Archive for the 'F-Prot6' Category

e4u.exe

e4u.exe
e4u.exe sample submitted on 2010-04-24 and identified as a threat.
Alias:
Threat File:e4u.exe
Submit time:2010-04-24
Excute time:7 min 33 sec
Level of Spread:2
Level of Threat:5
type:Trojan.Win32.Possador
Filesize:54K Bytes
Files type
e4u.exe is Windows exe file.
MD5:mYxLKF4i5M0FO0JVM2Ys64nJq7cg5bq1

trojan.win32.monder.deuf

trojan.win32.monder.deuf
Threat Name: trojan.win32.monder.deuf
Spread Method:
Instant Message(MSN,Gtalk,QQ etc.)
External Storage Device (USB Device etc.)
Registry Value Creation
Threat type:trojan.win32
trojan.win32.monder.deuf first detected:2010-04-22
Virus file known is PE EXE file written in C++
File Size:122K Bytes.
Behavior:sends a request to IP address
Level of Spread:6
Level of Threat:4
Reported Path:
c:\windows\system32\juhiruma.dll
c:\windows\system32\giyesewu.dll
c:\windows\system32\fatenuva.dll
dalopije.dll
C:\Program Files\adc32.dll
c:\windows\system32\zawibavu.dll
c:\windows\system32\yutegeve.dll
c:\windows\system32\wonupago.dll
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’hotanaduy
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’huwokiyud
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’selurosil
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’siniyezij
‘HKEY_LOCAL_MACHINE’,’SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler’,’{13e72d96-dcf8-4b0c-adf9-bbf18a8a8573}
‘HKEY_LOCAL_MACHINE’,’SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler’,’{0a5bb9ce-70d9-4d46-af8d-821b3f343132}
‘HKEY_LOCAL_MACHINE’,’SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler’,’{cb8e52d6-b08d-4612-9869-ed3c1fa837c8}
‘HKEY_LOCAL_MACHINE’,’SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler’,’{79c589e5-02be-4dfb-a4f8-980f56c78e6b}
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’hagabeyol
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’yuhidadil
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’zuteyinat
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’rapagoset
‘HKEY_LOCAL_MACHINE’,’SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler’,’{fb0397f4-f276-490d-8ab4-88b8b90d3715}
‘HKEY_LOCAL_MACHINE’,’SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler’,’{a12a8a8b-68e4-49e0-a5ed-137a9f47c43a}
‘HKEY_LOCAL_MACHINE’,’SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler’,’{5613f67d-24f7-4b31-be67-57c1cd82fe22}
c:\windows\system32\hagebuzi.dll
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad’,’mufijaked
‘HKEY_LOCAL_MACHINE’,’Software\Microsoft\Windows\CurrentVersion\Run’,’bodufoleb
c:\windows\system32\dobafigi.dll
C:\WINDOWS\system32\vuwiyane.dll
C:\Program Files\svchost.exe
c:\windows\system32\gugadobe.dll
MD5:UtH20iEl280K7FR307oniJ1MpxC3vm8p
SHA1..:dcOOJ3m7QY0sWNyQDC773qMu82kS17A8l1wWrR7U

azl.exe

what is it azl.exe, azl.exe remove, how to remove azl.exe, azl.exe removal, what is azl.exe
azl.exe sample submitted on 2010-04-18 and identified as a threat.
Alias:
Threat File:azl.exe
Submit time:2010-04-18
Excute time:9 min 48 sec
Level of Spread:4
Level of Threat:6
type:BackDoor.Bifrose
Filesize:79K Bytes
Files type
azl.exe is Windows exe file.
MD5:6f1rqm657SILuGpctNf8YTtpw03mV28J

cmos85.exe

cmos85.exe
cmos85.exe sample submitted on 2010-04-17 and identified as a threat.
Alias:
Threat File:cmos85.exe
Submit time:2010-04-17
Excute time:1 min 56 sec
Level of Spread:5
Level of Threat:1
type:Win32.Trafrox
Filesize:93K Bytes
13354K Bytes
1K Bytes
Files type
cmos85.exe is Windows exe file.
MD5:7j2vupW6Awlp8kt2wQi1CW8s0EM5yK0n

yeazel.exe

yeazel.exe
yeazel.exe sample submitted on 2010-04-16 and identified as a threat.
Alias:
Threat File:yeazel.exe
Submit time:2010-04-16
Excute time:10 min 53 sec
Level of Spread:4
Level of Threat:1
type:Win32.Worm.Allaple.Gen
Filesize:87K Bytes
Files type
yeazel.exe is Windows exe file.
MD5:7h2ttoV6YuKowIsevPh0BV7r8D35X30M

ose00001.exe

ose00001.exe
ose00001.exe sample submitted on 2010-04-15 and identified as a threat.
Alias:
Threat File:ose00001.exe
Submit time:2010-04-15
Excute time:1 min 56 sec
Level of Spread:5
Level of Threat:1
type:Win32.Trafrox
Filesize:93K Bytes
15022K Bytes
1K Bytes
Files type
ose00001.exe is Windows exe file.
MD5:7j2vupW6Awlp8kt2wQi1CX8s0EM5yK0n

digprot.exe

digprot.exe sample submitted on 2010-04-15 and identified as a threat.
Alias:
Threat File:digprot.exe
Submit time:2010-04-15
Excute time:8 min 42 sec
Level of Spread:3
Level of Threat:6
type:Trojan-Ransom.Win32
Filesize:69K Bytes
0K Bytes
1K Bytes
Files type
digprot.exe is Windows exe file.
MD5:qdcPOJ5m7QFJsEnaQKC876rNu82kS17H

2010-04-13 Infected latest viruses files

h0j8w.exe; a2xa.exe; 111.exe; 0i86rk.exe; wuaucldt.exe; xcxc.exe; w7ster.exe; the.exe; kap7win.exe; hh.exe; hh.exe; fiosejgfse.dll; mscjm.exe; sed.exe; mscjm.exe; t7uwb6a0.exe; mplay32xe.exe; msd.exe; lsie.exe; geurge.exe; rm2.exe; msinits.exe; lunq4edjg.exe; geurge.exe; ovj.exe; Usbconeted.exe; davclnt.exe Win32.Generic.pak 12.4.2010.; antiviruspro_2010.exe; digprot.exe; vcsdz.exe; winxepl.exe; winwjpvq.exe; winossrq.exe; wincxavhu.exe; vrt12.tmp; ov69fa.exe; nv4d97.exe; lnwya.exe; kme84d.exe; sun21_v26.exe; sqemoa.exe; qverua.exe; qjifua.exe; p0rnbet.exe.exe; joypluscheck.exe; hyden.dll.exe; hmekyb.exe; gryzya.exe; test24.exe;

avs.exe

Do you know what is avs.exe? How to remove avs.exe? avs.exe is what? Is avs.exe harmful?
avs.exe sample submitted on 2010-04-10 and identified as a threat.
Alias:
Threat File:avs.exe
Submit time:2010-04-10
Excute time:3 min 10 sec
Level of Spread:6
Level of Threat:3
type:BDS/Udr
Filesize:16K Bytes
0K Bytes
1K Bytes
Files type
avs.exe is Windows exe file.
MD5:C5N007dXG1rv1p041w5JidD82kSVfQHt

Latest Reported Viruses files on 2010-04-10

faststart.exe; facegame.exe; f508.exe; explorer.exe; event.exe; euuhsysguard.exe; esentutl.exe; yhrywusf.exe; erpogs.exe; qhqusftav.exe; eqbmamlnpsq.exe; ep.exe; eehl.exe; eehl.dll; ecjuungy.exe; ec1957.exe; e86.exe; e4u.exe; e1.exe; dxsetup.exe; imapde.dll; imapdb.exe; dxdlg.exe; dweqsfer.exe; dwbrk02.exe; dw20.exe; winupgro.exe; cjoqsftav.exe; dllhst3g.exe; ygqgsysguard.exe; df.exe; znov.exe; yu2n.exe; kure.exe; deva.exe; deoklyov.dll; dbg32.sys; d9faa.exe; d6.dll; d3.dll; uninstall.exe; ccmain.exe; ccmain.exe; csrss.exe; jfgksysguard.exe; crypter.exe; crssn.exe; fdensftav.exe; converter7.exe;