Archive for the 'Norman' Category

0227 infected virus file as delsbc.exe etc

zpharaoh.exe; s1.exe; qw6t0mpm.exe; q1.exe; kernel.dll; 4tddfwq2.dll; pwldypob.sys; xyskjxwmmfcwoikawqqgc.exe; vumczliwulgyogguoge.exe; pjf.exe; kizokvrebrlcrihune.exe; byocxhcokzsiwmkwo.exe; awx.exe; asr64_ldm.exe; ahhwcru.exe; asr64_ldm.exe; pjf.exe; awx.exe; xyskjxwmmfcwoikawqqgc.exe; xyskjxwmmfcwoikawqqgc.exe; vumczliwulgyogguoge.exe; vumczliwulgyogguoge.exe; kizokvrebrlcrihune.exe; byocxhcokzsiwmkwo.exe; byocxhcokzsiwmkwo.exe; ahhwcru.exe; winjrbp.exe; wgicyd.exe; winjfqyo.exe; ommu.exe; pjf.exe; wintbnfdt.exe; ivykf.exe; awx.exe; gxo.exe; ximox.exe; winfselyo.exe; w8a67c3.exe; gtk21.tmp; ahhwcru.exe; adnubroi.exe; ek1.exe; winnthu.exe; bqyi.exe; bbq.exe; kcxow.exe; les welch.exe; 7tbfcy86.exe; sysquery.dll;

Infected threat files on 20100226

7__68.exe; 703.exe; 715.exe; 725.exe; 729.exe; 730.exe; 731l1.exe; 732.exe; pdhqmmkhmi.dll; _voidlbudijoghu.sys; mylife.exe; cabxd.dll; zmd0l.dll; tesourar.exe; dan1252609492.exe; uh8zqxi_gkdaovbt.dll; gsuzwej.dll; _qbotviycv.exe; fibewoze.dll; guegae.exe; membus.sys; pc6202.exe; wgh.exe; wpv881254042811.exe; wpv311253178221.exe; eh42392.dll; ow35615.dll; ih1.exe; ftr.exe; 4dw4r3tsbwkolgop.sys; 4dw4r3oxqvlhpnwt.sys; cgx.exe; qsjqaij.exe; xp-85858c9a.exe; uwkbsftav.exe; hkehsftav.exe; xp-53092866.exe; 1dcm34_x8_aj5_.dll; pcz_gn8a0coff-.dll; b-o8-yg9.dll; 2d-qw_lfc59i_.dll; 74338934.exe; 20126920.exe; 621ab4.exe; vetarisa.dll; 9d4c1e.exe; fcdlkjzq.exe; cidrive32.exe; dpcaum.exe;

trojan-downloader.win32.fraudload.wwyr

Threat Name: trojan-downloader.win32.fraudload.wwyr
Spread Method:
Hacked Website
Threat type:trojan-downloader.win32
trojan-downloader.win32.fraudload.wwyr first detected:2010-02-17
Virus file known is PE exe file written in C language
File Size:20K Bytes.
Behavior:Unknow behavior
Level of Spread:1
Level of Threat:2
Reported Path:D:\Winnt\System32\
MD5:E6P118fAi1t826041y5LkfF0ImUXhsJv
SHA1..:MYx4LG2i5M78OT3V40Ys62nJq7dg5br8uH0TTOO6

setuper.exe

setuper.exe sample submitted on 2010-02-15 and identified as a threat.
Alias:
Threat File:setuper.exe
Submit time:2010-02-15
Excute time:1 min 28 sec
Level of Spread:2
Level of Threat:1
type:Win32:Hupigon
Filesize:37K Bytes
Files type
setuper.exe is Windows exe file.
MD5:6Q118gCj278H61O2a6MlgG0KnvY3tK7N

Trojan-GameThief.Win32.OnlineGames.vyrt

Threat Name: Trojan-GameThief.Win32.OnlineGames.vyrt
Spread Method:
Hacked Website
Windows Vulnerability
Threat type:Trojan-GameThief.Win32
Trojan-GameThief.Win32.OnlineGames.vyrt first detected:2010-02-08
Virus file known is dll file written in C++
File Size:243K Bytes.
Behavior:Attempted Connection to External Sites
Level of Spread:5
Level of Threat:6
Reported Path:D:\System Volume Information\
MD5:4UL34a6y32ho2M5L1lVBC63q0Xrg8w2v
SHA1..:VcnRT302ROiwOn8mMtejK0S8If05GfNdw3usuQJP

Newest viruses files detected on 0206

scs.dll; h4×0r.dll; cncomter.exe; a0×1.exe; wmpscfgs.exe; win16.exe; rzjekuzdm.dll; nkpaktnvm.dll; evshnhuek.dll; concordance.exe; bylrwigip.dll; alg.exe; alanbiaa.exe; 6_ldry3.exe; 5_odbn0.exe; 00006ea9.sys; c192rrq.exe; lds.exe; ukh.exe; herss.exe; ldm1.exe; c192rrq.exe; wingeppk.exe; wingrgo.exe; lds.exe; winjclua.exe; ukt.exe; ukh.exe; qulhs.exe; omlm.exe; c3s9gf17.exe; ubq3fhk4.exe; dbtjmti4e.exe; uwtdypob.sys; uwtyapod.sys; uxddrkod.sys; pxtdrpob.sys; bhsegjts.exe; uwdoqpog.sys; kxtdipow.sys; axtdrpod.sys; kwdcrpob.sys; 4_pinnew.exe; kfpyrpow.sys; fxldqpob.sys; kwtdqpob.sys; herss.exe; tkqxex.exe; d73×04vn.exe;

Trojan-Dropper.Win32.Small.eer

Threat Name: Trojan-Dropper.Win32.Small.eer
Spread Method:
Download From website
Download From website
Registry Value Creation
Threat type:Trojan-Dropper.Win32
Trojan-Dropper.Win32.Small.eer first detected:2010-01-30
Virus file known is PE exe file written in C language
File Size:660K Bytes.
Behavior:Copies own executable file
Level of Spread:3
Level of Threat:1
Reported Path:E:\Program Files\
MD5:Bgiwpv2d8L10lB0IS88n2m87Oc7S0R4y
SHA1..:J2318121FtFK6J1qb807I7X7VkVB1aT2rPRGY2PM

Trojan-Dropper.Win32.Agent.bjck

Threat Name: Trojan-Dropper.Win32.Agent.bjck
Spread Method:
USB Disk
Threat type:Trojan-Dropper.Win32
Trojan-Dropper.Win32.Agent.bjck first detected:2010-01-25
Virus file known is driver file *.sys written in C++
File Size:663K Bytes.
Behavior:Unknow behavior
Level of Spread:3
Level of Threat:1
Reported Path:D:\Windows\System32\
MD5:8xsA7Dyos0m73atlGFA0v1HP6cNEqHTS
SHA1..:220bDl25tJ51Q276nnbI1LowB3vm6pCtO5J3l458

ir32_32.dll

ir32_32.dll
ir32_32.dllsample first submit on 2009-07-13 and considered unsafe.
Description:
Threat File:ir32_32.dll
Sample Submission:2009-07-13
Processing time:3 min 40 sec
Threat type:TR/Drop.Stabs
Filesize:23K Bytes
Path:
c:\System Volume Information\ _restore…\ir32_32.dll

st_1243718863.exe

st_1243718863.exe sample first submit on 2009-07-11 and considered unsafe.
Description:
Threat File:st_1243718863.exe
Sample Submission:2009-07-11
Processing time:4 min 44 sec
Threat type:Win32/PEMask
Filesize:56K Bytes
Path:
C:Documents and SettingsAll UsersApplication Datast_1243718863.exe
E:System Volume Information _restore…st_1243718863.exe