Submission Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Packed with a packer that is known to be used by malware (e.g. to complicate threat analysis or detection).
Contains characteristics of an identified security risk.

 

Technical Details:

NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.

 

Possible Security Risk

Security RiskDescription
Trojan-Downloader.Ejik Trojan-Downloader.Ejik disguises itself as an intaller for Skype and downloads and installs other malware on the affected system.

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 [file and pathname of the sample #1] 241,033 bytes MD5: 0xAFBB6057193BAF6640656F97F21FA64E
SHA-1: 0xEEAC90BEDEF858814A61AC463FBF7830DE2B5473
Possible_Virus [Trend Micro]
2 %System%\SkypeClient.EXE 81,920 bytes MD5: 0x4F96A943DD01FA3E8D943EDCE9FBBD4E
SHA-1: 0x796A69F6471C6E98BA8F3C8A1D76BB9B92FF5258
Adware-BDSearch.dldr [McAfee]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]806,912 bytes
SkypeClient.EXE%System%\skypeclient.exe81,920 bytes

 

Other details

China

PortProtocolProcess
1038UDP[file and pathname of the sample #1]

Server NameServer PortConnect as UserConnection Password
pc112233.cn80(null)(null)

URL to be downloadedFilename for the downloaded bits
http://download.skype.tom.com/Tom-SkypeSetup.exe%ProgramFiles%\Skype\~Te3.tmp
http://skype.tom.com/download/install/sobar.exe%ProgramFiles%\Skype\~Te4.tmp
http://skypetools3.tom.com/download/promote/promote.dll%System%\promote.dll
http://www.pc112233.cn/soft/my8848.exe%System%\my8848.exe
http://www.pc112233.cn/soft/yoyo1048.exe%System%\yoyo1048.exe
http://www.pc112233.cn/soft/e21.exe%System%\e21.exe
http://www.pc112233.cn/soft/msn.exe%System%\msn.exe
http://www.pc112233.cn/soft/ggcg.exe%System%\ggcg.exe
http://www.pc112233.cn/soft/winxp3.exe%System%\winxp3.exe
http://www.pc112233.cn/soft/winxp4.exe%System%\winxp4.exe
http://www.PC112233.cn/soft/UUSee_heima_Setup_110253.exe%System%\UUSee_heima_Setup_110253.exe
http://download.skype.tom.com/Tom-SkypeSetup.exe%ProgramFiles%\Skype\~Te1.tmp
http://skype.tom.com/download/install/sobar.exe%ProgramFiles%\Skype\~Te2.tmp

 

 

Downloaded File Summary:

What's been foundSeverity Level
Downloads/requests other files from Internet.
Registers a 32-bit in-process server DLL.
Packed with a packer that is known to be used by malware (e.g. to complicate threat analysis or detection).
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Adware.Agent Adware.Agent will display advertisements on an infected system.
Adware.Sogou Adware.Sogou comes bundled with various trojans and is secretly installed onto the unsuspecting users computer. It produces pop-up and pop-under advertisements.
Trojan-Downloader.QQHelper Trojan.Downloader.QQHelper contacts a remote server in order to download and execute additional malware onto a users computer without their knowledge.

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A potentially unwanted adware program designed to deliver various advertisements to the users' systems

 

File System Modifications

#Filename(s)File SizeFile Hash
1 %CommonAppData%\Skype\DefaultFlashs\Skype A_W___1743ZHXJTOSC.pkg 29,724 bytes MD5: 0x7A8F84E8B1A2883294D8EF7EBEE8BB22
SHA-1: 0xFED152F8ED8F270BBC86AD72A83A28A3D5C383AB
2 %CommonAppData%\Skype\DefaultFlashs\Skype B_W___3379ZHLDTOSC.pkg 39,537 bytes MD5: 0xF9FF7A87330EB8F36E4D6EA63BC94E3A
SHA-1: 0xAA83F3AE32A276DBA5860D25A41B4E4E7B55F8B2
3 %CommonAppData%\Skype\DefaultFlashs\Skype C_W___3515ZHWGTOSC.pkg 66,710 bytes MD5: 0x3806A74278398CE36EA13DD302225E54
SHA-1: 0xDC23001B31FAFE0B8688D2C3FA8C31A00CC3DA44
4 %CommonAppData%\Skype\DefaultFlashs\Skype D_W___5443ZHMGTOSC.pkg 16,877 bytes MD5: 0x7ED8E6FD30CDB34311C737FFD02742A6
SHA-1: 0x2A4CD70F8FA34672D23D7E3B7D98E22BE3B1951A
5 %CommonAppData%\Skype\DefaultFlashs\Skype E_W___3331ZHWGTOSC.pkg 99,537 bytes MD5: 0x760B2F892CCB94F7394F88344745BB27
SHA-1: 0x5AAAD7E793EA1D81E4CB113D526BB03A6E3DF4E5
6 %CommonAppData%\Skype\DefaultFlashs\Skype F_W___3154ZHLDTOSC.pkg 103,812 bytes MD5: 0x4BC00C69DBF1F0D441A59559B012A002
SHA-1: 0x7E1A3661F7155873CBA7C31749CD030CC1A6DF73
7 %CommonAppData%\Skype\DefaultFlashs\Skype G_W___2304ZHLDTOSC.pkg 73,657 bytes MD5: 0x5313829D9B82C9A1D1B5C2EB15B6D621
SHA-1: 0x67E5A537AB206EF5C2F7D8AF0D54F28EB3995316
8 %CommonAppData%\Skype\DefaultFlashs\Skype H_W___3115ZHLDTOSC.pkg 41,650 bytes MD5: 0xD16BB9C45265007444FC158FED209A76
SHA-1: 0x629E334376E26EDC7503FFCE175145346D70BB38
9 %CommonAppData%\Skype\DefaultFlashs\Skype I_W___3544ZHLDTOSC.pkg 39,967 bytes MD5: 0x273D6145DAD9B47CCD51C65F658FF7E0
SHA-1: 0x93F4F5261BA8944E6FB583A772012ACF7AB87D86
10 %CommonAppData%\Skype\DefaultFlashs\Skype J_W___2404ZHLDTOSC.pkg 95,371 bytes MD5: 0x6E1C6D135E653D78F46D3459318EEEA5
SHA-1: 0xA9E491070B434217DB5332332A6C9C5016361005
11 %CommonAppData%\Skype\Defaultpics\Skype berry.gif 17,211 bytes MD5: 0x1237A8DC51A80F74DC5B666C51692530
SHA-1: 0xF1EAB4BCA9DB20A37F453ABF63E42930FC820280
12 %CommonAppData%\Skype\Defaultpics\Skype Byebye.gif 13,128 bytes MD5: 0x124BAC8DFCA8CF94DA2883671401235E
SHA-1: 0xF27A5C93D727537592D01EE017C298E3FDD3A8B8
13 %CommonAppData%\Skype\Defaultpics\Skype Call.gif 17,121 bytes MD5: 0x6AD4C831FA092B02AD3FBE71D7327F07
SHA-1: 0x4A9BB58A31F87515F327369653C8036319D0E2E8
14 %CommonAppData%\Skype\Defaultpics\Skype clap.gif 16,349 bytes MD5: 0xF5C3F17C2B0135EE90A713DC6EF009A1
SHA-1: 0x5F6ABFE3CA7CAC05BA04FE231B226E9512BE14C8
15 %CommonAppData%\Skype\Defaultpics\Skype Depressed.gif 26,660 bytes MD5: 0x5945ABA0C5E0FDDB81E435AA8FD21B79
SHA-1: 0x5E2DBCD2C50EE6E4FADA2F14B5A62059EA2A6CF0
16 %CommonAppData%\Skype\Defaultpics\Skype Faint.gif 25,917 bytes MD5: 0x5EBAB033D5A5E1B71CD603ED5DF29DCB
SHA-1: 0xB3676D9D6CDD3745F489B374E70EDACC39D06E2C
17 %CommonAppData%\Skype\Defaultpics\Skype Hug.gif 7,268 bytes MD5: 0x4AA25F82351F38662B29874556724F25
SHA-1: 0x28FB5C776F7EEB46FFECB933EAE8F0CE144C0B81
18 %CommonAppData%\Skype\Defaultpics\Skype Icecream.gif 10,569 bytes MD5: 0x8A970E530B56ACDDE26FE97814D5668B
SHA-1: 0x4C58166E484A5213F28BB8E0D717351F0CEB9498
19 %CommonAppData%\Skype\Defaultpics\Skype Love.gif 9,258 bytes MD5: 0x8F94E0D0158F32B83549E9CD2E7FC557
SHA-1: 0x3A1A5763D7B09702641657273E6C3E2789B31592
20 %CommonAppData%\Skype\Defaultpics\Skype Morning.gif 27,024 bytes MD5: 0xF01F770CD8E73A4D7641CC58A76D4945
SHA-1: 0x8F456B0D1E9F353E4A7D91AE757AD3ACF0065CD2
21 %CommonAppData%\Skype\Defaultpics\Skype Motobike.gif 30,769 bytes MD5: 0xDA618FDC6B5D9C0C9CFC13A130885FD0
SHA-1: 0x3ACAF64428D2868EBD39D646C34954C95435FCE2
22 %CommonAppData%\Skype\Defaultpics\Skype Passby.gif 32,532 bytes MD5: 0x1F089EEBD79CD35491C5099848E1F254
SHA-1: 0x807AB7F46FB8F4754E7BC59833059CA0CD542091
23 %CommonAppData%\Skype\Defaultpics\Skype Salary.gif 9,110 bytes MD5: 0x70B232D122B4C0EFFDF4F00F06EA96A9
SHA-1: 0x851BF64B05AC6C275167FFD9E023596507D6997F
24 %CommonAppData%\Skype\Defaultpics\Skype Search.gif 9,375 bytes MD5: 0xA72D4A4C9D96121A5F42AD52A420F6D6
SHA-1: 0x378786502269535913560BD07E175B555C3DC342
25 %CommonAppData%\Skype\Defaultpics\Skype Sleep.gif 26,820 bytes MD5: 0xE8DD2BA202AA3D5E2C8285D7F8AE1FEB
SHA-1: 0xD9B7B92E688FB39F9CD7E6707D61D8ABEAB71973
26 %CommonAppData%\Skype\Defaultpics\Skype Smelly.gif 13,806 bytes MD5: 0xC163411A8D8BE3EAD314696F3ECC2090
SHA-1: 0xEA1AE1B5EC3DEEBA23B7D925507122D7ED7D4A4D
27 %CommonAppData%\Skype\Defaultpics\Skype Sweat.gif 34,782 bytes MD5: 0x7C7876215128C87AFBF434FC06D3C9D9
SHA-1: 0xCC671DF034D4E2E57EC00C61651615813985926B
28 %CommonAppData%\Skype\Defaultpics\Skype Tea.gif 26,765 bytes MD5: 0xC68585AC8EA332A0421F041C2FF235AC
SHA-1: 0xED6B9A102B02984FEE29263CECFE295530AED155
29 %CommonAppData%\Skype\Defaultpics\Skype Vacuity.gif 36,436 bytes MD5: 0x56813866128EC92BF2E90204D54F5E80
SHA-1: 0x5FF38FB15DE70A70555A788675C8F598C87DCC04
30 %CommonAppData%\Skype\Defaultpics\Skype Work.gif 43,626 bytes MD5: 0xE010A18F99843BADD7B9C7EDEE7619A2
SHA-1: 0x07C89022AD5B32590069F1BC0C852165632E8024
31 %CommonAppData%\Skype\Pictures\Angel Skype.png 8,978 bytes MD5: 0x2BE1981DB07A180401FC7A5A8CEF5075
SHA-1: 0x92D963CE8F595391E9E98BF635D0F1F13D65DA3C
32 %CommonAppData%\Skype\Pictures\Architect Skype.png 8,424 bytes MD5: 0x81DD886F6ED943A5222D5D4C8683C56A
SHA-1: 0x6E67D5F7FB6FB16D76502BAD86CF4981EDB04701
33 %CommonAppData%\Skype\Pictures\Beach Skype.png 11,437 bytes MD5: 0x005C88ACFA72F8AE0D6E0C032F97B07B
SHA-1: 0x917C65E8429689943185C838F9E3E8796697A826
34 %CommonAppData%\Skype\Pictures\Behind Skype.png 9,348 bytes MD5: 0xEA4B973BF1AEA29E6D3A465BEEA8D6EC
SHA-1: 0xE4156EB3F59C413C93680F7E12C36F94F27DC460
35 %CommonAppData%\Skype\Pictures\Business Skype.png 11,265 bytes MD5: 0xD3D2CD045E0DABCCBB20C0EFEDA28FEB
SHA-1: 0x666AFC113222CEB585F6C1543EC79A45229C4E0B
36 %CommonAppData%\Skype\Pictures\Call Me Sweetheart.png 7,433 bytes MD5: 0xC8E7B81E5A7D846D9E2116DFE0C14AEA
SHA-1: 0x6208250679A6C59F58EC3CEF429D007627FE4336
37 %CommonAppData%\Skype\Pictures\Call Me.png 7,517 bytes MD5: 0x9B7D45ADDCBD4EBEC98AE6ED18F8B4A7
SHA-1: 0xD5ABE53E3C214A280AB14B94A3602F0679ADF834
38 %CommonAppData%\Skype\Pictures\Carnival Skype.png 18,785 bytes MD5: 0x689EBD763A9689AA588942EFF3AF16EA
SHA-1: 0x67ADB6C897D37A1F578F40C187B2CEAA99515CF9
39 %CommonAppData%\Skype\Pictures\Chic Skype.png 9,043 bytes MD5: 0x4AEB13CE3D1DFD7F26BBE89796C068CB
SHA-1: 0xF90AE092624D9F3D055705F3FFA756CB2C354839
40 %CommonAppData%\Skype\Pictures\Christmas Skype.png 10,028 bytes MD5: 0xAB057C96DD039206722D76BB907F55B8
SHA-1: 0x5882C59E5A97D64A9F44666B240B99ABD66B9CD2
41 %CommonAppData%\Skype\Pictures\College Skype.png 8,823 bytes MD5: 0xC2F526CC6924635FFC2D807C58D97E57
SHA-1: 0x01C553A9C808AB49923D722F3CFB9FAA9783B265
42 %CommonAppData%\Skype\Pictures\Desert Skype.png 14,460 bytes MD5: 0x177DF4575F2980C7894FCEC26FB97527
SHA-1: 0x1901BEC1DD3442673B37C42D1253BC4DDC83DF56
43 %CommonAppData%\Skype\Pictures\Designer Skype.png 4,658 bytes MD5: 0x0258A33721B5796FD8532BCD2E8D8902
SHA-1: 0x581423222933E60FD71D584A00C1A1B0E66998E2
44 %CommonAppData%\Skype\Pictures\Devil Skype.png 10,626 bytes MD5: 0xEA92FDB9996751A6C0E469EDAD0B180C
SHA-1: 0x3D1A7E041477A71922DAB630EC368787351CEB0E
45 %CommonAppData%\Skype\Pictures\DIY Skype.png 14,658 bytes MD5: 0xBC21C17137709C8E731D10653174F573
SHA-1: 0x97E37DDEA788516399DBA2F631738DD7D3D53AB3
46 %CommonAppData%\Skype\Pictures\DJ Skype.png 9,392 bytes MD5: 0xCEBDD50E3EF9F4635593AEE28FD91C39
SHA-1: 0xE18E69325652826ADC4A47ADA3A62480C26EAA02
47 %CommonAppData%\Skype\Pictures\Earbud Skype.png 5,949 bytes MD5: 0xDD8B8411EB4BF5102B3241A70704B45F
SHA-1: 0x0309C98D4D54BB9913E1FE02D59CFB139A017AE0
48 %CommonAppData%\Skype\Pictures\Empire Skype.png 10,411 bytes MD5: 0xE2DB087448D6432785AC9F70C6C25D1A
SHA-1: 0xE5B047D73FD7F29E500ACD50C36DCAF8EC9021CD
49 %CommonAppData%\Skype\Pictures\Fax Skype.png 3,171 bytes MD5: 0x253F4FF10BD479BE4366D6F7F13FEDF1
SHA-1: 0x99290A9A9BC4C9E71476D55B33C59240561E832C
50 %CommonAppData%\Skype\Pictures\Geisha Skype.png 16,162 bytes MD5: 0x96C600CABC18CD0FECF38B22C73AE7B6
SHA-1: 0xFA3E33FE0249627257750D8AEEA5EC8E7C1808E5
51 %CommonAppData%\Skype\Pictures\Hula Skype.png 11,994 bytes MD5: 0x72842D87F0C5D5B05439ECDE2421DBB0
SHA-1: 0x8B37E513BD71117D01887B73C26F48583A9C8AD5
52 %CommonAppData%\Skype\Pictures\Make Skype Not War.png 7,949 bytes MD5: 0xBE816D7A43C88FD2D1226E8F3B95365B
SHA-1: 0xD8AED98B15BF6763C78B38D5E66B61838B670488
53 %CommonAppData%\Skype\Pictures\Metal Skype.png 19,470 bytes MD5: 0x6DA0DFFFD6AF8067264F1A71068B03B8
SHA-1: 0x376582F1FCBB381DA406F63B9E929AF693120C0F
54 %CommonAppData%\Skype\Pictures\Ninja Skype.png 10,063 bytes MD5: 0x239A56E1EE9DA25758BE8E0611E1937E
SHA-1: 0x178CE60138BC7B256002304711EABFA03738F597
55 %CommonAppData%\Skype\Pictures\Party Skype.png 11,904 bytes MD5: 0x4236FAADD5FDD3A29D4B1ED8C2E0711C
SHA-1: 0x53B0906BC01D72F1F78523A7256E65340A6DECD5
56 %CommonAppData%\Skype\Pictures\Pop Skype.png 10,599 bytes MD5: 0x6B5A5971E82286FFB738E81D06379505
SHA-1: 0x484D7D43F70EE62DE1DDC965E48935CE89588C64
57 %CommonAppData%\Skype\Pictures\Rice Skype.png 12,155 bytes MD5: 0x24424D6DDF2B34BA4D0884C566EFFF30
SHA-1: 0xF17F2419C561223AC3C19D9979B12B327501FC33
58 %CommonAppData%\Skype\Pictures\Skypahontas.png 11,726 bytes MD5: 0xDA10C9D3AD09DE5A6EF48626171FAFAB
SHA-1: 0x2BEB3B17A943B3FDD08B7B78927C9378E79FA7BD
59 %CommonAppData%\Skype\Pictures\Skype 502.png 26,055 bytes MD5: 0x03C4612F1CC54801E5461166AAAE6E16
SHA-1: 0xEB5D937B30BC90EC08F30408F6D56A364E56DB44
60 %CommonAppData%\Skype\Pictures\Skype Aid.png 10,309 bytes MD5: 0x9BD96D8DF1517B127CEB28DA08C75506
SHA-1: 0x7174BFC78F3380DC03418546F94EB7BB6B951112
61 %CommonAppData%\Skype\Pictures\Skype Artiste.png 23,078 bytes MD5: 0x8E5EE7A75574178865B8F75A57AC09B3
SHA-1: 0xC6A7302E0DD0D6FBB026248DE7E01843972D31D7
62 %CommonAppData%\Skype\Pictures\Skype Beauty.png 10,560 bytes MD5: 0x0BF9310938CE6E3435DF567430285AEA
SHA-1: 0xD7E1BA3520EEDD2C536F735D6BC2A469688DD138
63 %CommonAppData%\Skype\Pictures\Skype Bling.png 13,299 bytes MD5: 0x50894A9AE54BB9FCB983BCB60E3CE697
SHA-1: 0xB3122ACBD75C7FC48CEC70D9D914E9A0B28ED664
64 %CommonAppData%\Skype\Pictures\Skype Boarder.png 14,140 bytes MD5: 0x8E87EEBD9CED5672098FDB89936E027F
SHA-1: 0x2B5EBB6088267BC67C891501E0A3A232C32FC4CE
65 %CommonAppData%\Skype\Pictures\Skype Brrr... .png 16,753 bytes MD5: 0x63C22C6B568D69A6BCF7A4625F2B2297
SHA-1: 0x083FCD444335E8D8E521F6D0C88B16CCAF46FF09
66 %CommonAppData%\Skype\Pictures\Skype Candy.png 10,209 bytes MD5: 0xA1CD540840AF1FF9D5C4FD75F731A3E9
SHA-1: 0xB1CEE0253B77F3C6C0960C9F05A9FC1E680A95E6
67 %CommonAppData%\Skype\Pictures\Skype Cola.png 8,557 bytes MD5: 0xBCA2A44C0B589B9F9B53E7D7F04D39C6
SHA-1: 0xC2DF4C4034CF3770931BF732377FFFEC388462B4
68 %CommonAppData%\Skype\Pictures\Skype Cool Shades.png 7,632 bytes MD5: 0xEAE2CCA87F4EE40C49BF9A02F8F3C43D
SHA-1: 0xB6988569AA07304FEC69C7E066AD1DF77693BBF6
69 %CommonAppData%\Skype\Pictures\Skype Extreme.png 9,602 bytes MD5: 0x3997284EB74FB2D71A9CF57AD408232F
SHA-1: 0x59BFEAE81DAAFFB47B5A0B81FB6ADFBA1455AD4D
70 %CommonAppData%\Skype\Pictures\Skype Goaaaaal.png 9,636 bytes MD5: 0x207C1E1292AF235D7EDF4FA54CE64212
SHA-1: 0xB5BE9D9AAA3ABEE498224F39A9D8E1BE7B5C81E4
71 %CommonAppData%\Skype\Pictures\Skype Headset.png 9,604 bytes MD5: 0xA3DB03146AE64F45180217906767EC1C
SHA-1: 0x5EDE34C47ED26E4E3390F9BF13F157A81EBB2507
72 %CommonAppData%\Skype\Pictures\Skype in a Bag.png 7,339 bytes MD5: 0xB525F2BD3A410D1523549903D63E9FE5
SHA-1: 0x959A59DD6796973ACE5993044A21164D9459D876
73 %CommonAppData%\Skype\Pictures\Skype Jah.png 12,597 bytes MD5: 0xB336310F2C76DADC42730CD77515A0B0
SHA-1: 0xFEEC691FD534B55F8B7BB469C9F110A74210012D
74 %CommonAppData%\Skype\Pictures\Skype Jyve.png 9,817 bytes MD5: 0x8B2B752568FE58F3F5A40D7AA771338B
SHA-1: 0x7E8B3815E53047DE70F0B8ADBFD30B78C87E4A04
75 %CommonAppData%\Skype\Pictures\Skype Safety.png 12,674 bytes MD5: 0x9DF407A009F6C42A8B3EB494E1027CBA
SHA-1: 0x67EF513A7FBB3C1F1706294E7CC54B4F3CAEB8EF
76 %CommonAppData%\Skype\Pictures\Skype San.png 11,471 bytes MD5: 0xD2B60266E57ADFAB15684BEA2CA67498
SHA-1: 0xD99E569F150F6E1E313E85F91BFB0E42052925A9
77 %CommonAppData%\Skype\Pictures\Skype Shorty.png 4,343 bytes MD5: 0x98E3E5EA7B669419B757D8E7D0AAC5CB
SHA-1: 0x7D4160038F3C4E6D15F9DAAE5AF6AF0B6F8988CC
78 %CommonAppData%\Skype\Pictures\Skype Smiley.png 6,663 bytes MD5: 0xC21C9D102F98A2CE6EF4FD85004FB33D
SHA-1: 0x319E209420C19C839E78AC117BED90700F2DCE86
79 %CommonAppData%\Skype\Pictures\Skype Time.png 13,315 bytes MD5: 0x88BE7012315860E0BAB96CEF4C87955A
SHA-1: 0xC125343A1F6990B46A9411DE329AAA2795A73FA2
80 %CommonAppData%\Skype\Pictures\Skype-a-Manger.png 9,077 bytes MD5: 0x09A1207AF41075404A4E9C2076956C13
SHA-1: 0x431FDAF5753BE0FA470AC106268AD86B533A3A37
81 %CommonAppData%\Skype\Pictures\Skype-ahoy.png 13,057 bytes MD5: 0x8B1617D9BC11C8D4424AF9B5E1F3FCAF
SHA-1: 0x11C8D8BB80D1BE936A43D6724A94462207CE11EF
82 %CommonAppData%\Skype\Pictures\Skype-in-one.png 10,816 bytes MD5: 0xC7EDCFC021634AE620B02683B54DACF6
SHA-1: 0x5701BB6DF9B5BB4B7694C1B0BA77570BB9ACBF1F
83 %CommonAppData%\Skype\Pictures\Skype.png 7,695 bytes MD5: 0xCADA508DC4124FFE1E6FA72A4D702108
SHA-1: 0x0F0CE76D84F247E748C5F86BB2E5096F3B50AE7A
84 %CommonAppData%\Skype\Pictures\Skypers of the Caribbean.png 9,786 bytes MD5: 0xBF0EB1C09A56414D07CD6987EAC94351
SHA-1: 0x74AE75ED40639813FE8FC769F33086037E50B16B
85 %CommonAppData%\Skype\Pictures\Star Skype.png 8,075 bytes MD5: 0x2E5C7273C2A4D275D00C62D708082AD6
SHA-1: 0x4F313A5A689DF0238D5F0F2087DAECB7CAE714A7
86 %CommonAppData%\Skype\Pictures\Sushi Skype.png 11,588 bytes MD5: 0x1A7AC5C5478D3484E873DB2C7179ABB3
SHA-1: 0xA66B52B88A051443167406EBE8D88F5D20875641
87 %CommonAppData%\Skype\Pictures\The Skypeness.png 10,252 bytes MD5: 0x893C7B19426AB820E9F299E86E076520
SHA-1: 0x72213065CD65038BD9F279FDA2470149801EBDBC
88 %CommonAppData%\Skype\Pictures\ThinkPad Skype.png 10,844 bytes MD5: 0x14A3442E6469E11C09DD6ABABC4DB369
SHA-1: 0x099ACE427265218B7ED5C701F539E2929EF58589
89 %CommonAppData%\Skype\Pictures\Travel Skype.png 8,565 bytes MD5: 0xF2B3C7E298D7D24245272293DF986320
SHA-1: 0x6BABDDA560F2152CC6F0D60CA930CA46CBDDAB65
90 %CommonAppData%\Skype\Pictures\Wetsuit Skype.png 8,620 bytes MD5: 0xD3EBBD96729EEC00B36734B3FA57ABDC
SHA-1: 0x9AD5ADEF687923E7E5F31C66A6BD6A5C91A0F7C5
91 %CommonAppData%\Skype\Pictures\Yin Yang Skype.png 6,342 bytes MD5: 0x78A8D511ECF9567698A594313787CDA1
SHA-1: 0x45631E857278F837105CC7D986C6AABBCBB80047
92 %CommonAppData%\Skype\Plugins\collection.ini 354 bytes MD5: 0x881AA51FAA8B72716AA5CCEBB50F7DD0
SHA-1: 0x25F1844FB714F798062C90EABD4EC655B48E1B50
93 %CommonAppData%\Skype\Plugins\ipxml.xml 19,743 bytes MD5: 0xB55416D94B8327B80AF9118380321173
SHA-1: 0xE50F1122F6DAE6557634EE2449AB099053BE22E4
94 %CommonAppData%\Skype\Plugins\Local Cache\04B3EC9B2B5945A1B7AFC5FAFC297401_icon48.png 2,229 bytes MD5: 0x4D2F17C20EE11C12254BEB466108C04B
SHA-1: 0x663BDCD08147CB88F85FF10405C91EC007ACE808
95 %CommonAppData%\Skype\Plugins\Local Cache\04B3EC9B2B5945A1B7AFC5FAFC297401_more.jpg 40,605 bytes MD5: 0x6ACF1241E015022900FE61091F4539CB
SHA-1: 0xB6EEB05D8116924E5E0B55F015AA863AD237F854
96 %CommonAppData%\Skype\Plugins\Local Cache\1163D2B46CC742E5A3CC9E4157887751_icon24.png 4,206 bytes MD5: 0xFC68D83D9CF0729CE1786236AA5FB57B
SHA-1: 0xCE0BDF358DF90165641BCD0BB2F694F115329264
97 %CommonAppData%\Skype\Plugins\Local Cache\1163D2B46CC742E5A3CC9E4157887751_icon48.png 3,451 bytes MD5: 0x407FA30F1CA157100155D7A210DD6744
SHA-1: 0x1391E52B1FB88C6CD27F3F8D73838FB302749DCE
98 %CommonAppData%\Skype\Plugins\Local Cache\1163D2B46CC742E5A3CC9E4157887751_more.jpg 10,555 bytes MD5: 0x7D19DA6D4FDF2F039868E74CB281DD54
SHA-1: 0x581CB23C25BFA0187F7FD2F71246AF70560585C5
99 %CommonAppData%\Skype\Plugins\Local Cache\1D5BFC86FB85431BA61248FDB2467411_icon24.png 4,533 bytes MD5: 0x848187BF4814658A125BB938D9E9A84E
SHA-1: 0xCE351599134502752C0FE5C751E49473EC82F029
100 %CommonAppData%\Skype\Plugins\Local Cache\1D5BFC86FB85431BA61248FDB2467411_icon48.png 8,279 bytes MD5: 0xF60AA5C86B95D928333792D0550F8EDD
SHA-1: 0x87349D289511D1DA810A1D61DA721F1CFDE47CC9

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #8][file and pathname of the sample #8]684,032 bytes
Skype.exe%ProgramFiles%\skype\phone\skype.exe25,993,216 bytes
[filename of the sample #4][file and pathname of the sample #4]24,576 bytes
[filename of the sample #5][file and pathname of the sample #5]241,664 bytes
[filename of the sample #6][file and pathname of the sample #6]200,704 bytes
[filename of the sample #9][file and pathname of the sample #9]192,512 bytes
[filename of the sample #7][file and pathname of the sample #7]200,704 bytes
ad.exe%System%\inf\ad.exe3,854,336 bytes
bass-plugins.exe%ProgramFiles%\uusee\bass-plugins.exe188,416 bytes
msc03.exe%System%\config\msc03.exe184,320 bytes
check_cmd.exe%ProgramFiles%\common files\uusee\check_cmd.exe147,456 bytes
uuplayer.exe%ProgramFiles%\common files\uusee\uuplayer.exe32,768 bytes
uuupgrade.exe%ProgramFiles%\common files\uusee\uuupgrade.exe249,856 bytes
msc03.exe%System%\inf\msc03.exe184,320 bytes
[filename of the sample #1][file and pathname of the sample #1]22,294,528 bytes
[filename of the sample #2][file and pathname of the sample #2]634,880 bytes

Module NameModule FilenameAddress Space Details
[filename of the sample #3][file and pathname of the sample #3]Process name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x3E0000 - 0x3E8000
skmsg.dll%ProgramFiles%\Skype\Phone\skmsg.dllProcess name: Skype.exe
Process filename: %ProgramFiles%\skype\phone\skype.exe
Address space: 0x10000000 - 0x10013000

Service NameDisplay NameStatusService Filename
ProtectedStoragerProtected Storage Manager"Running"%System%\svchost.exe -k netsvcs

Service NameDisplay NameNew StatusService Filename
MSIServerWindows Installer"Running"%System%\msiexec.exe /V

 

Registry Modifications

 

Other details

PortProtocolProcess
1048UDPSkype.exe (%ProgramFiles%\Skype\Phone\Skype.exe)
1049UDPSkype.exe (%ProgramFiles%\Skype\Phone\Skype.exe)
1050UDPSkype.exe (%ProgramFiles%\Skype\Phone\Skype.exe)

Remote HostPort Number
push.cpushpop.com1044

Server NameServer PortConnect as UserConnection Password
bar.baidu.com80(null)(null)
firefox.cnppaa.cn80(null)(null)

URL to be downloadedFilename for the downloaded bits
http://soft.c393c.cn/newup3.txt%Windir%\TEMP\~ups.log

 

 

Downloaded Files Summary (Generation #2):

What's been foundSeverity Level
Downloads/requests other files from Internet.
Registers a 32-bit in-process server DLL.
Registers a Browser Helper Object (Microsoft's Internet Explorer plugin module).
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Security RiskDescription
Trojan.Adclicker!sd6 Trojan.Adclicker!sd6 is a malicious program that does not infect other files but may represents security risk for your computer and/or network environment.
Adware.Agent Adware.Agent will display advertisements on an infected system.

Threat CategoryDescription
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment
A potentially unwanted adware program designed to deliver various advertisements to the users' systems

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 [file and pathname of the sample #1] 188,416 bytes MD5: 0xD4BD08B05A2EB33566F839AD5EC5BFE3
SHA-1: 0x767DE3FE9E2B9A552C9D373F8C9F901FD9464B77
(not available)
2 [file and pathname of the sample #2] 69,632 bytes MD5: 0x6C5F6417C6174C95DE463D7265BDBD33
SHA-1: 0x6D054FEAA36A9FE5C91600925129154BCC5F0C61
Trojan.Adclicker!sd6 [PCTools]
Trojan.Adclicker [Symantec]
not-a-virus:AdWare.Win32.Agent.bmt [Kaspersky Lab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]188,416 bytes

Module NameModule FilenameAddress Space Details
[filename of the sample #2][file and pathname of the sample #2]Process name: [generic host process]
Process filename: [generic host process filename]
Address space: 0x3E0000 - 0x3F1000

 

Registry Modifications

 

Other details

China

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2010 ThreatExpert. All rights reserved.