| Visit ThreatExpert web site | | | Close Report |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %AppData%\GuardSupport\GuardConvert.exe | 179,232 bytes | MD5: 0x666AFC1F08313201F213130425EBF867 SHA-1: 0x059CF2322F61007F7BC24ECF13EE48694B92F811 |
PWS-Zbot.gen.aju [McAfee] AdWare.Win32.Hebogo [Ikarus] |
| 2 | %AppData%\MicroLab\MyEngin\Common\MicroProCon.exe | 105,504 bytes | MD5: 0xA341729E7FB6D5A3B115331B99E70292 SHA-1: 0x75883478FC60DBCE34034C5F9E37AB56968DAD49 |
AdWare.Win32.Hebogo [Ikarus] |
| 3 | %AppData%\MicroLab\MyEngin\Common\Uninstall\IRIMG1.JPG | 2,362 bytes | MD5: 0xAF18F3F894BE69733E04750B236E219A SHA-1: 0x8E552822666E75F5B6054787E827FF51D3425A2E |
(not available) |
| 4 | %AppData%\MicroLab\MyEngin\Common\Uninstall\IRIMG2.JPG | 29,054 bytes | MD5: 0xAC40DED6736E08664F2D86A65C47EF60 SHA-1: 0xC352715BBF5AE6C93EEB30DF2C01B6F44FAEDAAA |
(not available) |
| 5 | %AppData%\MicroLab\MyEngin\Common\Uninstall\uninstall.dat | 127,656 bytes | MD5: 0xC05CD9714FB343D7BA213E92F36667B9 SHA-1: 0x00AD0CA5A544593E6C697C5222FB41FAC9CBD168 |
(not available) |
| 6 |
%AppData%\MicroLab\MyEngin\Common\Uninstall\Uninstall.exe
%Temp%\_ir_sf_temp_0\irsetup.exe
|
580,096 bytes | MD5: 0x3FE7C92DBA5C9240B4AB0D6A87E6166A SHA-1: 0x7980D7DFFC073515B621834246DDA33AB00C308D |
packed with UPX [Kaspersky Lab] |
| 7 | %AppData%\MicroLab\MyEngin\Common\Uninstall\uninstall.xml | 7,371 bytes | MD5: 0xB85F0EC6DACB9F63821A8C4A998803F2 SHA-1: 0x6FE2DA7BBE5829542A3CFE454F773C1AB489C20B |
(not available) |
| 8 | [file and pathname of the sample #1] | 868,536 bytes | MD5: 0x6B70AC3E6DCEADCE55F63924C834E2EA SHA-1: 0xDF6A742ABF9427F80E2CE287A4DC8B20F657280A |
(not available) |
| 9 |
%System%\VB6KO.DLL
|
102,160 bytes | MD5: 0x84742B5754690ED667372BE561CF518D SHA-1: 0xEF97AA43F804F447498568FC33704800B91A7381 |
(not available) |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 86,016 bytes |
irsetup.exe![]() | %Temp%\_ir_sf_temp_0\irsetup.exe![]() | 1,576,960 bytes |
| MicroProCon.exe | %AppData%\MicroLab\MyEngin\Common\MicroProCon.exe | 98,304 bytes |
| guardconvert.exe | %AppData%\guardsupport\guardconvert.exe | 172,032 bytes |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Republic of Korea |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.