| Visit ThreatExpert web site | | | Close Report |
[Microsoft]| What's been found | Severity Level |
| Creates a startup registry entry. | ![]() |
| Registers a 32-bit in-process server DLL. | ![]() |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %CommonDesktopDir%\PC Scout Support.lnk | 1,357 bytes | MD5: 0xD7F2DF02EDDE4308CC58A07AD6330C2C SHA-1: 0x3239FD1ECF049E3ED3A055E2B96CA7E2C721B07F |
(not available) |
| 2 | %CommonDesktopDir%\PC Scout.lnk | 465 bytes | MD5: 0x9ED543DB9417D06E23FD5744AEBD96DE SHA-1: 0xC6B0AFF2423F06B12CF87AB1B4AD9A4BA2D86A66 |
(not available) |
| 3 | %CommonPrograms%\PC Scout\PC Scout Support.lnk | 1,369 bytes | MD5: 0xE932D395F40223C89C725861693911AE SHA-1: 0x4ED0DA0622FFE2CEB21D3A5FB061E072D4F86A5F |
(not available) |
| 4 | %CommonPrograms%\PC Scout\PC Scout.lnk | 477 bytes | MD5: 0x0C650334C92B84C236E71D9EFE8E41D0 SHA-1: 0x1C187E9155046C8E1E2D27AA415C7866FA067E8A |
(not available) |
| 5 | %CommonPrograms%\PC Scout\Uninstall PC Scout.lnk | 665 bytes | MD5: 0x59990BC7029279AF1BCC3824FAA14018 SHA-1: 0xF9EA9C9262E149F3BB4580E27ACD90F53FC6752F |
(not available) |
| 6 | %Temp%\4otjesjty.mof | 441 bytes | MD5: 0x7D69833C6AE32DC75A52F439A3CDB426 SHA-1: 0x6DADBF0EF1EF3BC1A030F8F8BE4BBB5DE4E09AFA |
(not available) |
| 7 | %ProgramFiles%\PC Scout\core.cga | 3,639,120 bytes | MD5: 0xA0F3FB4A3865FA4A4DA33D5B500B8F0E SHA-1: 0x8251A652FC980A2DEF623103CD2BDC53362F6E2A |
(not available) |
| 8 | %ProgramFiles%\PC Scout\CoreExt.dll | 67,072 bytes | MD5: 0x9679855394575FF25EEC526EBBDE6DCF SHA-1: 0xD7CC674F20EAAD8E01EDB5860FBE1B57C33ABAD4 |
Mal/Generic-A [Sophos]Trojan:Win32/FakeCog [Microsoft]Trojan.Win32.FakeCog [Ikarus] |
| 9 | %ProgramFiles%\PC Scout\help.ico | 99,678 bytes | MD5: 0xB66299EB626E4F57A3316CF3A6C1E05B SHA-1: 0xD859F85F56C7B6DB2A53C6508C8BAEE5A271621B |
(not available) |
| 10 |
%ProgramFiles%\PC Scout\pcscout.exe
[file and pathname of the sample #1] |
5,808,128 bytes | MD5: 0xE3581D5902242E5368E25A43E167B680 SHA-1: 0x37A0BA31025BF2C5E5F3DDD1F408FE941FB94F95 |
Trojan:Win32/Tibs.IT [Microsoft] |
| 11 |
%ProgramFiles%\PC Scout\Uninstall.exe
|
53,248 bytes | MD5: 0x492F2DC8316A79903D80CEAF0F1F8847 SHA-1: 0x5FC39932424AFBDA3D30DA2EBBB7486CCB7D112E |
RogueAntiSpyware.CoreGuardAntivirus2009 [PCTools] CoreGuardAntivirus2009 [Symantec]Packed.Win32.TDSS.y [Kaspersky Lab]Mal/TDSSPack-A [Sophos]Trojan:Win32/FakeCog [Microsoft] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| pcscout.exe | %ProgramFiles%\PC Scout\pcscout.exe | 5,836,800 bytes |
| Service Name | Display Name | New Status | Service Filename |
| wscsvc | Security Center | "Stopped" | %System%\svchost.exe -k netsvcs |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Russian Federation |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2009 ThreatExpert. All rights reserved.