Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Creates a startup registry entry.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %AppData%\lizkavd.exe 159,856 bytes MD5: 0x7A12938530B38C7D66A92699239C9AA2
SHA-1: 0xFE3CD7105C1206662ECAE7A05B852607C5219E77
Packed.Win32.Krap.ah [Kaspersky Lab]
2 %AppData%\seres.exe
%AppData%\svcst.exe
[file and pathname of the sample #1]
21,504 bytes MD5: 0x7D96CE7F588613F0343049918DE70665
SHA-1: 0xC00A96C4237F2B3FAE05BDE121BF5FEDBAE258FE
Trojan.Win32.Vilsel.iop [Kaspersky Lab]
Mal/EncPk-KP [Sophos]
3 %Temp%\tmpwr2 564,724 bytes MD5: 0x3DA03789438F33DA1AE705D7EAD6014C
SHA-1: 0x28ACA6B30B92B2F5C3F6EB7192A843AFA0C5240D
(not available)
4 %Temp%\tmpwr3 265,220 bytes MD5: 0xBB7EFC8B6C5DEE2A0FB7513042FE9B32
SHA-1: 0x773CB0DFE5D1D4689DF0DA84278ECFC8010B8AEB
(not available)
5 %Temp%\tmpwr4 452,100 bytes MD5: 0x62CCA99D2DC23F29A2CEAE780B4C92D0
SHA-1: 0x50F9F82ECE8A0360CAFC570E4A8006D5D77F2E3B
(not available)
6 %Temp%\tmpwr5 732,212 bytes MD5: 0x4E0417676D7B372FF314A83F4265C157
SHA-1: 0x79A01D1297D6104C0ECD087866BCBBDA9A2F6957
(not available)
7 %Temp%\tmpwr6 151,428 bytes MD5: 0xB84B89F326E20110AF6A486BEA85B13D
SHA-1: 0x2AB5970963A234C30A786F985DDC8F02C36D15CC
(not available)
8 %Temp%\tmpwr7 1,088,644 bytes MD5: 0x6C73AB4C610611887E42707902F1319D
SHA-1: 0x97DDA778E066B1A0D9D5E07EF2472E8D5C464F05
(not available)

 

Memory Modifications

Process NameProcess FilenameMain Module Size
seres.exe%AppData%\seres.exe45,056 bytes
svcst.exe%AppData%\svcst.exe45,056 bytes

 

Registry Modifications

 

Other details

PortProtocolProcess
1049UDPsvcst.exe (%AppData%\svcst.exe)

Remote HostPort Number
64.237.55.3980

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.