Virus Characteristics
| File Property | Property Value |
| FileName | spotify.exe |
| McAfee Artemis | Artemis!5e7b3aa525fa
|
| McAfee Detection | W32/IRCbot.gen.z |
| Length | 2,592,656 bytes |
| CRC | 6A5781CD |
| MD5 | 5E7B3AA525FAF3F74E486E7FCB080A88
|
| SHA1 | 2DFD88E43DDAC37E455BFBC9BB4C63E5B89010B5
|
Other Common Detection Aliases
| Company Name | Detection Name |
| F-Prot | ~W32/Heuristic-210!Eldorado
|
| rising | Packer.Win32.UnkPacker.b [Suspicious]
|
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Enumerates running processes
| Medium |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\spotify.exe
The following files have been added to the system:
%USERPROFILE%\application data\spotify%USERPROFILE%\local settings\application data\spotify%USERPROFILE%\local settings\application data\spotify\storage%USERPROFILE%\local settings\application data\spotify\storage\index.dat
The following registry elements have been created:
HKEY_LOCAL_MACHINE\software\classes\spotify\shell\open\ddeexec\HKEY_LOCAL_MACHINE\software\classes\spotify\shell\open\ddeexec\application\HKEY_LOCAL_MACHINE\software\classes\spotify\shell\open\ddeexec\ifexec\HKEY_LOCAL_MACHINE\software\classes\spotify\shell\open\ddeexec\topic\