Submission Summary:

 

Technical Details:

NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\Seekapp\readme.html 5,019 bytes MD5: 0xF973CD924863345B5E8A3382D18809B9
SHA-1: 0x6A99B669DE7C262686C2DBF2925C42F74D8742D7
packed with Edit [Kaspersky Lab]
2 %Temp%\Seekapp\seekapp.dll 589,824 bytes MD5: 0xBD5422A6AB1ED411988D352F57FE0386
SHA-1: 0x9BD0F12C0C770EFA1ACC852C81F87A72F64B9E60
(not available)
3 %Temp%\Seekapp\seekapp.exe
%Temp%\Seekapp\seekapp132.exe
54,760 bytes MD5: 0xFBDC2DA56D7794963B74ED95EB0FFA20
SHA-1: 0x8C5161330BADC044CD7BCBE52F5C13E3682FE664
Troj/Agent-KQM [Sophos]
4 %Temp%\Seekapp\seekapp1.dll
%Temp%\Seekapp\seekapp2.dll
%Temp%\seekapp.dll
577,536 bytes MD5: 0x6E30895BEE903D90CCF2AE20144A2BA5
SHA-1: 0x8ED15260DABF11910A3D61BF3F22F6DE911F7C77
Adware-BHO.gen.g [McAfee]
Mal/BHO-S [Sophos]
Gen.Trojan [Ikarus]
5 %Temp%\Seekapp\seekapp149.exe
%Temp%\Seekapp\seekappsrch.exe
54,760 bytes MD5: 0xF8F8B7B76C5C618BEBD0FA60BB1C115B
SHA-1: 0x32D913160E3533DC927678D10A081FD52B56F0E3
(not available)
6 %Temp%\Seekapp\uninstall.exe 127,144 bytes MD5: 0x4D37323BC4F7AB3EAB1D7397BA8FE604
SHA-1: 0xDB06F708D11B12E8625C4620C6BF2FBC7418449E
(not available)
7 %Temp%\seekapp.exe 33,280 bytes MD5: 0x8358193945474F68A2D498CBED8EB97E
SHA-1: 0xA905C9849147628387F6B1D5A7BF88FD5A64F15F
(not available)
8 [file and pathname of the sample #1] 1,369,630 bytes MD5: 0xF74708DA4F2D06C8114B1077F957DC68
SHA-1: 0x0F88DDE2E1BE82E7C7CC476BFF8EBF9863BB4E71
Gen.Trojan [Ikarus]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
seekappsrch.exe%Temp%\seekapp\seekappsrch.exe49,152 bytes
seekapp.exe%Temp%\seekapp\seekapp.exe49,152 bytes
seekapp132.exe%Temp%\seekapp\seekapp132.exe49,152 bytes
seekapp149.exe%Temp%\seekapp\seekapp149.exe49,152 bytes
[generic host process][generic host process filename]45,056 bytes
Au_.exe%Temp%\~nsu.tmp\Au_.exe258,048 bytes
seekapp.exe%Temp%\seekapp.exe45,056 bytes
uninstall.exe%Temp%\Seekapp\uninstall.exe258,048 bytes

Service NameDisplay NameStatusService Filename
Seekapp ServiceSeekapp Service"Stopped""%CommonAppData%\Seekapp\seekapp132.exe" "seekapp.dll" Service

 

Registry Modifications

 

Other details

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.