PE:Malware.XPACK-LNR/Heur!1.5594 also known as PUP.Optional.InstallCore.A, RDN/Generic.hra!bw, Trojan.Win32.Generic!BT.
Malware Analysis of PE:Malware.XPACK-LNR/Heur!1.5594
Created files:
%Common Startmenu%\Programs\FlvPlayer\FlvPlayer.lnk
%Common Startmenu%\Programs\FlvPlayer\Uninstall.lnk
%Appdata%\FlvPlayer\FLVPlayerApp.exe
%Appdata%\FlvPlayer\uninstall.exe
%Local Appdata%\Google\Chrome\User Data\Default\Cache\f_0000a1
Autostart registry keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FlvPlayer\DisplayName: “FlvPlayer”
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FlvPlayer\UninstallString: “%Appdata%\FlvPlayer\uninstall.exe”
Detected by UnHackMe:
FLVPLAYERAPP.EXE
Default location: %APPDATA%\FLVPLAYER\FLVPLAYERAPP.EXE
Dropper hash(md5): abb71a856f8cbbb8de875a653110f2c5