Archive for the 'Kaspersky' Category
Threat Name: Trojan-Downloader.Win32.FraudLoad.wyxh
Infected by some nasty trojans such as following:Trojan-Downloader.Win32.FraudLoad.wyxh, Exploit.HTML.Iframe.FileDownload, HEUR:Trojan-Downloader.Win32.Generic, Trojan-Spy.HTML.Fraud.Gen, Trojan-Win32.FraudPack.rdo in spite of a commercial AV and firewall.
Spread Method:
Instant Message(MSN,Gtalk,QQ etc.)
Threat type:Trojan-Downloader.Win32
Trojan-Downloader.Win32.FraudLoad.wyxh first detected:2010-03-07
Virus file known is PE EXE file written in Java
File Size:602K Bytes.
Behavior:Copies files to the Windows system directory
Level of Spread:6
Level of Threat:2
Reported Path:Unkonow path
MD5:B4M007CWFbqu1o830v4HHc082IQ7ePGr
SHA1..:JVu32Ddfn36vL52S38Vpp1KGNqyD4xo6rE7QPL4n
March 7th, 2010 | Posted in Kaspersky | No Comments
Threat Name: win.32.small.aply
Spread Method:
Download From website
Threat type:win.32
win.32.small.aply warning from kasper kept popping up sayin that my winlogon.exe was infected with the trojan downloader.
win.32.small.aply first detected:2010-03-07
Virus file known is PE exe file written in C language
File Size:650K Bytes.
Behavior:Downloads files from URLs
Level of Spread:1
Level of Threat:2
Reported Path:Unkonow path
MD5:D5O007dYh1sv1q041w5JjeE02kSWgRIt
SHA1..:LXw3JE1hoL68N63U48Xr62mIP6bf5ap7tG8SRMM5
March 7th, 2010 | Posted in Kaspersky | No Comments
Threat Name: Trojan.win32.autorun.abd
Spread Method:
Network Spread
Windows Vulnerability
Same time infected with trojan.win32.autorun.abj,trojan.win32.autorun.abd, gamethief-magania.cxkv, gamethief-magania.cxad appearing over and over again.
Threat type:Trojan.win32
Trojan.win32.autorun.abd first detected:2010-03-06
Virus file known is dll file written in Basic
File Size:482K Bytes.
Behavior:Unknow behavior
Level of Spread:4
Level of Threat:5
Reported Path:System Volume Information on C,D and E drives seems to be most infected.
MD5:g41cdSlrbyAHyEh1wE567jcis5JXqO8N
SHA1..:5UF34bta32BP2G5F1LWBDr350Xrg8w2VPdNLN302
March 6th, 2010 | Posted in Kaspersky | No Comments
Infected with Virus.Boot.Malmo as a resut my network is very slow
Threat Name: Virus.Boot.Malmo
Spread Method:
File Creation
Threat type:Virus.Boot
Virus.Boot.Malmo first detected:2010-03-06
Virus file known is javascript file
File Size:60K Bytes.
Behavior:Downloads files from URLs
Level of Spread:3
Level of Threat:1
Reported Path:C:\Program Files\
MD5:g1srnT58tJMvHqdtNg0AU7qxB34W28K0
SHA1..:5Nb07vXF0ko1iy4cp5Iiv182JR7fQGlK8o331dgh
March 6th, 2010 | Posted in Kaspersky | No Comments
5927hacz5ool710.dll; 59119oz-a-virusc.ocx; 57e5download9z1926.ocx; 56f754e8-d155-878e-b588-ebb344869fc5.exe; 56701spambot9cez.ocx; 55z5addware9779.exe; 55azs59ware2618.exe; 5510addw9ze1500.exe; 54e5thr9at20z36.dll; 541fste9l15z0.exe; 53594zpy76f.ocx; 5347ztea59593.dll; 52f3d59nloadzr68.exe; 51e54c7f08.sys; 51849worm621z.exe; 5159sparsz137.ocx; 51267dfe7a.sys; 51040hac9tzol3fe.exe; 5098zirusa4.exe; 4zf5vir59269.exe; 4z55thr9at15466.ocx; 4e055ownloadez20859.ocx; 4d5spzr5e389.exe; 4b589ir1865z.exe; 49c55hief1989z.dll; 497.exe; 4935spambzt9c6.ocx; 47a45hreatz3819.exe; 477cs9arse15z0.ocx; 4670.exe; 45fz5r1996.dll; 4591thiefz800.ocx; 458asparze9713.exe; 4589pa5botcz.dll; 456ddow9zoader2343.ocx; 4535thie9z73.ocx; 438z9te5l721.exe; 4342d9wnl5ader286z.dll; 4300tzr9at30956.exe; 4245spy4zf9.exe; 4209.exe; 4119.exe; 4107spy2z95.exe; 405fthief91z9.exe; 3f24spyz9re14335.dll; 3ed6backdz952765.dll; 3cfbe0e1f4.sys; 3c4zad9ware1535.dll; 3bcstea5891z.dll;
March 6th, 2010 | Posted in Kaspersky, TrendMicro | No Comments
59427.exe; uyupesiq.dll; jiffmt.dll; mediaacck.exe; netsi.exe; uyupesiq.dll; jiffmt.dll; izekegasudevibeb.dll; eputahefozujecaz.dll; is-nor64.exe; bill102.exe Win32.Trojan.VB.ENI 4.3.2010.; odbns.exe Win32.Trojan.Agent.MPM 4.3.2010.; wmisftl.exe; smvm232.exe; sikvnxhn.dll; 59.doc.exe; j-di_vr.exe; fd33.exe; cbd3c7.exe; vnkgsmjexjdnrofkuia.exe .; ujdwfwqiyhyfgaoq.exe; runver2.exe; regdllhelper.exe; oner2010.dll; nt32inf10.exe; nhdldrht.exe; iawmaqua.exe; hujeneje.dll; e569e6.exe; dirstems.exe; atnadm.exe; a6087d.exe; a14c40.exe; 5d7d74.exe; 31f52b.exe; 7dea53.exe; e840ee.exe; f385b0.exe; 6adaa8.exe; dc50cc.exe; dc50cc.exe; wx4d15e4.exe; wx48a701.exe; wx43410f.exe; nt32inf10.exe; e569e6.exe; xv447c65.exe; wx63af95.exe; tx8d2fec.exe;
March 5th, 2010 | Posted in Clam, Kaspersky, NOD32 | No Comments
Threat Name: Net-Worm.Win32.kido.ih
Spread Method:
File Creation
Network Spread
Threat type:Net-Worm.Win32
Net-Worm.Win32.kido.ih first detected:2010-03-04
Virus file known is PE exe file written in C language
File Size:405K Bytes.
Behavior:Unknow behavior
Level of Spread:4
Level of Threat:5
Reported Path:D:\Program Files\
MD5:d30yBPiOxv7Ev0E0tB4prgyFp42Un4uK
SHA1..:3RChixqw21XM11mC0JT80o2n87Od7T1SMaK33281
March 4th, 2010 | Posted in Kaspersky | No Comments
Kaspersky detects Backdoor.Win32.Small.ive. KIS also deleted it. Threat Name: Backdoor.Win32.Small.ive
Spread Method:
Registry Value Creation
Threat type:Backdoor.Win32
Backdoor.Win32.Small.ive first detected:18.02.2010 07:01
Virus file known is PE exe file written in C language
File Size:20K Bytes.
Behavior:Unknow behavior
Level of Spread:1
Level of Threat:2
located at C:\WINDOWS\explorer.exe
MD5:E6P118fBi1t826041y5LkfF0JmUXhsJv
SHA1..:MYx4LG2i5M78OT3V40Ys62nJq7dg5br8uH0TTOO6
March 4th, 2010 | Posted in Kaspersky | No Comments
Threat Name: Trojan-Dropper.win32.Autoit.k
Spread Method:
Connection to Specific Sites
USB Disk
Registry Value Creation
Threat type:Trojan-Dropper.win32
Trojan-Dropper.win32.Autoit.k first detected:2010-03-04
When scanned, kaspersky reported one of my file contains nearly 200 virus of the type Trojan program Trojan-dropper.win32.Autoit.k on Today, 14:53
File Size:499K Bytes.
Behavior:Usualy have random filename and refers to many versions of a dynamic link library
Level of Spread:1
Level [...]
March 4th, 2010 | Posted in Ikarus, Kaspersky | No Comments
Threat Name: Trojan-Spy.Win32.Agent.bdpj
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Spread Method:
Hacked Website
Malware Installation
Threat type:Trojan-Spy.Win32
Trojan-Spy.Win32.Agent.bdpj first detected:2010-03-02
Virus file known is PE exe file written in C language
File Size:385K Bytes.
Behavior:Registered as a Dynamic Link Library File
Level of Spread:3
Level of Threat:5
Reported Path:D:\Documents and Settings\[Users]\Local Settings\Temp\
MD5:c30XAOhNxu7Dv0D0sA3pqgyFol2Um3t3
SHA1..:kQCgiwpv2d8L10lB0IS88o2n87Oc7S1R4yJ23181
March 2nd, 2010 | Posted in Kaspersky | No Comments