Submission Summary:

What's been foundSeverity Level
Creates a startup registry entry.
Registers a 32-bit in-process server DLL.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %CommonDesktopDir%\PC Scout Support.lnk 1,357 bytes MD5: 0xD7F2DF02EDDE4308CC58A07AD6330C2C
SHA-1: 0x3239FD1ECF049E3ED3A055E2B96CA7E2C721B07F
(not available)
2 %CommonDesktopDir%\PC Scout.lnk 465 bytes MD5: 0x9ED543DB9417D06E23FD5744AEBD96DE
SHA-1: 0xC6B0AFF2423F06B12CF87AB1B4AD9A4BA2D86A66
(not available)
3 %CommonPrograms%\PC Scout\PC Scout Support.lnk 1,369 bytes MD5: 0xE932D395F40223C89C725861693911AE
SHA-1: 0x4ED0DA0622FFE2CEB21D3A5FB061E072D4F86A5F
(not available)
4 %CommonPrograms%\PC Scout\PC Scout.lnk 477 bytes MD5: 0x0C650334C92B84C236E71D9EFE8E41D0
SHA-1: 0x1C187E9155046C8E1E2D27AA415C7866FA067E8A
(not available)
5 %CommonPrograms%\PC Scout\Uninstall PC Scout.lnk 665 bytes MD5: 0x59990BC7029279AF1BCC3824FAA14018
SHA-1: 0xF9EA9C9262E149F3BB4580E27ACD90F53FC6752F
(not available)
6 %Temp%\4otjesjty.mof 441 bytes MD5: 0x7D69833C6AE32DC75A52F439A3CDB426
SHA-1: 0x6DADBF0EF1EF3BC1A030F8F8BE4BBB5DE4E09AFA
(not available)
7 %ProgramFiles%\PC Scout\core.cga 3,639,120 bytes MD5: 0xA0F3FB4A3865FA4A4DA33D5B500B8F0E
SHA-1: 0x8251A652FC980A2DEF623103CD2BDC53362F6E2A
(not available)
8 %ProgramFiles%\PC Scout\CoreExt.dll 67,072 bytes MD5: 0x9679855394575FF25EEC526EBBDE6DCF
SHA-1: 0xD7CC674F20EAAD8E01EDB5860FBE1B57C33ABAD4
Mal/Generic-A [Sophos]
Trojan:Win32/FakeCog [Microsoft]
Trojan.Win32.FakeCog [Ikarus]
9 %ProgramFiles%\PC Scout\help.ico 99,678 bytes MD5: 0xB66299EB626E4F57A3316CF3A6C1E05B
SHA-1: 0xD859F85F56C7B6DB2A53C6508C8BAEE5A271621B
(not available)
10 %ProgramFiles%\PC Scout\pcscout.exe
[file and pathname of the sample #1]
5,808,128 bytes MD5: 0xE3581D5902242E5368E25A43E167B680
SHA-1: 0x37A0BA31025BF2C5E5F3DDD1F408FE941FB94F95
Trojan:Win32/Tibs.IT [Microsoft]
11 %ProgramFiles%\PC Scout\Uninstall.exe 53,248 bytes MD5: 0x492F2DC8316A79903D80CEAF0F1F8847
SHA-1: 0x5FC39932424AFBDA3D30DA2EBBB7486CCB7D112E
RogueAntiSpyware.CoreGuardAntivirus2009 [PCTools]
CoreGuardAntivirus2009 [Symantec]
Packed.Win32.TDSS.y [Kaspersky Lab]
Mal/TDSSPack-A [Sophos]
Trojan:Win32/FakeCog [Microsoft]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
pcscout.exe%ProgramFiles%\PC Scout\pcscout.exe5,836,800 bytes

Service NameDisplay NameNew StatusService Filename
wscsvcSecurity Center"Stopped"%System%\svchost.exe -k netsvcs

 

Registry Modifications

 

Other details

Russian Federation

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.