Submission Summary:

What's been foundSeverity Level
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Trojan.TDSServ Trojan.TDSServ is a trojan horse that may represent security risk for the compromised system and/or its network environment. The program uses rootkit-specific techniques designed to hide the software presence in the system. This trojan also blocks user access to security website such as pctools.com.
Backdoor.Tidserv!sd6 Backdoor.Tidserv!sd6 is a malicious application that runs in the background and allows remote access to your system, giving the attacker full control of your system.

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\Mediacodec.exe 38,912 bytes MD5: 0x72EDE7E934E0777120EC95FA229F0A2A
SHA-1: 0x560C3BB2EB9A2A52C1955D3CCF70EDF06670F998
Packed.Win32.Tdss.w [Kaspersky Lab]
Trojan:Win32/Alureon.gen!J [Microsoft]
2 %Temp%\tmp4.tmp 26,624 bytes MD5: 0x54E93C5BDB57B1C1BC4907813175AB83
SHA-1: 0xBE001441CC6AAED75A1E7A0453D23BF0E4A40360
Suspicious.Vundo.2 [Symantec]
Packed.Win32.Tdss.w [Kaspersky Lab]
Trojan:Win32/Alureon.BH [Microsoft]
3 %Temp%\tmp5.tmp 343,040 bytes MD5: 0x03B8A99F177D12D9745F4D7A14FCEA79
SHA-1: 0xB8043C5612A6E08ADA04D3C31DDED5DF7B6AB5C6
Backdoor.Tidserv!sd6 [PCTools]
Backdoor.Tidserv [Symantec]
Trojan.Win32.Patched.go [Kaspersky Lab]
DNSChanger!q [McAfee]
W32/Autorun-AFM [Sophos]
Trojan:Win32/Alureon.BP [Microsoft]
Win-Trojan/DNSChanger.343040 [AhnLab]
4 %Programs%\Mediacodec\Uninstall.lnk 713 bytes MD5: 0xA3AF0243A4F44CE5ACA89DF426B87E34
SHA-1: 0x8E950F664BD8E75A9C33424F0B82262E9DCCB598
(not available)
5 %ProgramFiles%\Mediacodec\Uninstall.exe 62,821 bytes MD5: 0x969093CB0B368BD4452C66D58C1C1D59
SHA-1: 0xA48650AAEB8A23613A9EB5260FCED566D38B4842
Trojan.Win32.Alureon [Ikarus]
6 %Windir%\pchealth\ERRORREP\UserDumps\spoolsv.exe.20090709-075705-00.hdmp 2,497,508 bytes MD5: 0x65CC7C366AA65D9C8B9E4B042486D99A
SHA-1: 0x0C255AC01927565CA902B5683AC2B6EE3FB59B82
(not available)
7 %Windir%\pchealth\ERRORREP\UserDumps\spoolsv.exe.20090709-075705-00.mdmp 51,199 bytes MD5: 0xF1A2602774AE2FF0040EBC7EAEEB9EFB
SHA-1: 0x5C8447EF9CD0CDFA621B084570B129610EAC1713
(not available)
8 [file and pathname of the sample #1] 93,106 bytes MD5: 0x8254D797DC12ADAA7E50F30128199B17
SHA-1: 0xC4271A82C3EB84B40B3BE9BFD282DE0DB0E8D28F
Packed.Win32.Tdss.w [Kaspersky Lab]
Trojan.Win32.Alureon [Ikarus]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
Mediacodec.exe%Temp%\Mediacodec.exe94,208 bytes
[filename of the sample #1][file and pathname of the sample #1]3,883,008 bytes

Service NameDisplay NameNew StatusService Filename
SpoolerPrint Spooler"Stopped"%System%\spoolsv.exe

 

Registry Modifications

 

Other details

Remote HostPort Number
213.163.66.24180

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.