Win32/TrojanDownloader.Small.OBC
Win32/TrojanDownloader.Small.OBC was detected with the following virus:
VBS/AutoRun.AD (2), Win32/Adware.AdMedia, Win32/Adware.AntiSpySpider (2), Win32/Adware.PowerAntivirus (2)
Win32/TrojanDownloader.Small.OBC was detected with the following virus:
VBS/AutoRun.AD (2), Win32/Adware.AdMedia, Win32/Adware.AntiSpySpider (2), Win32/Adware.PowerAntivirus (2)
BackDoor-DOQ virus file name known as C:\Documents and Settings\[UserName]\Start Menu\Programs\startup\userinit.exe
C:\Windows\System32 \drivers\services.exe
W32.Vbac.A virus file known as VGod.DLL,Visible Symptoms
The hidden file VGod.DLL or VCab.dll exists in the Temporary folder.
Infected EXE and DLL files have increased in size.
W32/Socks.AF.worm also known as SHeur.BAQW (AVG),Trojan.Spambot.3092 (DrWeb),32/Socks.af (TheHacker),W32/Socks.E.worm (Panda),Win32:Socks-AE (Avast),Worm.Socks.af (Ewido)
Win32.Worm.Socks.2 is a network-aware worm that attempts to replicate across the existing network(s),Threat Level: High
BackDoor.FireOn.6 virus files commonly on the path of C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30- 83E44C588624} or related C:\System Volume Information\_restore path
Dropper.Agent.HHL virus file know as zip.dll,commonly on the path as C:\WINDOWS\Installer \{9ee01140-4ce8-4ec8-ac27-ac56b5e0cd7d}
Worm/Generic.GWR spreads by emails as a message attachment and via P2P networks.Worm/Generic.GWR copies itself as scanregw.exe,
Trojan.Sockrypt.Gen virus File MD5: 0×407A8F344B57607DA49CEB991DB4972F ,Filesize: 24,064 bytes ,Trojan.Sockrypt.Gen Alias: Trojan.Sockrypt.Gen [PCTools], Trojan.Win32.Nosok.ac [Kaspersky Lab], W32.SillyP2P [Symantec], BackDoor-DOQ [McAfee]
The following Registry Keys were created:
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
AdWare.Win32.Virtumonde.alud virus file known as edyehkbt.dll.AdWare.Win32.Virtumonde.alud characteristics of Vundo ,AdWare.Win32.Virtumonde.alud cause popups and advertises rogue antispyware programs. Vundo can be installed by visiting a Web site link contained in a spammed email. It is known to create a DLL file in the Windows system32 directory and inject it into system processes winlogon.exe and explorer.exe.