Submission Summary:

What's been foundSeverity Level
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %AppData%\Ykihuk\piyba.exe 334,848 bytes MD5: 0x04D83CD02C175C5EAD47F5C705062E0A
SHA-1: 0x58C33CB0EE430155D72820AD177B7E646B587B54
Trojan-Spy.Win32.Zbot.evho [Kaspersky Lab]
PWS-Zbot.gen.alg [McAfee]
2 %AppData%\ymmoqo.syg 1,322 bytes MD5: 0xB9D8C2739BD87F8757CEAC7C85C3CE4F
SHA-1: 0x518AF44D80F4D1638BAA4D5872CB88576D54DD34
(not available)
3 %Temp%\tmp8767cfc8.bat 168 bytes MD5: 0xE7CB04493D14D43588D6DE433257FAA8
SHA-1: 0x4BCACA738E583369A40630ABC35A8BAAA237E172
(not available)
4 [file and pathname of the sample #1] 334,848 bytes MD5: 0x64949FF9E177573BCF5C560277FC6F82
SHA-1: 0x5E45B6C352C432D2B69855AE0B4C1FF137AE9CAE
Trojan-Spy.Win32.Zbot.evho [Kaspersky Lab]
PWS-Zbot.gen.alg [McAfee]
PWS:Win32/Zbot [Microsoft]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
piyba.exe%AppData%\ykihuk\piyba.exe356,352 bytes
[filename of the sample #1][file and pathname of the sample #1]356,352 bytes

Process NameProcess FilenameAllocated Size
cmd.exe%System%\cmd.exe278,528 bytes

 

Registry Modifications

 

Other details

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.