Submission Summary:

What's been foundSeverity Level
Registers a 32-bit in-process server DLL.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile Hash
1 %Temp%\2.0\AlKir BF2 Ban Checker.exe 518,797 bytes MD5: 0xDB2C1E1AFE5EDBEFEF65CEE998CC7FC7
SHA-1: 0xFF4506F036A298718E484CB636B7865A38AF983E
2 %Temp%\2.0\Fix Runtime Error.bat 446 bytes MD5: 0xADC8A6BB772387AC6880875BA3DA10C2
SHA-1: 0xDFD5DDEA7CFBB09B69CD8DFB50949D1D27BAF0B9
3 %Temp%\2.0\runtime\comdlg32.ocx 152,848 bytes MD5: 0xAB412429F1E5FB9708A8CDEA07479099
SHA-1: 0xEB49323BE4384A0E7E36053F186B305636E82887
4 %Temp%\2.0\runtime\glxpbuttonz.oca 24,576 bytes MD5: 0x11FCA46CDB9651EF92C7A56A9D5A3671
SHA-1: 0xB22C5858604722EA17F29B89E850FD915813A7EB
5 %Temp%\2.0\runtime\glxpbuttonz.ocx 110,592 bytes MD5: 0x455812A36B41A4CE537589EBD1410111
SHA-1: 0x6A7872729D72F4FE8BC979846237D25436DEEC11
6 %Temp%\2.0\runtime\HexUniControls28.oca 667,648 bytes MD5: 0x105072010248D0FBF84D0C7D9093D8FE
SHA-1: 0x74C8EC0F92177D4D5C3A4956FD725DB91C03F270
7 %Temp%\2.0\runtime\HexUniControls28.ocx 1,482,752 bytes MD5: 0xF6332293F4DFC4DC18B1D45DA1E7B61B
SHA-1: 0xA727DD3487344D03D1A590524614D7569411CEE2
8 %Temp%\2.0\runtime\MSCOMCTL.OCX 1,081,616 bytes MD5: 0xECC7D7F0D3446DE36045D1D9E964FAFE
SHA-1: 0xDA6B0EC081D628C33B150327F3BD16D3B7FA4729
9 [file and pathname of the sample #1] 1,640,160 bytes MD5: 0xB42307E9608A7D8B62705CF0F1EC8F5A
SHA-1: 0xDCFBA62D9A1C993F3EC7E8A5BF4AFF7467761170

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[generic host process][generic host process filename]45,056 bytes

Module NameModule FilenameAddress Space Details
comdlg32.ocx%Temp%\2.0\runtime\comdlg32.ocxProcess name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x217A0000 - 0x217C3000
glxpbuttonz.ocx%Temp%\2.0\runtime\glxpbuttonz.ocxProcess name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x11000000 - 0x1101B000
HexUniControls28.ocx%Temp%\2.0\runtime\HexUniControls28.ocxProcess name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x11000000 - 0x11183000
MSCOMCTL.OCX%Temp%\2.0\runtime\MSCOMCTL.OCXProcess name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x27580000 - 0x27686000

 

Registry Modifications

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.