| Visit ThreatExpert web site | | | Close Report |
[Ikarus]
![]() | Possible Security Risk |
| Threat Category | Description |
![]() |
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | c:\Date.Msi\3proxy.cfg | 132 bytes | MD5: 0x8342B622CA3CE4DC24DFE9D1D73AA231 SHA-1: 0x88DDBD474304E28A13F0B8B645074456CC78641B |
(not available) |
| 2 |
c:\Date.Msi\alg.exe
|
184,832 bytes | MD5: 0xB266ECB0D859A5F5D049CF75EE3F8878 SHA-1: 0x8D8E12CAE1174339906FC2E2AE92501093D5F7D1 |
(not available) |
| 3 |
c:\Date.Msi\cssrs.exe
|
151,040 bytes | MD5: 0x11BC899833A9B8B5A27FA311FFA1F1B0 SHA-1: 0xFC819AE8DB8559741BCF522FACD9BA506DA338F6 |
Backdoor.Trojan [Symantec]not-a-virus:Server-Proxy.Win32.3proxy.ge [Kaspersky Lab] Proxy-Thrap [McAfee]not-a-virus:Server-Proxy.Win32.3proxy [Ikarus] |
| 4 |
c:\Date.Msi\DiskDoctor.lnk
%Programs%\Startup\DiskDoctor.lnk |
497 bytes | MD5: 0xC98E10C0AE1A6C892F0A4483A7605C26 SHA-1: 0x95A58B8352E0D228A9A368C62830EB342339982A |
(not available) |
| 5 |
c:\Date.Msi\System.exe
|
330,752 bytes | MD5: 0xF4BF5C28BED38E31C143ABFB9BEBB6D5 SHA-1: 0x015F3E7CE4FF406F712B4EE1C893EDFAA9276259 |
(not available) |
| 6 | [file and pathname of the sample #1] | 407,533 bytes | MD5: 0x469A1AEA390CC8594BA0895D56678CF9 SHA-1: 0xA9ABC885AF6E9584BB127E7CC1154102E5ED5811 |
not-a-virus:Server-Proxy.Win32.3proxy.ge [Kaspersky Lab] not-a-virus:Server-Proxy.Win32.3proxy [Ikarus] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 221,184 bytes |
cssrs.exe![]() | c:\date.msi\cssrs.exe![]() | 159,744 bytes |
alg.exe![]() | c:\Date.Msi\alg.exe![]() | 241,664 bytes |
system.exe![]() | c:\date.msi\system.exe![]() | 360,448 bytes |
![]() | Registry Modifications |
![]() | Other details |
| Remote Host | Port Number |
| zeta.proxyfied.net | 22 |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.