Archive for the 'BitDefender' Category

Latest Worm, Trojan and Backdoor Files Report On 20110124

wingvpdx.exe; winfjlgwo.exe; winfbcomp.exe; windnow.exe; wincnpuqa.exe; winbdm.dll; winafpisw.exe; wihbao.exe; wcc8116.exe; wa7dca.exe; w9110b.exe; w8e141.exe; w87393.exe; w61914b.exe; w3536dd.exe; w311648.exe; w2d56ef.exe; w29481d.exe; w26609aa.exe; w23367df.exe; uusee8675.exe; tsjs.exe; tdan.exe; sxdy.exe; sssm.exe; spwkq.exe; qgyxj.exe; oucw.exe; nhhrb.exe; msct.exe; mlpwtg.exe; mao8675.exe; ldbi.exe; jlfxh2ro.exe; humk.exe; gua8675.exe; gtxtuf.exe; gtapi_signed.dll; fuydu.exe; etolpbsyjo.exe; etdq.exe; bnet.exe; 345.exe; daohang.exe; a2s4f6.exe; 90e5.exe; 6015tcpqgyxj.exe; 230043.exe; 1087tcpdaohang.exe;

juzjf.exe

We suggest you to remove juzjf.exe from your computer as soon as possible.
juzjf.exe sample submitted on 2010-12-07 and identified as a threat.
Alias:
Threat File:juzjf.exe
Submit time:2010-12-07
Excute time:1 min 3 sec
Level of Spread:2
Level of Threat:5
type:Trojan-Downloader.Win32.FraudLoad
Filesize:58K Bytes
Files type
juzjf.exe is Windows exe file.
MD5:2g6647Qx7d2W0617oGbavV6YcKo8Iyed

Latest Worm, Trojan, Backdoor Virus Files Report On 20101207

9207.exe; 8437.exe; 3909.exe; 13876.exe; rljlz.exe; oekx.exe; gimouhur.exe; ltzqai.exe; msfteml.dll; msftcore.dll; adobeupdate.exe; winscrnv.exe; 731.exe; 252.exe; winsvcrn.exe; vougukypot.exe; lotufour.exe; gymmurit.exe; juzjf.exe; wincdsvn.exe; xtumg.exe; 2756318.exe; sesdessecetra.exe; ooyjsp.exe; ikbanw.exe; dvadessest.exe; 708.exe; 360vsqnl.exe; uvla.exe; uvla.exe; cf1.exe; qz1.exe; fqrksgvxcf.dll; cxhrjhuxpe.dll; dvdcepoyrb.exe; wve.exe; wsh.exe; jki.exe; wvd.exe; wfl.exe; jkh.exe; yoj.exe; wscsvc32.exe; wnddsl.exe; wmsdk64_32.exe; wicfte.exe; wcjcl8.exe; temp_01.exe;

Backdoor.Win32.Inject.hbd

Backdoor.Win32.Inject.hbd created following files C:\Program Files\Common Files\UServer.exe
C:\Windows\MyInformations.ini, C:\Windows\System32\URAT.dll. And it modify the register as HKLM\System\CurrentControlSet\Services\URATrkb\DisplayName = “Microsoft Device Manager”
HKLM\SYSTEM\CurrentControlSet\Services\URATrkb\Description = “监测和监视新硬件设备并自动更新设备驱动。”
HKLM\Software\URATrkb\Parameters\ServiceDll = “C:\Windows\System32\URAT.dll”
Threat Name: Backdoor.Win32.Inject.hbd
Spread Method:
Instant Message(MSN,Gtalk,QQ etc.)
Network Spread
External Storage Device (USB Device etc.)
Threat type:Backdoor.Win32
Backdoor.Win32.Inject.hbd first detected:2010-12-02
Virus file known is PE EXE file written in C++
File Size:296K Bytes.
Behavior:False Instant Message
Level of Spread:6
Level [...]

Latest Infected Virus Files In General On 20101115

xwojbokyax.dll; wxtfqiwljq.exe; 18046.exe; ksafe.exe; se2010.exe; svshotz.exe; explore.exe; dwh.exe; dsoqq0.dll; dsoqq.exe; dsoqq.exe; iexplore.exe; spider.exe; ifconfigprofiles.exe; pcvaccineu.exe; bestboanmon.exe; bestboancfg.exe; bestboan.exe; uxiroquqofolinin.dll; ucavarukur.dll; ymrvsoddlta.exe; uxiroquqofolinin.dll; ucavarukur.dll; uxiroquqofolinin.dll; ucavarukur.dll; srpz20.dll; msr950.dll; msiwow.exe; uxiroquqofolinin.dll; ucavarukur.dll; msiwow.exe; csnp2uvc.dll; uxiroquqofolinin.dll; ucavarukur.dll; uxiroquqofolinin.dll; ucavarukur.dll; uxiroquqofolinin.dll; ucavarukur.dll; uxiroquqofolinin.dll; ucavarukur.dll; srpz20.dll; msr950.dll; uxiroquqofolinin.dll; ucavarukur.dll; l9q17ce.sys; file.exe; vhubaa.exe; vhubaa.exe; ulahoc.exe;

rememberthis.scr

rememberthis.scr is au nsafe files using this name are associated with the malware and has been detected as a Worm. rememberthis.scr sample submitted on 2010-11-05 and identified as a threat. REMEMBERTHIS.SCR refers to many versions of an executable program.
Alias:
Threat File: rememberthis.scr
Submit time: 2010-11-06
Excute time:7 min 17 sec
Level of Spread:5
Level of Threat:4
type:Win32/PEMask
Filesize:81K Bytes
Files type
Unknow file [...]

Latest Virus Files Infected On 20101106

1q9wsk.exe; 1q9317.exe; 1oceiq.exe; 1ocei7.exe; 1oc317.exe; 1m931c.exe; 1m9317.exe; 1ku31i.exe; 1iq3ws.exe; 1gm31w.exe; 1gm317.exe; 1eiqgm.exe; 1ei3qg.exe; 1ei31q.exe; 1c9s1e.exe; 1a9k17.exe; 1a93ei.exe; 17y3c7.exe; 17ws1e.exe; 17w31y.exe; 17qgm7.exe; 17oce7.exe; 17oc17.exe; 17m3gm.exe; 17k3yw.exe; 17i31q.exe; 179o1o.exe; 179m1g.exe; 179ku7.exe; 179k17.exe; 179aa7.exe; 1793yw.exe; 1793g7.exe; 17931y.exe; 17931e.exe; 1063tcp2.exe; 1060tcp2.exe; 1058tcp2.exe; 1055tcp2.exe; 1053tcp2.exe; naruc.exe; server.exe; delb.exe; temp3.exe; steale2r.exe; pla.exe; nlwyet.exe; msfttcp.dll; msfteml.dll;

ctf32.exe

ctf32.exe is detected as a trojan and modify the register. We advice you remove this virus asap. ctf32.exe sample submitted on 2010-11-05 and identified as a threat.
Alias:
Threat File:ctf32.exe
Submit time:2010-11-05
Excute time:7 min 6 sec
Level of Spread:1
Level of Threat:4
type:Win32:Small
Filesize:26K Bytes
0K Bytes
1K Bytes
Files type
ctf32.exe is Windows exe file.
MD5:3m7QY1sWNaQEC873rNu82kT17A8l1xWr

findxplorer.exe

Following tell you what is findxplorer.exe virus and how to remove this findxplorer.exe malware. findxplorer.exe sample submitted on 2010-10-27 and identified as a threat.
Alias:
Threat File:findxplorer.exe
Submit time:2010-10-27
Excute time:5 min 22 sec
Level of Spread:1
Level of Threat:4
type:Win32:Spyware-gen
Filesize:36K Bytes
Files type
findxplorer.exe is Windows exe file.
MD5:jVuI2Cjfm380L8GSJ1Vpp3K2NqyD4xn0

Eapp32hst.dll

Eapp32hst.dll registered as a Dynamic Link Library File and is Trojan/Backdoor, commonly located as the temp files in windows temp folder. We suggest you to remove eapp32hst.dll from your computer as soon as possible. For delete eapp32hst.dll virus file you need restart you computer to safe mode and kill the file directly. Following is [...]