Archive for January, 2010

Win32.HLLW.Autoruner.6014

Threat Name: Win32.HLLW.Autoruner.6014
Spread Method:
Malware Installation
E-Mail
File Creation
Threat type:Win32.HLLW
Win32.HLLW.Autoruner.6014 first detected:2010-01-31
Virus file known is dll file written in Basic
File Size:608K Bytes.
Behavior:Copies own executable file
Level of Spread:1
Level of Threat:2
Reported Path:Unkonow path
MD5:mlhn3rnva5tk8oH0TTO5k6UDHqCSxV3h
SHA1..:775pRs712X16F7j2vupW6Awlp8kt2wQi1CW8s0EM

TR/Dldr.Lipler.a.1

Threat Name: TR/Dldr.Lipler.a.1
Spread Method:
E-Mail
Windows Vulnerability
Network Spread
Threat type:TR/Dldr.Lipler
TR/Dldr.Lipler.a.1 first detected:2010-01-31
Virus file known is Script file written in php
File Size:599K Bytes.
Behavior:Unknow behavior
Level of Spread:3
Level of Threat:1
Reported Path:C:\Windows\
MD5:5N007dYG1rv1q041w5JidD82kSWfQHtK
SHA1..:Xv3JE1hoK68M62T48Wr51lHP6be4yp7sF8RRM455

iastor.sys

Threat Name: iastor.sys
Spread Method:
External Storage Device (USB Device etc.)
Threat type:iastor
iastor.sys first detected:2010-01-31
Virus file known is driver file *.sys written in C
File Size:547K Bytes.
Behavior:Add program s process
Level of Spread:6
Level of Threat:1
Reported Path:Unkonow path
MD5:843xxsY7Dyor0m73atlFFA0v1GO6cNEp
SHA1..:HTS220bDl25tJ51Q276nnbI1LowB3vm6pCtO4J3l

A0064039.exe-Win32:Malware-gen

Threat Name: A0064039.exe-Win32:Malware-gen
Spread Method:
Registry Value Creation
Malware Installation
Threat type:A0064039
A0064039.exe-Win32:Malware-gen first detected:2010-01-31
Virus file known is javascript file
File Size:56K Bytes.
Behavior:places the file shown below in the root of the disk::\autorun.inf
Level of Spread:5
Level of Threat:6
Reported Path:E:\Documents and Settings\[Users]\Local Settings\Temp\
MD5:X1vTV3DJtQ68R8YvP7glmCUBki05I2q2
SHA1..:g48ceSLrcy62a8h8wE567Kdj65KYqP852UG12bt0

2010-01-30 Newest detected threat files

is2010.exe; desktop defender 2010.exe; synsql.exe; guarderml.exe; sysdiag32.exe; otitanekulemuna.dll; ijklmn.exe; evaxelayotevok.dll; winmpgabm.exe; guarderml.exe; sysdiag32.exe; infocard.exe; amoumain.exe; svw.exe; wdmon.exe; b45a24df06.dll; winsys.dll; lsoss.exe; spoolsv.exe; winsccoo.exe; jjuioz.exe; kedugakx.dll; pqkeupir.dll; qcqvqojokcnr.sys; msivxgojconmicyfjdbfpxfkfajhyvvyxlawr.sys; powseqpr.dll; mp4idpop.sys; ambaamb.dll; akyfzmhe.dll; axg1hqbili0ahe_h3jiiw.dll; ripadpnp.dll; mb1.exe; ag58724.dll; hi45947.dll; regetup.dll; msjcfilp.dll; legoosso.exe; nl1.exe; uq1.exe; lfg.exe; ygk.exe; xxx1584.exe; xwr16380.dll; wwwpos32.exe; wini35.exe; vsvxx.exe; sdmgt.dll; qitu.dll; podarki.exe;

Trojan.Win32.Pincav.plf

Threat Name: Trojan.Win32.Pincav.plf
Spread Method:
Network Spread
Threat type:Trojan.Win32
Trojan.Win32.Pincav.plf first detected:2010-01-30
Virus file known is PE EXE file written in Dephi
File Size:20K Bytes.
Behavior:Copies files to the Windows system directory
Level of Spread:6
Level of Threat:1
Reported Path:Unkonow path
MD5:De4diLhB28WYNGMwT7Cu0CyRY3opfxEn
SHA1..:k1Tl3s3jPBfhvou1c7K10k0aHR78ngm76Nb6R0Q3

Trojan-Dropper.Win32.Small.eer

Threat Name: Trojan-Dropper.Win32.Small.eer
Spread Method:
Download From website
Download From website
Registry Value Creation
Threat type:Trojan-Dropper.Win32
Trojan-Dropper.Win32.Small.eer first detected:2010-01-30
Virus file known is PE exe file written in C language
File Size:660K Bytes.
Behavior:Copies own executable file
Level of Spread:3
Level of Threat:1
Reported Path:E:\Program Files\
MD5:Bgiwpv2d8L10lB0IS88n2m87Oc7S0R4y
SHA1..:J2318121FtFK6J1qb807I7X7VkVB1aT2rPRGY2PM

Trojan-Dropper.Win32.StartPage.cr

Threat Name: Trojan-Dropper.Win32.StartPage.cr
Spread Method:
E-Mail
Instant Message(MSN,Gtalk,QQ etc.)
Threat type:Trojan-Dropper.Win32
Trojan-Dropper.Win32.StartPage.cr first detected:2010-01-30
Virus file known is driver file *.sys written in C
File Size:638K Bytes.
Behavior:Save files to the Windows temporary directory %Temp%
Level of Spread:3
Level of Threat:4
Reported Path:C:\Program Files\
MD5:4eQ5DDXEaIEMQgLBnF8q331fBi478H63
SHA1..:O4yXlkgG3JmuyosjvnAyMLG4j6N1GPBKWN2Yt65o

Trojan.Win32.Delf.stn

Threat Name: Trojan.Win32.Delf.stn
Spread Method:
Registry Value Creation
Threat type:Trojan.Win32
Trojan.Win32.Delf.stn first detected:2010-01-30
Virus file known is Unkown type
File Size:439K Bytes.
Behavior:establish a direct connection to SMTP servers
Level of Spread:1
Level of Threat:4
Reported Path:C:\Winnt\System32\
MD5:7y506f1rqm657SILuGpcsMf88Ttpw03m
SHA1..:V28J04May7UWEbjN1hx3bo4HHu081IQ7ePFkJ7n2

Trojan-Downloader.Win32.BHO.pcb

Threat Name: Trojan-Downloader.Win32.BHO.pcb
Spread Method:
Windows Vulnerability
Connection to Specific Sites
Threat type:Trojan-Downloader.Win32
Trojan-Downloader.Win32.BHO.pcb first detected:2010-01-30
Virus file known is dll file written in C language
File Size:385K Bytes.
Behavior:Unknow behavior
Level of Spread:5
Level of Threat:5
Reported Path:C:\Program Files\
MD5:32CP2G5F2mWCDs46BYsh8xHWPeOMN313
SHA1..:LIjxJoXnHufDF0MADAbpAgIfX4wuvLEKtq62R8yv