| Visit ThreatExpert web site | | | Close Report |
[PCTools]
[Symantec]| What's been found | Severity Level |
| Produces outbound traffic. | ![]() |
| Downloads/requests other files from Internet. | ![]() |
| Creates a startup registry entry. | ![]() |
| Contains characteristics of an identified security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
| Trojan.DNSblocker | Trojan.DNSblocker is a malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment. |
| Threat Category | Description |
![]() |
A network-aware worm that attempts to replicate across the existing network(s) |
![]() |
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment |
![]() |
A code with the rootkit-specific techniques designed to hide the software presence in the system |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %Temp%\zpskon_1259758877.exe | 46,080 bytes | MD5: 0x2BEE8080D2FBD6E1B8C9065A1C0A0FE3 SHA-1: 0xC9B0B53A85D801FEA51093478A53D1F1DC9157E6 |
(not available) |
| 2 |
%Windir%\010112010146100101.xxe
%Windir%\010112010146111103.xxe %Windir%\0101120101465355.xxe |
2 bytes | MD5: 0x4F59236A872D3D23FE86871831A2ADC8 SHA-1: 0x27CD3AD00D41D7F0601DE9C8B22998E9E173F882 |
(not available) |
| 3 |
%Windir%\bk23567.dat
%Windir%\fdgg34353edfgdfdf |
1 bytes | MD5: 0xC81E728D9D4C2F636F067F89CC14862C SHA-1: 0xDA4B9237BACCCDF19C0760CAB7AEC4A8359010B0 |
(not available) |
| 4 | %Windir%\freddy75.exe | 55,296 bytes | MD5: 0xB50A54B54E64F87AC1DC5D3EFFF0662F SHA-1: 0xC9390822FD27CF2BA38EE77B41719173BA5C4CD1 |
Net-Worm.Win32.Koobface.csf [Kaspersky Lab] Win-Trojan/Malware.55296.G [AhnLab] |
| 5 |
%Windir%\ld15.exe
[file and pathname of the sample #1] |
41,472 bytes | MD5: 0xEE54F6FC8B1A3C42A1263708C67FA4AD SHA-1: 0x1B37349241DD7CD55515D7CC307934A3BA40BA15 |
Net-Worm.Koobface [PCTools]W32.Koobface.D [Symantec]Net-Worm.Win32.Koobface.csa [Kaspersky Lab] W32/Koobface.worm.gen.u [McAfee] |
| 6 |
%Windir%\pp12.exe
|
38,912 bytes | MD5: 0x9BC9652E2E1C633BCBDCF9594956D74C SHA-1: 0xC2406F79E64D4169F876844EE15EE44A789253E6 |
Net-Worm.Win32.Koobface.cse [Kaspersky Lab] |
| 7 |
%Windir%\rdr_1259729075.exe
%Windir%\rdr_1259729158.exe |
92,672 bytes | MD5: 0xEA9173CC0A85B804E6D7B764DEEB0BBF SHA-1: 0xF993EC082306FB217208AEFEB458607B1F4A8677 |
Trojan.Dropper [PCTools]Trojan.Dropper [Symantec]Trojan-Dropper.Win32.Agent.biin [Kaspersky Lab] W32/Koobface.worm.gen.d [McAfee] W32/KoobFa-N [Sophos] VirTool:WinNT/Koobface.gen!D [Microsoft] Worm.Win32.Koobface [Ikarus]Win32/Koobface.worm.92672 [AhnLab] |
| 8 |
%System%\drivers\fio32.sys
|
59,520 bytes | MD5: 0xB5897245E34DF833A207241A11C065F8 SHA-1: 0x5B164A222DC6B83C7E851FD9F28D45A57F352DB6 |
Trojan.Generic [PCTools]Trojan Horse [Symantec]Rootkit.Win32.Agent.wqv [Kaspersky Lab] Generic.dx!gzf [McAfee] Mal/Generic-A [Sophos]VirTool:WinNT/Koobface.gen!D [Microsoft] Rootkit.Win32.Agent [Ikarus] |
| 9 |
%System%\fio32.dll
|
50,688 bytes | MD5: 0x2926C3F8EA16177F03DC8969AC983EAA SHA-1: 0x2A14DC70513D317E9DC7E2698EE45E0C3D7279D9 |
Net-Worm.Koobface [PCTools]W32.Koobface.A [Symantec]Net-Worm.Win32.Koobface.cln [Kaspersky Lab] Mal/Generic-A , Mal/KoobHeur-A [Sophos]Worm.Win32.Koobface [Ikarus]Win32/Koobface.worm.50688.C [AhnLab] |
| 10 |
%System%\__c003F894.dat
%System%\__c0081000.dat |
34,816 bytes | MD5: 0x9BE2B2412E653B3969A988C8D4A44087 SHA-1: 0x4DA69696E22B1B27A2DFFFB558EE599F6396D29E |
packed with PE_Patch [Kaspersky Lab] |
| 11 | c:\xcrashdump.dat | 57 bytes | MD5: 0xC538F93E7A688C0F45489B3B7CFC4DF9 SHA-1: 0xE4724C7F1A22CF4C06DF8603D71309EA0E1C4360 |
(not available) |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| freddy75.exe | %Windir%\freddy75.exe | 57,344 bytes |
pp12.exe![]() | %Windir%\pp12.exe![]() | 94,208 bytes |
| Module Name | Module Filename | Address Space Details |
| __c0081000.dat | %System%\__c0081000.dat | Process name: explorer.exe![]() Process filename: %Windir%\explorer.exe ![]() Address space: 0xF90000 - 0xF9C9BC |
| __c0081000.dat | %System%\__c0081000.dat | Process name: IEXPLORE.EXE![]() Process filename: %ProgramFiles%\internet explorer\iexplore.exe ![]() Address space: 0x1990000 - 0x199C9BC |
fio32.dll![]() | %System%\fio32.dll![]() | Process name: svchost.exe![]() Process filename: %System%\svchost.exe ![]() Address space: 0x10000000 - 0x10024000 |
| Driver Name | Driver Filename |
fio32.sys![]() | %System%\drivers\fio32.sys![]() |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Russian Federation |
| Port | Protocol | Process |
| 1067 | UDP | freddy75.exe (%Windir%\freddy75.exe) |
| Remote Host | Port Number |
| 200.58.120.56 | 80 |
| 204.0.5.10 | 80 |
| 204.0.5.19 | 80 |
| 213.193.213.123 | 80 |
| 61.235.117.83 | 80 |
| 62.149.165.29 | 80 |
| 64.6.241.26 | 80 |
| 69.63.181.11 | 80 |
| 69.63.187.19 | 80 |
| 74.125.95.103 | 80 |
![]() | Outbound traffic (potentially malicious) |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2010 ThreatExpert. All rights reserved.