# | Filename(s) | File Size | File Hash | Alias |
1 | %Temp%\BClib\dp1.fne
%Temp%\E_4\dp1.fne | 114,688 bytes | MD5: 0x6D4B2E73F6F8ECFF02F19F7E8EF9A8C7
SHA-1: 0x09C32CA167136A17FD69DF8C525EA5FFECA6C534 | Trojan.Autorun.kku [PCTools]
W32/AutoRun-MO [Sophos]
Trojan.Win32.AutoRun [Ikarus] |
2 | %Temp%\BClib\Exmlrpc.fne
%Temp%\E_4\Exmlrpc.fne | 73,728 bytes | MD5: 0xF79EE77A4F30401507E6F54A61598F58
SHA-1: 0x7F3EF4945F621ED2880FF5A10A126957B2011A17 | (not available) |
3 | %Temp%\BClib\krnln.fne
%Temp%\BClib\krnln.fnr
%Temp%\E_4\krnln.fnr | 417,792 bytes | MD5: 0x7567BA52775AA0A1A9B88D873479BD56
SHA-1: 0xD0E93B703C23CD77A1AC02BDAA496A0F9095CF61 | packed with UPX [Kaspersky Lab] |
4 | %ProgramFiles%\Kuivccccs\srvany.exe | 8,192 bytes | MD5: 0x4635935FC972C582632BF45C26BFCB0E
SHA-1: 0x7C5329229042535FE56E74F1F246C6DA8CEA3BE8 | (not available) |
5 | %FontsDir%\e452c71ecd05de415019165b3142ffc6.dat
%System%\Aoucnzrvo.exe
[file and pathname of the sample #1] | 771,158 bytes | MD5: 0x43C50D3D73E385288DBD8B75DBB86307
SHA-1: 0xD0568F7CFECDFDF8A6797EF2C36702493B1482F4 | BackDoor-DRV.gen.c [McAfee] |
6 | %System%\Aoucnzrvo.dll | 2,638,848 bytes | MD5: 0x3C93BDC268EFF119C3A3930F77030748
SHA-1: 0x1390435DD3BDDF6E35CCE020857160DAF6C72693 | Troj/DwnLdr-HRL [Sophos] |