Submission Summary:

What's been foundSeverity Level
Creates a startup registry entry.
Registers a 32-bit in-process server DLL.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile Hash
1 %AppData%\Desktopicon\eBay.ico 26,694 bytes MD5: 0xAF58EF89F016E5E3AC0400C7700D9C8C
SHA-1: 0x837CEF6A95783C44A25B6CBF89FFE59C886DD918
2 %AppData%\Desktopicon\uninst.exe 31,836 bytes MD5: 0x94CAA5D82CA7AFCBCFF00FD6D5ECDCFC
SHA-1: 0x13172806B95883F6A516D0CEC3F129E01A2639C1
3 %DesktopDir%\eBay.lnk 1,280 bytes MD5: 0x8E1DBB76681C12D4EE27B3E39F1990F7
SHA-1: 0x2113420076666DCCEC5AECD5AD4CE58C893397D7
4 %Temp%\nsa3.tmp\eBay_shortcuts_1016_new.exe 38,695 bytes MD5: 0x9837D9E8118D428EF0CA8C5C18629821
SHA-1: 0xBC187E3D392F529CA6448985EAC2FCC127B4FFC6
5 %StartMenu%\eBay.lnk 1,280 bytes MD5: 0x570A70DC7F56B4EC137C457B7274F465
SHA-1: 0xF9D531CBA18244E9B97FB6EDA34235B7579151EF
6 %Programs%\Unlocker\README.lnk 682 bytes MD5: 0x823C0D9E5B27238C35617C26A175F504
SHA-1: 0x0A79DD0A5A2476D0146485CD43F582E085CC54F7
7 %Programs%\Unlocker\Start Unlocker Assistant.lnk 739 bytes MD5: 0xFE373E75129A3BD92B4F1A768B504FA0
SHA-1: 0x870D5770DF791D7FA9EC516019B4E62E1BF760B5
8 %Programs%\Unlocker\Uninstall.lnk 507 bytes MD5: 0x341B99BA3640736E376278F704FDB96D
SHA-1: 0xE3AC9C7B6D7F5C1B340648991E8D8C33A44EBC37
9 %Programs%\Unlocker\Website.lnk 694 bytes MD5: 0xFE5EFBBD8F445AA6B6CC3BF4B73B7888
SHA-1: 0x2F7EB05B76084EC388396D81058E62494C038B3C
10 %ProgramFiles%\Unlocker\README.TXT 1,646 bytes MD5: 0x1E4F56310340D972501B8931B5AB43E3
SHA-1: 0x04336A4EB4A258BB02479AB9DC2E90C330CFF257
11 %ProgramFiles%\Unlocker\uninst.exe 92,253 bytes MD5: 0x0FEBACAE5A04D1866A71C2BEDEC4D771
SHA-1: 0x41E2E974DEA05C6FBFB25BE36B5A414D50B3C92A
12 %ProgramFiles%\Unlocker\Unlocker.exe 87,552 bytes MD5: 0xF90041030EB8EAC265AF30F8F7D6E4AD
SHA-1: 0x6E02A9FBAA28BE4254C84F6506ACF1DD64B94721
13 %ProgramFiles%\Unlocker\Unlocker.url 59 bytes MD5: 0xD8843CE8A17012C12BA8FD35DE88379E
SHA-1: 0xF11FD6407BAE44B19C37C4CE60EF3F094F8711CA
14 %ProgramFiles%\Unlocker\UnlockerAssistant.exe 15,872 bytes MD5: 0x1DB01CEE814A7DF4DCFBA14B4115434A
SHA-1: 0x7B5985045B879D48EAA58FCA829EA4EDB3E8441B
15 %ProgramFiles%\Unlocker\UnlockerCOM.dll 10,240 bytes MD5: 0x9F76F8DAF96A12CD5EBAA8F2F615F91D
SHA-1: 0x69B9CC3DD872E2280F439443AF445DD9CA6CB7DB
16 %ProgramFiles%\Unlocker\UnlockerDriver5.sys 4,096 bytes MD5: 0xF365FA561C3AB455D8685770D208691A
SHA-1: 0x18D7A5F9AFD375C362DFDDC426AE0A870E091E24
17 %ProgramFiles%\Unlocker\UnlockerHook.dll 4,608 bytes MD5: 0x0342543031665181073FECD77CB59C25
SHA-1: 0xB8ACCBAB3426296E3ECE5EFAAB6161A2A15015F9
18 [file and pathname of the sample #1] 220,454 bytes MD5: 0xE375121E3E53726A2C6CDB52F4D80AE3
SHA-1: 0x06C15CA58DDDA1072F5AB4C820DAC979FAA72A34

 

Memory Modifications

Process NameProcess FilenameMain Module Size
ebay_shortcuts_1016_new.exe%Temp%\nsa3.tmp\ebay_shortcuts_1016_new.exe184,320 bytes
[filename of the sample #1][file and pathname of the sample #1]212,992 bytes
UnlockerAssistant.exe%ProgramFiles%\Unlocker\UnlockerAssistant.exe24,576 bytes

 

Registry Modifications

 

Other details

United Kingdom

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2014 ThreatExpert. All rights reserved.