Mal/Cleaman-B

Category: Viruses and Spyware Protection available since:03 Feb 2012 04:57:32 (GMT)
Type: Malicious behavior Last Updated:11 Apr 2014 21:25:11 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Mal/Cleaman-B include:

Example 1

File Information

Size
53K
SHA-1
0011ba8be8daf49f061819d2f594c4f7e4c2305f
MD5
c9460b78f3f344b5f1bbd427d3d19f7c
CRC-32
4d82cf65
File type
Windows executable
First seen
2012-07-05

Runtime Analysis

Processes Created
  • c:\windows\system32\svchost.exe

Example 2

File Information

Size
120K
SHA-1
0018ae4807157ae24c71e409c0f04b7ba8463c7b
MD5
3be086e148300bf764ca0a3d5865a1d4
CRC-32
56f636e8
File type
application/x-ms-dos-executable
First seen
2012-02-03

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\xzipirymydeakcuapmiiscpdeewnkqyv2\svcnost.exe
Dropped Files
  • c:\Documents and Settings\test user\Application Data\ntuser.dat
  • C:\WINDOWS\system32\drivers\etc\hosts
Modified Files
  • %PROFILE%\Application Data\desktop.ini
    • Changed the file contents
    • Set the system and archive flags
  • %SYSTEM%\drivers\etc\hosts
    • Changed the file contents
Registry Keys Created
  • HKCU\Software\Microsoft\Internet Explorer\LowRegistry
    SavedLegacySettingsML
    42□□5□P6□ 6□□
  • HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
    c:\Documents and Settings\test user\Application Data\xzipirymydeakcuapmiiscpdeewnkqyv2\svcnost.exe
    c:\Documents and Settings\test user\Application Data\xzipirymydeakcuapmiiscpdeewnkqyv2\svcnost.exe:*:Enabled:ldrsoft
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    Windows Init
    "c:\Documents and Settings\test user\Application Data\xzipirymydeakcuapmiiscpdeewnkqyv2\svcnost.exe"
Processes Created
  • c:\Documents and Settings\test user\application data\xzipirymydeakcuapmiiscpdeewnkqyv\svcnost.exe
IP Connections
  • 89.149.243.6:80
  • 89.149.244.130:80
DNS Requests
  • uxeny.ru

Example 3

File Information

Size
180K
SHA-1
001bac27036180b9a375bd096dcacb2c1904c2d0
MD5
4ea2cbd7db703d2fd30e5151c608d215
CRC-32
52e1c90d
File type
Windows executable
First seen
2013-01-09

Runtime Analysis

Registry Keys Created
  • HKCU\Software\WinRAR
    HWID
    {C□PD□P1□`E□0-□`2□`E□□4□□6□□-□□F□05□□3□□4□P3□ B□□2□@7□0}□
DNS Requests
  • www1.geoborders.com

download Try Sophos products for free
Download now