Home > malware > Malware Report: dbabf61e953cd55a799e0490eebb2f9fbe47c0c2

Malware Report: dbabf61e953cd55a799e0490eebb2f9fbe47c0c2

November 10th, 2009 xandora Leave a comment Go to comments

File SHA1: dbabf61e953cd55a799e0490eebb2f9fbe47c0c2
File MD5 : a8dd09fa7f968e5b085da420e366c493
File Type: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
Date: Tue Nov 10 00:45:21 MYT 2009
Possible Malware: YES

#– Files Created: –

/Documents and Settings/All Users/Application Data/Microsoft/Dr Watson
/WINDOWS/Temp/VRT1.tmp
/WINDOWS/system32/lowsec
/WINDOWS/system32/sdra64.exe

#– Registry Created: –

[SOFTWARE]
+ [software\Microsoft\PCHealth\ErrorReporting\ExclusionList]
+ [software\Microsoft\PCHealth\ErrorReporting\InclusionList]
[SYSTEM]
[SECURITIES]
[DEFAULT]
[NTUSER]

#– Malware Traffic – DNS: –

colopin.cn
irc.zief.pl

#– Malware Traffic – Connections: –

218.93.205.30.80
91.206.201.39.80

#– Malware Traffic – www: –

colopin.cn/oc/box.txt

#– Screenshots: –

Screen After 90 Seconds

Screen After 120 Seconds

Categories: malware Tags:
  1. No comments yet.
  1. No trackbacks yet.