Submission Summary:

What's been foundSeverity Level
Contains characteristics a SPAM bot, backdoor trojan, and a rootkit. The backdoor component allows the remote hacker to download/install additional components and instruct the bot to launch massive SPAM attacks from the compromised system.
Capability to send out email message(s) with the built-in SMTP client engine.
Stealth-mode characteristics common to Rootkits.
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Hacktool.Rootkit!sd6 Hacktool.Rootkit!sd6 is a malicious application that could be used by attackers to break into a system.
Trojan.Srizbi!sd6 Trojan.Srizbi!sd6 is a malicious program that does not infect other files but may represents security risk for your computer and/or network environment.

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A hacktool that could be used by attackers to break into a system

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %System%\pqasghjd.sys 62,384 bytes MD5: 0x39C69645D67D49273F0E9F5F00114294
SHA-1: 0x323B0C052AF198B17E48CEA7497F0D9ECDBAF134
Hacktool.Rootkit!sd6 [PCTools]
Hacktool.Rootkit [Symantec]
Generic BackDoor [McAfee]
2 [file and pathname of the sample #1] 66,048 bytes MD5: 0xE6CCB9C7C60FB56B22BF620DF772A596
SHA-1: 0xF9A8DDCC742290E92A6BF44C207A76047FA3CF22
Trojan.Srizbi!sd6 [PCTools]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]73,728 bytes

Process NameProcess FilenameAllocated Size
services.exe%System%\services.exe65,536 bytes
services.exe%System%\services.exe98,304 bytes

Driver NameDriver Filename
pqasghjd.sys%System%\pqasghjd.sys

 

Registry Modifications

 

Other details

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2009 ThreatExpert. All rights reserved.