| Visit ThreatExpert web site | | | Close Report |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash |
| 1 |
%AppData%\11350.png
%AppData%\13468.png %AppData%\13910.png %AppData%\2193.png %AppData%\27182.png %AppData%\27283.png %AppData%\308.png %AppData%\5287.png |
167,425 bytes | MD5: 0x6BB18CDE663C34507DA422A5FC61CDA0 SHA-1: 0x0503F01FA79BEC12DA36A696B70D61F780FB164A |
| 2 | %AppData%\40916.png | 176,881 bytes | MD5: 0x7887AD5E54DC1DB156CD4B180BDBC8D2 SHA-1: 0xD58345A638AC8C3FC853966F05911616A070DA5C |
| 3 |
%AppData%\Belove Pet.exe
%Temp%\Beloved Pet.exe |
87,366 bytes | MD5: 0x0C734F265264B26642EDD62B95EF70EF SHA-1: 0x5B3546AF7F139EC933E292B9533748C5FD47AA41 |
| 4 |
%AppData%\FacbookUpdate.exe
[file and pathname of the sample #1] |
2,269,230 bytes | MD5: 0xB489A71595BD0ACAC6A51F7BF5B54C9E SHA-1: 0x8CE342779787AAD34E4D1D86B3F1EE1BA1AE4148 |
| 5 |
%AppData%\iexplorer.exe
%Temp%\Pets.exe |
97,910 bytes | MD5: 0x4514B6A94847612363D672124EDDC583 SHA-1: 0xF0A058B76FFD77D7D341DA550911B0661E3A8ECF |
| 6 |
%Temp%\AppLaunch\Service.exe
|
1,140,920 bytes | MD5: 0x2C1E2BC0384BA3C12534E92223CB039F SHA-1: 0x258CBE81CB972334A28E0939B512233AB3A284E6 |
| 7 |
%Temp%\%ComputerName% - 8-28-2012-8.46.04-AM.gif
%Temp%\%ComputerName% - 8-28-2012-8.48.03-AM.gif %Temp%\%ComputerName% - 8-28-2012-8.50.03-AM.gif |
33,226 bytes | MD5: 0x2850276F35368B13FC2633B6B93D3D36 SHA-1: 0xC992C44AA1013B15CEA3AF8B4E4C387626A7B408 |
| 8 | %Temp%\Missing 2.png | 99,374 bytes | MD5: 0xFAE081666C5BC1A2A8AB875A4F80DB39 SHA-1: 0x29AE825DB20CBBEA9A890FBE290DB33ECD0048E3 |
| 9 | %Temp%\missing 4.jpg | 11,281 bytes | MD5: 0x340AE5C2664180D5A1981308B16D4EB3 SHA-1: 0xEA2448F70B9C56D65B2A3780790C54859181DDEE |
| 10 |
%Temp%\svhosts.exe
|
443,838 bytes | MD5: 0x235447E63F3C76E01D0A7D09798D529D SHA-1: 0xE5C81A106986632635613CE2700553C5F4C0D107 |
| 11 | %Temp%\tmp.ini | 5 bytes | MD5: 0xD1EA279FB5559C020A1B4137DC4DE237 SHA-1: 0xDB6F8988AF46B56216A6F0DAF95AB8C9BDB57400 |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
Service.exe![]() | %Temp%\AppLaunch\Service.exe![]() | 1,396,736 bytes |
| [generic host process] | [generic host process filename] | 45,056 bytes |
![]() | Registry Modifications |
![]() | Other details |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.