Submission Summary:

What's been foundSeverity Level
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Rootkit.Protector Rootkit.Protector is a threat that relies on rootkit-specific techniques in order to hide its presence in the system.

Threat CategoryDescription
A code with the rootkit-specific techniques designed to hide the software presence in the system
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\WERf757.dir00\appcompat.txt 16,296 bytes MD5: 0xF560A82E9385739415E085B4553CBA8F
SHA-1: 0x958B55E9517896C07D689F6BDDED4EF10D0718A9
(not available)
2 %Temp%\WERf757.dir00\manifest.txt 1,742 bytes MD5: 0x8B26D008FC95624621BD4BD20A2A6BC8
SHA-1: 0xFE3777DB272CE078D9354100553856397B93750B
(not available)
3 %Temp%\WERf757.dir00\services.exe.hdmp 6,273,748 bytes MD5: 0x40FB5C50729EB4F5A08D7DEF88B26BBB
SHA-1: 0xEBD0683F507C35832B1649B3C22CA9941DF2F6A1
(not available)
4 %Temp%\WERf757.dir00\services.exe.mdmp 59,713 bytes MD5: 0xC2A5EA5444FAF293938D888AA47D2118
SHA-1: 0x48FAB490A24F068B8E77957C22D41DC1A623502E
(not available)
5 %System%\drivers\ati7tfxx.sys 32,768 bytes MD5: 0x193A94DF3AF2E31D784040A76D5FCE5A
SHA-1: 0x2CD6DBC8681E01028B01788731A28A1A45F9F687
Rootkit.Protector [PCTools]
Trojan.Pandex [Symantec]
Rootkit.Win32.Protector.bd [Kaspersky Lab]
Cutwail.gen.a [McAfee]
TROJ_PANDEX.ROY [Trend Micro]
Troj/Pushu-Gen [Sophos]
VirTool:WinNT/Cutwail.K [Microsoft]
VirTool.WinNT.Cutwail.K [Ikarus]
6 [file and pathname of the sample #1] 40,960 bytes MD5: 0x98955DA3CE4BE1CAD36C2BEA9DDAE701
SHA-1: 0xB916C157EF6424E43012D367C1F1A72C9265BAF7
Mal/Pushdo-A [Sophos]
TrojanDropper:Win32/Cutwail.AL [Microsoft]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]53,248 bytes

Driver NameDriver Filename
ati7tfxx.sys%System%\drivers\ati7tfxx.sys

 

Registry Modifications

 

Other details

Remote HostPort Number
216.195.56.2280

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.