Archive for the 'BitDefender' Category

2010-02-23 detected threat file qbl.exe; tml.exe; dc3yh.exe;

qbl.exe; tml.exe; dc3yh.exe; herss.exe; win.exe; riukhcpkfqnzxnfyhl.exe; riukhcpkfqnzxnfyhl.exe; piwonkzwtgfttlfalrlv.exe; cuhywsgcykivuleying.exe; user.exe; system.exe; hjr.exe; uqnxzi.exe; evh.exe; herss.exe; 382.exe; jql.exe; svchost.com; 15515522.exe; zb1.exe; svchost.exe; dc3yh.exe; svchost.exe; hlx.exe; herss.exe; herss.exe; e.exe; svchost.com; rjvjlsvw.exe; rjvjlsvw.exe; rsbyii.exe; 589.exe; svchost.com; setuper.exe; rjvjlsvw.exe; 886.exe; 441.exe; wingymi.exe; wingpssc.exe; rjvjlsvw.exe; hhh.exe; 836.exe; jhh.exe; qbl.exe; tml.exe; winchhy.exe; litufi.exe; winjrmi.exe; winnnac.exe;

rootkit.win32.tdss.c

Threat Name: rootkit.win32.tdss.c
Spread Method:
Windows Vulnerability
USB Disk
Threat type:rootkit.win32
rootkit.win32.tdss.c first detected:2010-02-09
Virus file known is driver file *.sys written in C
File Size:285K Bytes.
Behavior:Add/modify system registry key parameter
Level of Spread:2
Level of Threat:4
Reported Path:C:\Winnt\
MD5:X1vTV3DJtQ68R8YvP7glmCUBki05I2q2
SHA1..:g48ceSLrcy62a8h8xE567Kdj65KYqP852UG12bt0

Virus files on 0207 as chsftrn.exe and bnagthly.exe

herss.exe; fn1.exe; herss.exe; ssr.exe; vs60wiz.exe; pn1.exe; incognito.exe; herss.exe; lds.exe; userjhwm.exe; wincnrstw.exe; winvnios.exe; setupv.exe; ldm1.exe; fn1.exe; ssr.exe; veasdy.exe; winrbnr.exe; wincsylge.exe; w2a1233.exe; vmdylv.exe; v3exclv.exe; pn1.exe; incognito.exe; lds.exe; nqiygi.exe; winmcmg.exe; userjhwm.exe; sshnas21.dll; awl.exe; awk.exe; smkiiz.exe; vobmerge251.exe; veb8iqoz.exe; jjd70g7h.exe; 03fyyliu.exe; 1ioetzzo.exe; yditvmj.exe; xoledbl.dll; wkxnwy.exe; tsryxtr.exe; smg.dll; oxxm.exe; kkalf.exe; putty.exe; 6jh25cic.exe; rayv.dll; pxtdypob.sys; pwrirfoc.sys;

mcenspc.dll - mcenspc.dll removal

mcenspc.dll - mcenspc.dll removal
Threat Name: mcenspc.dll
Spread Method:
Connection to Specific Sites
File Creation
Threat type:mcenspc
mcenspc.dll first detected:2010-02-04
Virus file known is Script file written in php
File Size:380K Bytes.
Behavior:launched itself automatically each time the system is booted
Level of Spread:1
Level of Threat:1
Reported Path:C:\Program Files\
MD5:C8K8AXymXd2cV3tRTIB2Ro51PuWtm04j
SHA1..:kASYIf25glN3e30acQjPawXFw1F0uC46sibHq4IV

sysguard.exe and sysguard.exe removal

sysguard.exe and sysguard.exe removal
Threat Name: sysguard.exe
Spread Method:
Instant Message(MSN,Gtalk,QQ etc.)
Threat type:sysguard
sysguard.exe first detected:2010-02-04
Virus file known is Unkown type
File Size:591K Bytes.
Behavior:Add/modify system registry key parameter
Level of Spread:6
Level of Threat:5
Reported Path:C:\Documents and Settings\All Users\Application Data\
MD5:U5VM34b7032ip2n5M2mWCD6460Ysh8xH
SHA1..:wWdoSU303SPjxQoXnNufkl0TAJg05H2Ofx4vtvRK

mfevtps.exe and mfevtps.exe removal

mfevtps.exe and mfevtps.exe removal
Threat Name: mfevtps.exe
Spread Method:
Malware Installation
Threat type:mfevtps
mfevtps.exe first detected:2010-02-04
Virus file known is dll file written in C language
File Size:386K Bytes.
Behavior:Creat files in Documents and Settings\[Users]\Local Settings\Temp\
Level of Spread:2
Level of Threat:4
Reported Path:Unkonow path
MD5:35uK52R37UoocJ1MpxC3wn6qDuP5J3m4
SHA1..:581s8NaQ1C5p3rNuqydSx506l1xWr647YHK7Fvby

deploytk.dll and deploytk.dll removal

Threat Name: deploytk.dll
Spread Method:
Connection to Specific Sites
Threat type:deploytk
deploytk.dll first detected:2010-02-04
Virus file known is dll file written in Basic
File Size:361K Bytes.
Behavior:launched itself automatically each time the system is booted
Level of Spread:4
Level of Threat:2
Reported Path:D:\Windows\
MD5:wk4k4Al5s5iwH12vou10Dq0H320nx78m
SHA1..:f476Tb6Y0X6xp45181M3ksKp6O35aEG747EBu3Ba

Latest viruses files detected on 2010-0202

w976ba.exe; iqaat.exe; winpgsnhk.exe; w92445.exe; vkq.exe; kbtx.exe; winvluouk.exe; wineorubf.exe; monfde.exe; rm0.exe; lw1.exe; c.exe; winyajq.exe; wae425.exe; lmpr.exe; pvb.exe; winyajfib.exe; zaist.exe; wyeke-wyekefrez.exe; winxaqbcl.exe; sfiagj.exe; vxpe.exe; rkverify.exe; webfettiinst.exe; appsetup.exe; 30422415.exe; winuomog.exe; 320.exe; 097.exe; synsql.exe; pbpbhf.exe; onlybelief.exe; mbam-setup.tmp; dvx.exe; wyrh.exe; wrugiww.exe; aebwttf.exe; cbss.dll; nxx.exe; sshnas21.dll; nxz.exe; sdra64.exe; cbr0wqsc.exe; younwnoa.dll; wwwpos32.exe; glb1a2b.exe; ywiseext.dll; ywiseext.dll; alsysio.sys;

iastor.sys

Threat Name: iastor.sys
Spread Method:
External Storage Device (USB Device etc.)
Threat type:iastor
iastor.sys first detected:2010-01-31
Virus file known is driver file *.sys written in C
File Size:547K Bytes.
Behavior:Add program s process
Level of Spread:6
Level of Threat:1
Reported Path:Unkonow path
MD5:843xxsY7Dyor0m73atlFFA0v1GO6cNEp
SHA1..:HTS220bDl25tJ51Q276nnbI1LowB3vm6pCtO4J3l

not-a-virus:AdWare.Win32.BadBar.f

Threat Name: not-a-virus:AdWare.Win32.BadBar.f
Spread Method:
Download From website
Threat type:not-a-virus:AdWare.Win32
not-a-virus:AdWare.Win32.BadBar.f first detected:2010-01-30
Virus file known is driver file *.sys written in C
File Size:570K Bytes.
Behavior:Unknow behavior
Level of Spread:6
Level of Threat:1
Reported Path:D:\Documents and Settings\[Users]\Local Settings\Temp\
MD5:A4L8×6A7Eaps0n830t4GGb0w1HP7dOFq
SHA1..:IUt22BcEl35uK52R37UoocJ1MpxC3wn6qDuP5J3m