Submission Summary:

What's been foundSeverity Level
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\certsystem.exe 47,872 bytes MD5: 0x8738BAB505367E09789E91A02337986B
SHA-1: 0x66E8432E8ABC68480EAE65A6A64BEA6A1476C267
Trojan.Win32.FakeAV [Ikarus]
2 %Temp%\microsoftdef.dll 18,941 bytes MD5: 0xA8D2DDE23081E085216413450CE9ECEA
SHA-1: 0x7B197E51CD59BB130FDD701516CE3890FB4AB9C8
Trojan.Win32.FakeAV [Ikarus]
3 %Temp%\regred.exe 38,352 bytes MD5: 0x405E6E5C06C3E0BE8BE6AAAB679521EF
SHA-1: 0xE0E2073DB72F5D383594F17875E9277E09DEB1EA
Trojan.Win32.FakeAV [Ikarus]
4 %Temp%\spoov.exe 51,197 bytes MD5: 0xEBB8481B89265CB919F382583FD42992
SHA-1: 0xF68E99AFDC465A400D33B9CD173960196D3CE3DF
Trojan.Win32.FakeAV [Ikarus]
5 %Temp%\sysnet.dll 1,959,936 bytes MD5: 0xB2ACDE07B7A5B7EF54EA3962D3794467
SHA-1: 0x1113DB76FF67FF1102E708C1D99BD266F36E4E3A
Trojan.Vundo [Symantec]
Packed.Win32.TDSS.aa [Kaspersky Lab]
FakeAlert-JU [McAfee]
Mal/FakeAV-BP [Sophos]
Trojan:Win32/FakeSpyguard [Microsoft]
6 %Temp%\usexplorer.exe 33,149 bytes MD5: 0xC9A582438D3851A6572CFA75A567E7C8
SHA-1: 0x551904C8B909D5339A7D0F6A4F53B3431B3191C4
Trojan.Win32.FakeAV [Ikarus]
7 %Temp%\yozezuna.dll 38,912 bytes MD5: 0x79EF6F21A3677D4B84F71FCE2BDB2751
SHA-1: 0x5487506BCACE413085993EFD3DE5A04F0A5A94F5
Vundo.gen.ab [McAfee]
Mal/Generic-A [Sophos]
Trojan:Win32/Vundo.FA [Microsoft]
8 [file and pathname of the sample #1] 2,086,110 bytes MD5: 0xA541EB00687C021371F76A83EFEE3247
SHA-1: 0x43CD61C91AAC728EE22534FC1580CFDACCF9E3EC
Packed.Win32.TDSS.aa [Kaspersky Lab]
Trojan.Win32.FakeAV [Ikarus]

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.