Submission Summary:

What's been foundSeverity Level
Registers a 32-bit in-process server DLL.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\61.tmp 68,096 bytes MD5: 0x8A46E66131D7B0F36833C7185FC1E692
SHA-1: 0x9F193699B2D8BB780B55473659872D0B7E4B1087
Trojan-Dropper.Win32.Wansrog [Ikarus]
packed with PE_Patch.UPX [Kaspersky Lab]
2 %System%\jrtivweq.dat 236,552 bytes MD5: 0xEE9B1FEFB2FBE701ADA29AB0411C9C3C
SHA-1: 0x6A1B0B7EF0E6FE6B62C4029480453F8338AF60F8
Trojan.Win32.Wansrog [Ikarus]
3 %System%\lauvkmdic.dll 983,552 bytes MD5: 0x888190E31455FAD793312F8D087146EB
SHA-1: 0x775191D293016D9541DDD6AEF5AC94AB3776849A
(not available)
4 %System%\zoijyarwq.dll 616,960 bytes MD5: 0x1AFF244CA134956C54474F4E2433E4CE
SHA-1: 0xBADA2E56BF23113BD7FA62FE2F159B514B66F02B
(not available)

 

Registry Modifications

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.