Home Malware Programs Trojans Orsam!rts

Orsam!rts

Posted: November 30, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 10,495
First Seen: November 30, 2010
Last Seen: June 17, 2023
OS(es) Affected: Windows

Aliases

Trj/Thed.V [Panda]Generic4_c.BSJR [AVG]W32/Dll.B!tr.pws [Fortinet]Gen.Trojan.Heur [Ikarus]Worm/Win32.FlyStudio [AhnLab-V3]TROJ_GEN.RCBOCHS [TrendMicro]Mal/PWSDLL-B [Sophos]W32.Trojan.Black [ClamAV]Win32.Packed.Vmpbad [eSafe]W32/SuspPack.BQ.gen!Eldorado [F-Prot]Generic.tfr!o [McAfee]Trojan.Obfuscator.xz [CAT-QuickHeal]W32/Banload.BKPU!tr.dldr [Fortinet]Win32/Banker.GOX [eTrust-Vet]Trojan.Siggen2.37666 [DrWeb]
More aliases (2529)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Desktop\projet de fin d'étude\flach\PFE1\flach\Proteus 7.6\Crack\LXK Proteus 7.6 SP0 v2.0.1.exe File name: LXK Proteus 7.6 SP0 v2.0.1.exe
Size: 34.98 KB (34980 bytes)
MD5: 6ba80e788821944a0e22fb62ca731b25
Detection count: 349
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\projet de fin d'étude\flach\PFE1\flach\Proteus 7.6\Crack\LXK Proteus 7.6 SP0 v2.0.1.exe
Group: Malware file
Last Updated: January 14, 2023
C:\Windows\SysWOW64\drivers\capusot.sys File name: capusot.sys
Size: 90.11 KB (90112 bytes)
MD5: e8c20f3175825ddb7d08d241868708bf
Detection count: 201
File type: System file
Mime Type: unknown/sys
Path: C:\Windows\SysWOW64\drivers\capusot.sys
Group: Malware file
Last Updated: June 4, 2023
%SystemDrive%\RECYCLER\S-1-5-21-839522115-1177238915-725345543-1004\$006dc3e42577c36147eed312bd380fa4\n. File name: n.
Size: 57.34 KB (57344 bytes)
MD5: a928ac4e1a34c4eb035b4ed6a8f7a6cb
Detection count: 108
Path: %SystemDrive%\RECYCLER\S-1-5-21-839522115-1177238915-725345543-1004\$006dc3e42577c36147eed312bd380fa4
Group: Malware file
Last Updated: December 17, 2012
%WINDIR%\system32\fastsrch.dll File name: fastsrch.dll
Size: 123.39 KB (123392 bytes)
MD5: 6de2f50a9a3aa8cf2c56800c1288462f
Detection count: 84
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 17, 2012
%APPDATA%\74A7.exe File name: 74A7.exe
Size: 58.36 KB (58368 bytes)
MD5: 3ec149822ca0219287b9217448a68bc9
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 8, 2013
%USERPROFILE%\kfphavn.exe File name: kfphavn.exe
Size: 33.28 KB (33280 bytes)
MD5: 4501cf0b9b18b5eb60782d7c03ff998a
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: April 17, 2013
%SystemDrive%\LogShos\Live.exe File name: Live.exe
Size: 378.36 KB (378368 bytes)
MD5: 08b8ffff3aa256c97ea62004cec5b7a6
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\LogShos
Group: Malware file
Last Updated: April 29, 2013
%SystemDrive%\config.bin\9A052F9196D.exe File name: 9A052F9196D.exe
Size: 401.92 KB (401920 bytes)
MD5: 8e2a22344811e3bc49b62a65a3d3d2f4
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\config.bin
Group: Malware file
Last Updated: November 29, 2012
C:\Windows\SysWOW64\drivers\SHXLock.sys File name: SHXLock.sys
Size: 5.5 KB (5504 bytes)
MD5: f40d82484b87d9a31b909c473abb0b1d
Detection count: 35
File type: System file
Mime Type: unknown/sys
Path: C:\Windows\SysWOW64\drivers\SHXLock.sys
Group: Malware file
Last Updated: September 12, 2022
%USERPROFILE%\tc_.exe File name: tc_.exe
Size: 194.04 KB (194048 bytes)
MD5: b7e57da4c27701ffc59e98d5ec445f72
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: January 28, 2013
%WINDIR%\system32\xlaunch.exe File name: xlaunch.exe
Size: 2.83 MB (2836332 bytes)
MD5: 81a9fe3616cb0050db09e0b4d629d33c
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 6, 2012
%LOCALAPPDATA%\{56C1A2E7-F781-4FCA-A660-F847BF2550C7}\mem.exe File name: mem.exe
Size: 397.68 KB (397682 bytes)
MD5: 348c39acf0e8ab6037324bc0266c04bc
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\{56C1A2E7-F781-4FCA-A660-F847BF2550C7}
Group: Malware file
Last Updated: April 29, 2013
%USERPROFILE%\6qhr47y7cp.exe File name: 6qhr47y7cp.exe
Size: 19.16 KB (19160 bytes)
MD5: e27015e38a62af7e89b9fcc21945c54a
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: April 8, 2013
%SystemDrive%\RECYCLER\S-1-5-21-57989841-630328440-1801674531-1003\$5afc4fbcf7e52eb2030b250d777f4919\n. File name: n.
Size: 54.27 KB (54272 bytes)
MD5: 323b8614e3ca39a90e9639700f64688e
Detection count: 12
Path: %SystemDrive%\RECYCLER\S-1-5-21-57989841-630328440-1801674531-1003\$5afc4fbcf7e52eb2030b250d777f4919
Group: Malware file
Last Updated: December 26, 2012
%USERPROFILE%\ztdf.exe File name: ztdf.exe
Size: 245.76 KB (245760 bytes)
MD5: d5a81196d047c3f215abb1ef8a8adaac
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: June 19, 2020
%USERPROFILE%\Documents\crss.exe File name: crss.exe
Size: 44.03 KB (44032 bytes)
MD5: 042a2fc533aba7b9fc0f821399f1798a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Documents
Group: Malware file
Last Updated: March 12, 2013
%APPDATA%\46.exe File name: 46.exe
Size: 216.66 KB (216664 bytes)
MD5: 0c3f9e01d87e398cc52bcfbfe31af8ff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 22, 2013
%APPDATA%\ldr.mcb File name: ldr.mcb
Size: 175.1 KB (175104 bytes)
MD5: 56dd1c7c901d62359545fbf4b3bef19d
Detection count: 5
Mime Type: unknown/mcb
Path: %APPDATA%
Group: Malware file
Last Updated: March 6, 2013
%APPDATA%\fontcache.exe File name: fontcache.exe
Size: 198.14 KB (198144 bytes)
MD5: 9ee7c4e223c5859d112a1d9933d3e5e5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 13, 2013

More files
Loading...