Archive for the 'Pctools' Category
Threat Name: Trojan-Downloader.Java.OpenStream.af, Trojan-Downloader.Java.OpenStream.af was found in C:\Users\XX\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\4076ba25-6fad8488 on 2/25/2010 12:21:08
It report C:\Windows\System32\drivers\L0phtPkt.sys as the virus file, but it may not the fact.
Spread Method:
Malware Installation
Instant Message(MSN,Gtalk,QQ etc.)
Threat type:Trojan-Downloader.Java
Trojan-Downloader.Java.OpenStream.af first detected:2010-02-27
Virus file known is PE EXE file written in Basic
File Size:438K Bytes.
Behavior:Creat files in Documents and Settings\[Users]\Local Settings\Temp\
Level of Spread:4
Level of Threat:5
Reported Path:D:\Windows\System32\
MD5:e30acQjPawXFx1F0uC46sibHq5IWo4vL
SHA1..:4SD33yrx21YN21nD1KU00q3o8Vqe8U1TNbLJ4202
February 27th, 2010 | Posted in Kaspersky, Pctools | No Comments
df2.exe; herss.exe; vwtmidwppfwbozgyzwplg.exe; vwtmidwppfwbozgyzwplg.exe; tsneyrizxladoxcsrmd.exe; blx.exe; lcx.exe; internurbjugs.exe; herss.exe; rnd.exe; hwr.exe; b.exe; tkx.exe; svchost.com; dc3yh.exe; 63352625.exe; 54407020.exe; 200.exe; jnnpkn.exe; herss.exe; 39.tmp; lxh8g.exe; nvvfnnv.exe; inh.exe; vwwixjz.exe; msinits.exe; fwqlsftav.exe; ohj.exe; ohh.exe; nriom.exe; winwkpirv.exe; winqowhqa.exe; kodnyp.exe; df2.exe; winlxfm.exe; winyxub.exe; winremgmj.exe; w2af7d1.exe; w1342ea7.exe; krqqn.exe; vgnqw.exe; blx.exe; kanf.exe; lcx.exe; wincceo.exe; touqfo.exe; w939a2.exe; pgyg.exe; winflemxk.exe;
February 19th, 2010 | Posted in Kaspersky, Pctools | No Comments
Threat Name: Win32.FraudPack.azjh
Spread Method:
Instant Message(MSN,Gtalk,QQ etc.)
Threat type:Win32.FraudPack
Win32.FraudPack.azjh first detected:2010-02-17
Virus file known is driver file *.sys written in C
File Size:579K Bytes.
Behavior:Unknow behavior
Level of Spread:6
Level of Threat:2
Reported Path:D:\Program Files\
MD5:A4L8y6B7Eapt1n830u4HGb0w1IQ7dOFr
SHA1..:IUt22CcEm36uK52R37Uoo1J1MqyC4wn6qD7PPK3m
February 17th, 2010 | Posted in Kaspersky, Pctools, TrendMicro | No Comments
frmwrk32.exe
frmwrk32.exesample first submit on 2009-07-13 and considered unsafe.
Description:
Threat File:frmwrk32.exe
Sample Submission:2009-07-13
Processing time:7 min 27 sec
Threat type:Win32:Vitro
Filesize:33K Bytes
Path:
C:\Windows\System\frmwrk32.exe
July 13th, 2009 | Posted in Pctools | No Comments
lmkgwrym.exe sample first submit on 2009-07-09 and considered unsafe.
Description:
Threat File:lmkgwrym.exe
Sample Submission:2009-07-09
Processing time:7 min 37 sec
Threat type:WORM/Allaple.Gen
Filesize:5K Bytes
Path:
D:\Program Files\lmkgwrym.exe
E:\Winnt\System32\lmkgwrym.exe
C:\System Volume Information\lmkgwrym.exe
July 9th, 2009 | Posted in Panda, Pctools | No Comments
is-mumgq.exe sample first submit on 2009-07-08 and considered unsafe.
Description:
Threat File:is-mumgq.exe
Sample Submission:2009-07-08
Processing time:5 min 32 sec
Threat type:Win32/Cryptor
Filesize:51K Bytes
Path:
E:\Windows\is-mumgq.exe
July 8th, 2009 | Posted in Pctools | No Comments
pcwr.exe sample first submit on 2009-06-28 and considered unsafe.
Description:
Threat File:pcwr.exe
Sample Submission:2009-06-28
Processing time:1 min 18 sec
Threat type:WORM/Allaple.Gen
Filesize:7897K Bytes
Path:
E:\System Volume Information\ pcwr.exe
E:\Windows\pcwr.exe
E:\Documents and Settings\[UserName]\Local Settings\Temp\pcwr.exe
June 28th, 2009 | Posted in Panda, Pctools | No Comments
spydb.exe sample first submit on 2009-06-28 and considered unsafe.
Description:
Threat File:spydb.exe
Sample Submission:2009-06-28
Processing time:9 min 26 sec
Threat type:Adware.Trymedia
Filesize:59K Bytes
Path:
D:\Program Files\spydb.exe
C:\Documents and Settings\All Users\Application Data\spydb.exe
C:\Documents and Settings\All Users\Application Data\spydb.exe
MD5:Bi478H6354yXlkgG3JmuyosjvmAyLLG4
SHA1..:j5N0GPBKWN2Yt65oJr7dh50r1ui2TtoO6YuDHxCS
SHA256:eVIh0BP7r0D45X30F1qIccwwAadlp2kb4eQ5DCXEaIEMQgKBnF8q331fBi478H63
Report Countries:
Iran
Romania
Greece
Japan
[...]
June 28th, 2009 | Posted in NOD32, Pctools | No Comments
pc.exe detected as Trojan.Fakeavalert!sd6 and RogueAntiSpyware.Sysguard by PC Tools,not-a-virus:FraudTool.Win32.Agent.jn and not-a-virus:FraudTool.Win32.PrivacyCenter.aby Kaspersky Lab ,Trojan.Fakeavalert by Symantec,SpywareGuard2008 by Symantec
File path as following:
C:\ProgramFilescacheboost\pc.exe
C:\ProgramFilesprivacy center\pc.exe
C:\ProgramFilesprivacy components\pc.exe
C:\windows\system32\pc.exe
June 23rd, 2009 | Posted in Kaspersky, Pctools | No Comments