| Visit ThreatExpert web site | | | Close Report |
[Symantec]
[Kaspersky Lab]
, Mal/Behav-010, Mal/Emogen-I [Sophos]| What's been found | Severity Level |
| Downloads/requests other files from Internet. | ![]() |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | [file and pathname of the sample #1] | 11,776 bytes | MD5: 0xEB4209AC9062804A8C83831FFB0DC6C7 SHA-1: 0xFD765CA128A0034E8D7582D81423B690B9A71693 |
Suspicious.MH690 [Symantec]Trojan-GameThief.Win32.Lmir.cha [Kaspersky Lab]Mal/Behav-328 , Mal/Behav-010, Mal/Emogen-I [Sophos]packed with PE_Patch.UPX [Kaspersky Lab] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 61,440 bytes |
![]() | Other details |
| URL to be downloaded | Filename for the downloaded bits |
| http://arplgm.cn/1.exe | %Windir%\1.exe |
| http://arplgm.cn/2.exe | %Windir%\2.exe |
| http://arplgm.cn/3.exe | %Windir%\3.exe |
| http://arplgm.cn/4.exe | %Windir%\4.exe |
| http://arplgm.cn/5.exe | %Windir%\5.exe |
| http://arplgm.cn/6.exe | %Windir%\6.exe |
| http://arplgm.cn/7.exe | %Windir%\7.exe |
| http://arplgm.cn/8.exe | %Windir%\8.exe |
| http://arplgm.cn/9.exe | %Windir%\9.exe |
| http://arplgm.cn/0.exe | %Windir%\0.exe |
| http://arplgm.cn/11.exe | %Windir%\11.exe |
| http://arplgm.cn/12.exe | %Windir%\12.exe |
| http://arplgm.cn/13.exe | %Windir%\13.exe |
| http://arplgm.cn/14.exe | %Windir%\14.exe |
| http://arplgm.cn/15.exe | %Windir%\15.exe |
| http://arplgm.cn/16.exe | %Windir%\16.exe |
[Sophos]
[Ikarus]
[Symantec]
[Sophos]
[Ikarus]
[Symantec]
[Sophos]
[Ikarus]| What's been found | Severity Level |
| Registers a 32-bit in-process server DLL. | ![]() |
| Registers a Browser Helper Object (Microsoft's Internet Explorer plugin module). | ![]() |
| Contains characteristics of an identified security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
Trojan-PWS.OnLineGames.GEN![]() |
Trojan-PWS.OnLineGames.GEN is a trojan that drops a dll and tries to steal vital information from the infected machine with regards to various online games and then tries to send that information to the author of the trojan. |
Trojan-Spy.Banker.ALR![]() |
Trojan.Spy.Banker.ALR steals personal information from an infected PC by monitoring users online activities including but not limited to login information and creditcard numbers which are subsequently sent to a remote server. |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 |
%System%\Assicen.dll
|
792,064 bytes | MD5: 0x6728270CB7DBB776ED086F5AC4C82310 SHA-1: 0xE913CC86F68627541DAE2A92509AB230F427E980 |
(not available) |
| 2 | %System%\Hatanem.dat | 256 bytes | MD5: 0x4ED88D8233C270356D21925B36DC01E6 SHA-1: 0x636C0D8A188A0C9E67AD373730558A6C624A70BC |
(not available) |
| 3 |
%System%\Marctw.dll
|
9,216 bytes | MD5: 0x43F1A08A6FBEFB6F5FF05F5DBD499A35 SHA-1: 0xCE4C84C928806AC9B83713590791D4BAD0426C6D |
Mal/HckPk-E [Sophos] |
| 4 |
%System%\myInsDll.exe
|
33,280 bytes | MD5: 0x8358193945474F68A2D498CBED8EB97E SHA-1: 0xA905C9849147628387F6B1D5A7BF88FD5A64F15F |
(not available) |
| 5 |
%System%\Ntuscrc.dll
|
14,848 bytes | MD5: 0x22A93F9F1ADF7C253B4943CAA176785D SHA-1: 0xE051377F94220C8C56C9D34E74E78B6253E9B5F2 |
packed with ASPack [Kaspersky Lab] |
| 6 |
%System%\QQ.dll
|
187,904 bytes | MD5: 0x354D2E3AB343FA7340D3D12D153FC2CC SHA-1: 0xC7AF1DA65C905D49790798CA6C7B2C9572FBA728 |
packed with PE_Patch.UPX [Kaspersky Lab] |
| 7 | [file and pathname of the sample #1] | 205,312 bytes | MD5: 0x5AEB58CD335731D731E2136D601893EB SHA-1: 0xEE2D0B92927D2792A4193A43B2A663AE4EC8A74F |
Mal/Generic-A [Sophos]Trojan-Dropper.Delf [Ikarus] |
| 8 | [file and pathname of the sample #2] | 16,896 bytes | MD5: 0xDF1E477C084CBA34C8CAAF33912B67A4 SHA-1: 0xE6992E8316A3EF3C62497A63440CD8FD635B9D56 |
Suspicious.MH690 [Symantec]Mal/HckPk-A [Sophos]Trojan.Zlob [Ikarus] |
| 9 | [file and pathname of the sample #3] | 18,944 bytes | MD5: 0x8CA28416EDF8C0DA6FCB764EA25EE8BE SHA-1: 0x89B3F8F06E4A3F33538FD869C1D1EA0BA901A20A |
Suspicious.MH690 [Symantec]Mal/HckPk-A [Sophos]Virus.Win32.JunkPoly [Ikarus] |
| 10 |
%System%\sfc32.dll
|
133,120 bytes | MD5: 0xE8F132E41430A1EFD24282BE4DFF0723 SHA-1: 0x96FF851E5CC953D99950110F64D0DA8E67D9B215 |
Trojan-Spy.Banker.ALR [PCTools]PatchedSFC [McAfee] |
| 11 |
%System%\Yamezakw.dll
|
3,584 bytes | MD5: 0xCFF013F4A17F309B8456269A836B1A6E SHA-1: 0x77D60AE7AF31CA90579348F30F8F12022881BC76 |
Mal/HckPk-E [Sophos] |
| 12 | %System%\Ynams.dat | 256 bytes | MD5: 0x9DBB43890B4A2964A96573679673B561 SHA-1: 0x0FEA263548AB2BA775AD9BA9FA221A4CA6CFA070 |
(not available) |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 229,376 bytes |
myInsDll.exe![]() | %System%\myinsdll.exe![]() | 45,056 bytes |
| [filename of the sample #3] | [file and pathname of the sample #3] | 57,344 bytes |
| [filename of the sample #2] | [file and pathname of the sample #2] | 57,344 bytes |
| [generic host process] | [generic host process filename] | 20,480 bytes |
| Module Name | Module Filename | Address Space Details |
Ntuscrc.dll![]() | %System%\Ntuscrc.dll![]() | Process name: myInsDll.exe![]() Process filename: %System%\myinsdll.exe ![]() Address space: 0xAC0000 - 0xBC3000 |
sfc32.dll![]() | %System%\sfc32.dll![]() | Process name: myInsDll.exe![]() Process filename: %System%\myinsdll.exe ![]() Address space: 0x76C60000 - 0x76C89000 |
![]() | Registry Modifications |
![]() | Other details |
![]() |
China |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2009 ThreatExpert. All rights reserved.