
SHA-1: 0x2FB5CD6D40C9B5E4ED308E8EBF9B053D26AE9895
Trojan.Virantix.C [Symantec]
Backdoor.Win32.Small.ejx [Kaspersky Lab]
Downloader.gen.a [McAfee]
Mal/TibsPak, Mal/EncPk-BB [Sophos]
Win-Trojan/Agent.6144.HK [AhnLab]
9 %System%\dllcache\beep.sys 28,672 bytes MD5: 0x471098B6001A434561CC4CE1F068907C
SHA-1: 0xDA1BF077F4B17D54641AF7DC6D1E888FC2BEA42E
Hacktool.Rootkit [Symantec]
Backdoor.Win32.UltimateDefender.igv [Kaspersky Lab]
FakeAlert-C.dr [McAfee]
Mal/FakeAle-C [Sophos]
Backdoor.Win32.UltimateDefender [Ikarus]
10 [file and pathname of the sample #1] 872,383 bytes MD5: 0x38EC817FEF29318DB0D001D084BAF4CC
SHA-1: 0xEAA1AB49FF795A4130FA633AB24862888DCF2F0B
Backdoor.Win32.UltimateDefender.ike, Packed.Win32.Krap.x, Trojan-Downloader.Win32.Agent.bqxc, not-a-virus:AdWare.Win32.Virtumonde.balk [Kaspersky Lab]
Trojan.Vundo [Ikarus]


Memory Modifications

Process NameProcess FilenameMain Module Size
braviax.exe%System%\braviax.exe53,248 bytes
11159064.exe%CommonAppData%\11159064\11159064.exe999,424 bytes


Registry Modifications


Other details


1055UDPbraviax.exe (%System%\braviax.exe)



