| Visit ThreatExpert web site | | | Close Report |
[Symantec]
[Ikarus]| What's been found | Severity Level |
| Registers a Winlogon notification package so that the installed module is loaded into the address space of winlogon.exe. | ![]() |
| Contains characteristics of an identified security risk. | ![]() |
![]() | Possible Security Risk |
| Threat Category | Description |
![]() |
A hacktool that could be used by attackers to break into a system |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 |
%Temp%\AMD64\antiwpa.dll
|
9,216 bytes | MD5: 0xE462556DC827175E5E01D34B16F2B531 SHA-1: 0xC2501DBCCB1A6CF87B72F459C198F9F28350B9DA |
Generic.dx [McAfee]HackTool:Win32/Wpakill [Microsoft]not-a-Virus.Hacktool.Wpakill [Ikarus] |
| 2 | %Temp%\AntiWPA3.cmd | 3,150 bytes | MD5: 0xAF9BD71FB0FF81D3ABDCC2A6FD946F4F SHA-1: 0x8D3D1026436B302E01901C1265B04C7A17473B1E |
(not available) |
| 3 |
%Temp%\IA64\antiwpa.dll
|
18,688 bytes | MD5: 0x3CF0071B0FA2245BD53E99828948ED03 SHA-1: 0x7D436B4DC50832D677E0423507A8CA0D12FEA1D4 |
Hacktool [Symantec]Generic.dx!xu [McAfee]HackTool:Win32/Wpakill.dll [Microsoft]not-a-Virus.Hacktool.Wpakill [Ikarus] |
| 4 | %Temp%\readme.txt | 20,627 bytes | MD5: 0x024EB905807AEE93E1B9F0D50BFB1D67 SHA-1: 0xA4CD71234303CF54E63E10CD73E15CD1D69C8070 |
(not available) |
| 5 |
%Temp%\X86\antiwpa.dll
%System%\antiwpa.dll
|
5,376 bytes | MD5: 0x98C332990684CD9F113FBD495841C6FA SHA-1: 0xB42D4F6996759CD5EC6B5DE89F1EF1F3A40E7084 |
Hacktool [Symantec]Generic PUP.x [McAfee]HackTool:Win32/Wpakill [Microsoft]not-a-Virus.Hacktool.Wpakill [Ikarus]Win-Trojan/Xema.variant [AhnLab] |
| 6 | [file and pathname of the sample #1] | 22,913 bytes | MD5: 0xE5A14C47E9C26E78FCCB22EE71FEDD51 SHA-1: 0x354CBEAAED498DEAF7B5B17FDCFBA67BD53D0692 |
Hacktool [Symantec]not-a-Virus.Hacktool.Wpakill [Ikarus] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [generic host process] | [generic host process filename] | 20,480 bytes |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Germany |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.