| Visit ThreatExpert web site | | | Close Report |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash |
| 1 |
%Temp%\947ae222a2c5196ffa87607faa37aee4\DirectDownloaderInstaller.exe
%Temp%\947ae222a2c5196ffa87607faa37aee4\OpenCL.dll %Temp%\947ae222a2c5196ffa87607faa37aee4\optimizer.exe
%Temp%\947ae222a2c5196ffa87607faa37aee4\smf %Temp%\947ae222a2c5196ffa87607faa37aee4\stub.exe
%Temp%\947ae222a2c5196ffa87607faa37aee4\updater.exe
|
125 bytes | MD5: 0x7C5F5A68051F6B0C0E9A2AD33C40D415 SHA-1: 0x120865765927A61AF83F02B83DC297EEDE61EC41 |
| 2 |
%Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderDDLR.exe
%Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderOFFER0.exe %Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderOFFER1.exe %Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderOFFER2.exe %Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderSTUB.exe |
59,640 bytes | MD5: 0xC7F6ED56312C8FBB58AE6ED445C38DF4 SHA-1: 0xE2DBA94EF052DB774478B9F7198C1A2298B334E5 |
| 3 |
%Temp%\947ae222a2c5196ffa87607faa37aee4\preinstaller.exe
|
218,624 bytes | MD5: 0x06BAEF00AE0F0E42FC5FEA24FC4EAC42 SHA-1: 0x9161574590F09CFE4C24498827386ED57F2E8C58 |
| 4 |
%Temp%\nsk1A.tmp\NSISdl.dll
%Temp%\nsp1E.tmp\NSISdl.dll
%Temp%\nsv20.tmp\NSISdl.dll
|
14,848 bytes | MD5: 0xA5F8399A743AB7F9C88C645C35B1EBB5 SHA-1: 0x168F3C158913B0367BF79FA413357FBE97018191 |
| 5 | [file and pathname of the sample #1] | 504,232 bytes | MD5: 0x6D2EE6D1184A62EADE797ADF2F729618 SHA-1: 0x623AE4046269078383982FA9F59656A1EA71C591 |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| ns12.tmp | %Temp%\nsb11.tmp\ns12.tmp | 32,768 bytes |
| downloaderOFFER0.exe | %Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderOFFER0.exe | 196,608 bytes |
| [filename of the sample #1] | [file and pathname of the sample #1] | 278,528 bytes |
| downloaderSTUB.exe | %Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderSTUB.exe | 196,608 bytes |
| downloaderDDLR.exe | %Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderDDLR.exe | 196,608 bytes |
| ns14.tmp | %Temp%\nsb11.tmp\ns14.tmp | 32,768 bytes |
| Process Name | Process Filename | Allocated Size |
| downloaderDDLR.exe | %Temp%\947ae222a2c5196ffa87607faa37aee4\downloaderddlr.exe | 8,392,704 bytes |
![]() | Other details |
[Ikarus]
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %CommonPrograms%\Optimizer Pro\Help.lnk | 687 bytes | MD5: 0x3D59ED9E6546689D9EBFFC0E19640384 SHA-1: 0xBCD6FB36F9BC8A976BA1B4C127B238EB3005A423 |
(not available) |
| 2 | %CommonPrograms%\Optimizer Pro\Optimizer Pro on the Web.lnk | 667 bytes | MD5: 0xD82B6CC593FC6481431295F6B4429034 SHA-1: 0x8E143E0F2414FD463CE47E77A67C45F6A95AF657 |
(not available) |
| 3 | %CommonPrograms%\Optimizer Pro\Optimizer Pro.lnk | 749 bytes | MD5: 0x24047A857A3C41E81E700629ECA35FCD SHA-1: 0x7DEF0CE13B30654F064E04FD9EC60D40DACD7195 |
(not available) |
| 4 | %CommonPrograms%\Optimizer Pro\Uninstall Optimizer Pro.lnk | 667 bytes | MD5: 0xF6239D50C5F481FD3F48963C4D97F35B SHA-1: 0x5D276CCD5AFD8C8D0C9B16FA20EAC8853982E70E |
(not available) |
| 5 | %DesktopDir%\Direct Downloader.lnk | 1,174 bytes | MD5: 0xC1685E7E88F0AF9F270BE7AB7D6730D5 SHA-1: 0x60F8F99DE6E3DF57593E30A2E15BE7CDD85A1B4F |
(not available) |
| 6 | %DesktopDir%\Optimizer Pro.lnk | 737 bytes | MD5: 0x14055E61D988323579FD26D3A8F9DCBF SHA-1: 0xF14273A994DED6CA143E10DB84381147AAB6DD7A |
(not available) |
| 7 | %AppData%\DirectDownloader\DirectDownloader.exe | 4,982,304 bytes | MD5: 0x57397D066AA71FC883F3E5911761F190 SHA-1: 0x2011254CCA31B46699F710A14BA94FAA609D2C14 |
(not available) |
| 8 | %AppData%\DirectDownloader\icon.ico | 34,494 bytes | MD5: 0x0D3E03DDDAC2D8E99483CD277408C4C8 SHA-1: 0x6C4FC59261456CF3FDEFBE4CC451334301F12C30 |
(not available) |
| 9 | %AppData%\DirectDownloader\settings.ini | 97 bytes | MD5: 0xF39A59672940E83F7C4F867FC52DCE64 SHA-1: 0xD59D2473AE6854CAC85029FA3ECBB85004E0AA2A |
(not available) |
| 10 |
%AppData%\DirectDownloader\Uninstall.exe
|
89,242 bytes | MD5: 0xB309122E4256317FBB1B36A747AD20BD SHA-1: 0xC05B65D689544B9F647FCF9DBAF8721AFF2E5919 |
(not available) |
| 11 | %AppData%\DirectDownloader\updateRunner.exe | 14,880 bytes | MD5: 0xD9AB17E87E67EAD82ADC0A74F0FC4DD6 SHA-1: 0xE054CA81E2A01639D64F325FC61138A4EB4D2A7D |
(not available) |
| 12 | %Programs%\DirectDownloader\DirectDownloader.lnk | 1,186 bytes | MD5: 0xF59C26DF9C317A40B7A046DEAAEDF255 SHA-1: 0x064248A5DA8A8EB3859FC15569110387D3F6A4FD |
(not available) |
| 13 | %Programs%\DirectDownloader\Launch Website.url | 174 bytes | MD5: 0xA5AC721C5EFDD7A75D166E00CBAD358E SHA-1: 0xB33D8D94AD7CB41B8B2222E1A797BA1831A5DD3A |
(not available) |
| 14 | %Programs%\DirectDownloader\Online Help.url | 179 bytes | MD5: 0xEF8A0E24AA36982072B80F73202F8F63 SHA-1: 0x9C240CFDA2EDCB2A2D6770721C767762FE8A84EB |
(not available) |
| 15 | %Programs%\DirectDownloader\Uninstall Program.lnk | 947 bytes | MD5: 0xF6A62E04A5059DBADA6407E34A45CD07 SHA-1: 0x2CAFDE306149B12FE42CA226B14137B49DB7FF6A |
(not available) |
| 16 | %Programs%\Startup\Direct Downloader.lnk | 1,202 bytes | MD5: 0x978391B978546441E66F31DB96A0140F SHA-1: 0xD5D535CC84B759542711063A78A2FE77944B4749 |
(not available) |
| 17 | %ProgramFiles%\Optimizer Pro\English.ini | 17,086 bytes | MD5: 0x414295A5CEEEE799B02F4D94DEA93943 SHA-1: 0x0E3F798F02C75B43984CEE88ADD712FD8C6CD925 |
(not available) |
| 18 | %ProgramFiles%\Optimizer Pro\file_id.diz | 861 bytes | MD5: 0x34D6FD255C48B63584D8CC5C862225D7 SHA-1: 0x494970E16DFE601A96F89239F335FB6D48F57370 |
(not available) |
| 19 | %ProgramFiles%\Optimizer Pro\HomePage.url | 54 bytes | MD5: 0x8B4796E82170E61D2FB8F1B9230D80BF SHA-1: 0xEE7B922DA00665F5A2EE646BA3A07156C01CC994 |
(not available) |
| 20 | %ProgramFiles%\Optimizer Pro\OptimizerPro.chm | 43,152 bytes | MD5: 0xAEAC7C2FA04F2D766D0BC9E65B3CCBCB SHA-1: 0x33B8ACEC7E4E209F965027637B132BF65FAA5055 |
(not available) |
| 21 | %ProgramFiles%\Optimizer Pro\OptimizerPro.exe | 0 bytes | MD5: 0xD41D8CD98F00B204E9800998ECF8427E SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709 |
(not available) |
| 22 | %ProgramFiles%\Optimizer Pro\OptProGuard.exe | 232,240 bytes | MD5: 0x94AEBE8F4BEB1157E557EDA1168A4FC8 SHA-1: 0x0279B6FA6AEFC65D28A9EEDF0A9352EFA74F1FE2 |
packed with UPX [Kaspersky Lab] |
| 23 | %ProgramFiles%\Optimizer Pro\OptProLauncher.exe | 79,664 bytes | MD5: 0x4639ADA987378DAC8FBA283E8FB05C37 SHA-1: 0xE38DA44318FB264A7FC8DE54EC90E558E611162C |
packed with UPX [Kaspersky Lab] |
| 24 | %ProgramFiles%\Optimizer Pro\OptProReminder.exe | 215,856 bytes | MD5: 0xDB768AD94C887062242507ACB2C32F25 SHA-1: 0x1034CCDCE2E727FCA4F2A968773C2488134A3FAA |
packed with UPX [Kaspersky Lab] |
| 25 | %ProgramFiles%\Optimizer Pro\OptProSchedule.exe | 194,864 bytes | MD5: 0x614C59E27B320ACD0C463FA4154183B7 SHA-1: 0xE916C1515A78A5C295B8675DCAB542DC08D28959 |
packed with UPX [Kaspersky Lab] |
| 26 | %ProgramFiles%\Optimizer Pro\OptProSmartScan.exe | 197,112 bytes | MD5: 0x2091DF889684304F68616CAE08B2FBCC SHA-1: 0xB7543EF0B5D581B3ACB42F880E81DA30E36C5A2F |
packed with UPX [Kaspersky Lab] |
| 27 | %ProgramFiles%\Optimizer Pro\OptProStart.exe | 207,664 bytes | MD5: 0x98574CB00E32B3A95BD706F4F0757FDE SHA-1: 0x3B4BE02F28AADB075FDD3EC45BB423610F4D6462 |
packed with UPX [Kaspersky Lab] |
| 28 | %ProgramFiles%\Optimizer Pro\OptProUninstaller.exe | 43,824 bytes | MD5: 0x660724D27FF01B1BDCB01A3307B433C0 SHA-1: 0x6D2E18196FC258A949A4F7C2AFC1225E5AB61EC7 |
packed with UPX [Kaspersky Lab] |
| 29 | %ProgramFiles%\Optimizer Pro\scan.gif | 56,626 bytes | MD5: 0x6858A1CE31E5F92785FB525CE9725B8A SHA-1: 0x6F666E761CB39EC0EFA78038038706C6E09641CA |
(not available) |
| 30 |
%ProgramFiles%\Optimizer Pro\sqlite3.dll
|
520,234 bytes | MD5: 0x0F66E8E2340569FB17E774DAC2010E31 SHA-1: 0x406BB6854E7384FF77C0B847BF2F24F3315874A3 |
(not available) |
| 31 | %ProgramFiles%\Optimizer Pro\unins000.dat | 4,210 bytes | MD5: 0xA973FD67EDDF55EE2A439358410B0F4F SHA-1: 0x68F0D0B2FA482F63BE0A76AEBA5455D927C06B84 |
(not available) |
| 32 |
%ProgramFiles%\Optimizer Pro\unins000.exe
|
707,361 bytes | MD5: 0x8292CF66F2543C84C6D42112F6B7F2C7 SHA-1: 0xCAD6AA02069480B621FB829DC36D44F2C4BA8E98 |
(not available) |
| 33 | [file and pathname of the sample #1] | 68,096 bytes | MD5: 0x099191BC3D3109FEB7BEC3155AEB5DA8 SHA-1: 0x81E6285B64D7D6807535D78EAEF62047C9C6A13A |
(not available) |
| 34 | [file and pathname of the sample #2] | 299,008 bytes | MD5: 0x34FD9CD85455F81559AB644161020AB6 SHA-1: 0x10F5EAE78FCB4904748FE87839A6801AC55A3A45 |
(not available) |
| 35 | [file and pathname of the sample #3] | 34,624 bytes | MD5: 0x46224113728EFAE885EDA63FC15970F6 SHA-1: 0x498036A681B2D2B1E1B41019F677ED9774223CFA |
(not available) |
| 36 | [file and pathname of the sample #4] | 2,683,184 bytes | MD5: 0xFC3C83FC81D62029659D03B8837896C1 SHA-1: 0x5BCB69A1275BCBE48C85FAAF7D22A4DE3E7E2C4E |
Trojan.Win32.Agent [Ikarus] |
| 37 | [file and pathname of the sample #5] | 4,997,344 bytes | MD5: 0xF4B56EDB6A3A0FB4DFCA673A43CDE123 SHA-1: 0x449C6657118FAC69F13399F8AAEDE54EBB719C87 |
(not available) |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [generic host process] | [generic host process filename] | 20,480 bytes |
| updaterunner.exe | %AppData%\directdownloader\updaterunner.exe | 36,864 bytes |
| [filename of the sample #5] | [file and pathname of the sample #5] | 262,144 bytes |
| [filename of the sample #4] | [file and pathname of the sample #4] | 2,703,360 bytes |
| optprolauncher.exe | %ProgramFiles%\optimizer pro\optprolauncher.exe | 192,512 bytes |
RegistryOptimizer.exe![]() | %Windir%\Temp\RegistryOptimizer.exe![]() | 81,920 bytes |
| RegistryOptimizer.tmp | %Temp%\is-1IH1L.tmp\RegistryOptimizer.tmp | 761,856 bytes |
| Module Name | Module Filename | Address Space Details |
| [filename of the sample #3] | [file and pathname of the sample #3] | Process name: [generic host process] Process filename: [generic host process filename] Address space: 0x3E0000 - 0x3F4000 |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Russian Federation |
| Server Name | Server Port | Connect as User | Connection Password |
| www.directdownloader.com | 80 | (null) | (null) |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.