I have accidentally deleted ( again during the execution of copy / paste operations and an unexpected imposed log off 88) ) my previous post ! :-\ If somebody had already checked it , please give me a short info . Thank you !!! >>> Advanced File Analysis System | Valkyrie VT : VirusTotal >>> My final Verdict is NOT Clean !!! But sometimes it´s just a question off definition … ! ![]()
Two new Files :
Human Expert Analysis = Clean >>> Advanced File Analysis System | Valkyrie
VT : VirusTotal
My Analysis Verdict = Not Clean - PUA.Variant.InstallCore
Some suspicious/malicious indicators : Matched Compiler/Packer signature ( Borland Delphi 4.0. ) , File has multiple PE Anomalies ( File contains more then 8 sections , PE file contains zero-size sections , PE Parsing in Sections “bss” , “tls”, “reloc” ) , File Code is packed and obfuscated , Reads the registry for installed applications , Scanning for window names , Scans for the windows taskbar , Contains ability to lookup the windows account name , Contains ability to reboot/shutdown the operating system , Opens the Kernel Security Device Driver , Found a known API Export symbol ( Found reference to API SHGetFolderPathA[at]SHFOLDER.DLL at PID 00002728 ) , Drops mutiple executable files , Drops executable files to the Windows system directory ( File type “VAX-order 68k Blit mpx/mux executable” was dropped at “%WINDIR%\Tasks\CouponViewer Toolbar.job” ) , Process drops a File with positive VT detection >>> “CVHP.exe” >>> VirusTotal , Creates named pipes for inter-process communication ( CreateNamedPipeA[at]KERNEL32.DLL at PID 00002728 & CreateNamedPipeA[at]KERNEL32.DLL at PID 00002800 ) , Installs hooks/patches the running process ( “regsvr32.exe” wrote bytes to address “0x76FE1000” ( part of NSI.DLL )
Dropped File :
Human Expert Analysis = Clean >>> Advanced File Analysis System | Valkyrie
VT : VirusTotal
My Analysis Verdict = Not Clean - PUA.Adware.Elex
Some suspicious/malicious indicators from the dropped File “CVHP.exe”: Found many suspicious Strings in file hex table , Matched Compiler/Packer signature ( VC8 → Microsoft Corporation ) , PE file contains unusual section name , Reads the active computer name , File Code is packed and obfuscated , Contains ability to lookup the windows account name , Tries to create guarded memory sections , Reads the registry for installed applications , Opens the Kernel Security Device Driver , Found API Hooks , Drops executable files ( CouponViewer Toolbar.job" has type "VAX-order 68k Blit mpx/mux executable ) , File querries the “Windows Internet library” and “Event Log” , File querries sensitive Browser settings (IE) ,