Troj/PWS-BSF

Category: Viruses and Spyware Protection available since:15 Jun 2011 03:05:12 (GMT)
Type: Trojan Last Updated:18 Aug 2013 15:51:49 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/PWS-BSF include:

Example 1

File Information

Size
139K
SHA-1
0067cec735cdcf8b443d60709b31592a8f597158
MD5
fe252640cb3154f2f871b6013a52612c
CRC-32
4fe2d8ab
File type
Windows executable
First seen
2007-05-07

Other vendor detection

Kaspersky
Trojan-Spy.Win32.Zbot.biwp

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Application Data\Uniw\ytbi.exe
    Size
    139K
    SHA-1
    fe8002c8642256e98dd7efd1bd385a36043a6c46
    MD5
    b215e9bab15e5ca78113feec38b8c120
    CRC-32
    fcdc8fed
    File type
    application/x-ms-dos-executable
    First seen
    2012-07-02
Processes Created
  • c:\windows\system32\cmd.exe

Example 2

File Information

Size
138K
SHA-1
00ecc3e417351522b0d03f49c20651cb4759b5c0
MD5
b81a2e611055700cff409d18cb2d9d67
CRC-32
ddc47dbf
File type
Windows executable
First seen
2012-02-20

Other vendor detection

Kaspersky
Trojan-Spy.Win32.Zbot.bopd

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Application Data\Vaguul\resox.exe
    Size
    138K
    SHA-1
    84bd60eaa5e01d4d6888ae789582c3fda4eb0c27
    MD5
    09833a7720934d551eb12d072f6d4c6a
    CRC-32
    6efbf606
    File type
    application/x-ms-dos-executable
    First seen
    2012-02-20
Processes Created
  • c:\windows\system32\cmd.exe

Example 3

File Information

Size
139K
SHA-1
028a92b44c33cf15bd27e5a2b1053130164874e3
MD5
4e47208ec38249df74bafc83b0463ed4
CRC-32
9b93fb78
File type
Windows executable
First seen
2013-06-16

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Application Data\Fuof\ytyt.ude
  • c:\Documents and Settings\test user\Application Data\Icnoh\ovwyp.exe
    Size
    139K
    SHA-1
    4d1877558172b9b09e2c0487564c8e430133744d
    MD5
    613be11262ff868f5b02fa7c129d9ce9
    CRC-32
    0044ec2b
    File type
    Windows executable
    First seen
    2013-06-16
  • c:\Documents and Settings\test user\Application Data\Fuof\ytyt.tmp
Modified Files
  • %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Inbox.dbx
  • %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Offline.dbx
  • %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Folders.dbx
Registry Keys Created
  • HKCU\Identities
    Identity Login
    0x00098053
  • HKCU\Software\Microsoft\Internet Explorer\Privacy
    CleanCookies
    0x00000000
  • HKCU\Software\Microsoft\Waib
    Ywvyipre
    I□□□□□□□□pi□□□□□/□□_□□□@□□□□□□G□pk□P□□□f□ i□□□□□e□@□□□□□□_□□□□□n□@v□□0□ #□0□□□U□`L□□T□□□□0□□ □□□;□P:□□x□□Z□□=□@q□□□□□z□□□□□C□□□□□□□□□□□□□@□□p□□0□□`^□□□□□□□□@□@□□ t□□9□□□□□2□
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    {685D52B1-D770-AE83-BA7F-1342B4F1EDD5}
    "c:\Documents and Settings\test user\Application Data\Icnoh\ovwyp.exe"
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
    1609
    0x00000000
  • HKCU\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Software\Microsoft\Outlook Express\5.0
    Compact Check Count
    0x00000008
  • HKCU\Software\Microsoft\Windows\CurrentVersion\UnreadMail\user@example.com
    TimeStamp
    52 a6 c0 5a 98 6a ce 01
Processes Created
  • c:\Documents and Settings\test user\application data\icnoh\ovwyp.exe
HTTP Requests
  • http://itsyoursolution.hebergement-anonyme.com/web/cfg.bin
DNS Requests
  • itsyoursolution.hebergement-anonyme.com

download Try Sophos products for free
Download now