Archive for the 'DrWeb' Category

latest infected viruses files on 2010-03-10

icn_19f4ad9090a22324bac8b67c0490d63e.dll; icn_191c6d002a05c9d4295881718d24f06b.dll; icn_156add4851af2fd4a88e9ef83a921bdc.dll; icn_0a6524732aaeb210da06000000000000.dll; 15815828.exe; libexpatw.dll; bgh.exe; 15815828.exe; oog.exe; r9rqzxqr.exe; kern.dll; fjyyz6iy.exe; takk.exe; msw.exe; 15815828.exe; kwlyifod.sys; fwldipoc.sys; ypartmgr.sys; fftdapod.sys; uxldqpob.sys; pxlyypob.sys; 9715sys.dll; pxldypob.sys; 19731254.exe; cuakep.exe; cuakep.exe; cuakep.exe; searchsettings.exe; svchosf.exe; netmeet.exe; juschedit.exe; dchcp.exe; antispyware.exe; vistadrive.exe; ckp32.log; cuakep.exe; bliss.exe; greendot.exe; cuakep.exe; stripe.exe; cuakep.exe; cuakep.exe; ckpexp.exe; greendot.jpg.exe; ipysvr.exe; ipysvc.exe; mszyplcq.dll; revent.dll; qhkparux.dll;

latest detected viruses files on 20100309

windowslogon.exe; sdra64.exe; palma.exe; SyncMan.exe; cracksearche0.exe; cracksearcher.exe; bgz.exe; babb1.exe; fxlyapog.sys; uxtdypob.sys; axtdypog.sys; pirovowi.dll; peheduke.dll; ace.com.exe; uflyrpow.sys; aftdypob.sys; kfwyipoc.sys; pxrdapob.sys; pxrorpob.sys; 0.10725813742607593.exe; kgloapog.sys; kgrorpoc.sys; fwlyrfob.sys; pgrdapow.sys; pwdorkoc.sys; uwqoqpoc.sys; fxkyqpob.sys; uflyrpow.sys; aftdypob.sys; kfwyipoc.sys; pxrdapob.sys; pxrorpob.sys; 0.10725813742607593.exe; kgloapog.sys; kgrorpoc.sys; fwlyrfob.sys; pgrdapow.sys; pwdorkoc.sys; uwqoqpoc.sys; fxkyqpob.sys; jzh.exe; jknjo.exe; winqqspv.exe; winfwebn.exe; windgnbmc.exe; winosahf.exe; muhc.exe; kqdgjd.exe; wintgfdtp.exe;

Backdoor.Tidserv!inf and atapi.sys

Threat Name: Backdoor.Tidserv!inf
Spread Method:
File Creation
External Storage Device (USB Device etc.)
External Storage Device (USB Device etc.)
Threat type:Backdoor
Backdoor.Tidserv!inf first detected:2010-02-26
Virus file known is PE EXE file written in Basic
File Size:417K Bytes.
Behavior:places the file shown below in the root of the disk::\autorun.inf
Level of Spread:6
Level of Threat:4
Reported Path:D:\Winnt\
MD5:BaNMI5k6OEHqCLxP3Bu75pLs71iR16Fw
SHA1..:j3VupQ6AwfJ8dt2WKj1DQ8t0EM5aL0h16JedxyBc

2010-0216 infected virus files list

2010-0216 infected virus files list
scoamk.exe; mpgmrc.exe; lsass.exe; hoschfg.exe; lsass.exe; scoamk.exe; xzd.exe; herss.exe; ikr.exe; kr1.exe; vwtmidwppfwbozgyzwplg.exe; tsneyrizxladoxcsrmd.exe; igaqjbrherfhrzdsqk.exe; igaqjbrherfhrzdsqk.exe; ggcupjbtshxbnxduuqid.exe; ggcupjbtshxbnxduuqid.exe; uwd.exe; bhr.exe; xzd.exe; ikr.exe; wincpnuf.exe; kr1.exe; msdtctr.exe; fcimcb.exe; drwatson64ex.exe; wingrpuii.exe; ohbl.exe; vgnqw.exe; elq.exe; wincgwj.exe; svd_dap.exe; 476.exe; wfda69.exe; duqdq.exe; bhr.exe; winmrou.exe; fxtdapod.sys; agkoqpow.sys; ffpoypod.sys; fxtdypoc.sys; afloikob.sys; byyk.exe; win16.exe; win.exe; system.exe; nvsvc32.exe; notepad.exe; mdm.exe; kfihdni.exe;

dskcolenh.exe

dskcolenh.exe sample submitted on 2010-02-15 and identified as a threat.
Alias:
Threat File:dskcolenh.exe
Submit time:2010-02-15
Excute time:10 min 55 sec
Level of Spread:1
Level of Threat:5
type:Win32.Virtob.Gen
Filesize:3409K Bytes
Files type
dskcolenh.exe is Windows exe file.
MD5:1824b2WIA6L2f0A7DhpsCn132t6gGb0d

Trojan-GameThief.Win32.OnlineGames.vyrt

Threat Name: Trojan-GameThief.Win32.OnlineGames.vyrt
Spread Method:
Hacked Website
Windows Vulnerability
Threat type:Trojan-GameThief.Win32
Trojan-GameThief.Win32.OnlineGames.vyrt first detected:2010-02-08
Virus file known is dll file written in C++
File Size:243K Bytes.
Behavior:Attempted Connection to External Sites
Level of Spread:5
Level of Threat:6
Reported Path:D:\System Volume Information\
MD5:4UL34a6y32ho2M5L1lVBC63q0Xrg8w2v
SHA1..:VcnRT302ROiwOn8mMtejK0S8If05GfNdw3usuQJP

Newest viruses files detected on 0206

scs.dll; h4×0r.dll; cncomter.exe; a0×1.exe; wmpscfgs.exe; win16.exe; rzjekuzdm.dll; nkpaktnvm.dll; evshnhuek.dll; concordance.exe; bylrwigip.dll; alg.exe; alanbiaa.exe; 6_ldry3.exe; 5_odbn0.exe; 00006ea9.sys; c192rrq.exe; lds.exe; ukh.exe; herss.exe; ldm1.exe; c192rrq.exe; wingeppk.exe; wingrgo.exe; lds.exe; winjclua.exe; ukt.exe; ukh.exe; qulhs.exe; omlm.exe; c3s9gf17.exe; ubq3fhk4.exe; dbtjmti4e.exe; uwtdypob.sys; uwtyapod.sys; uxddrkod.sys; pxtdrpob.sys; bhsegjts.exe; uwdoqpog.sys; kxtdipow.sys; axtdrpod.sys; kwdcrpob.sys; 4_pinnew.exe; kfpyrpow.sys; fxldqpob.sys; kwtdqpob.sys; herss.exe; tkqxex.exe; d73×04vn.exe;

2010-01-27 detected threat files

FieryAds.dll; mlburmh.exe; userlib.dll; windll.exe; cpco.exe; kqbv.exe; wgqi.exe; trhh.exe; sdigdvmg.exe; byyk.exe; [bleep]3.exe; dwytxrzf.exe; pdfupd.exe; pdfupd.exe; 440xpusa.exe; 440insta.exe; h8srtkrl32mainweq.dll; wsf6d0.exe; tbird1.exe; tbird.exe; uwtyrkog.sys; ufqyaaob.sys; kwddapog.sys; wuauclt.exe; ugtdypow.sys; kxtyyfow.sys; xegjgvprc.exe; wtogskwbn.exe; awryypoc.sys; pxroapog.sys; fxaiypog.sys; fuefue.exe; pdwb.exe; nqvkiv.exe; nesng.exe; ajeesil.exe; hidujuku.dll; tvmknwrd.dll; tvmcwrd.dll; gooredfix.exe; 440xpusa.exe; 440insta.exe; uwdyqpog.sys; pxtdapod.sys; ugtdypow.sys; kfldqpoc.sys; pxroapog.sys; lp791a.exe; slscv.exe;

kbdsock.dll

kbdsock.dll sample submitted on 2010-01-23 and identified as a threat.
Alias:
Threat File:kbdsock.dll
Submit time:2010-01-23
Excute time:10 min 53 sec
Level of Spread:4
Level of Threat:1
type:Win32.Worm.Allaple.Gen
Filesize:87K Bytes
Files type
kbdsock.dll is a A dynamic-link library,which acts as a shared library of functions.
MD5:7h2ttoV6YuKowIsevPh0BV7r8D35X30M

20100123 Detected threat files List

ojjw.exe; duehpow.exe; dqccpnq.exe; GoogleUpdate.exe; armordefender.exe; protectdefender.exe; protectsoldier.exe; apcsecure.exe; tregeury.exe; wpv641254042811.exe; wpv261257179558.exe; expoler.exe; 8a137.com; wpv261257179558.exe; winjkele.exe; winywysx.exe; winuogd.exe; winuhqo.exe; winonvfq.exe; wincjmor.exe; winbundem.exe; uyeuw.exe; qf1508.exe; mkyj.exe; fjfyd.exe; extaxa.exe; 8a137.com; ezecuhuh.dll; zoqan.sys; unamupag.dll; izoqixusy.exe; cydusypy.exe; ewibixaxayug.dll; ewibixaxayug.dll; c4e7b72c.ocx; 85a58256.ocx; 80f54c17.ocx; 7673d9ac.ocx; rryet.dll; qopmkk.dll; vezareginfo.dll; a12bdd4ae2.sys; irejurijafecufi.dll; aneyuhaxovab.dll; ayevarowige.dll; 2276601680.exe; 2222023200.exe; hostwww.exe.exe; msa.exe;