Home Malware Programs Viruses Cutwail.F

Cutwail.F

Posted: November 30, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 829
First Seen: November 30, 2010
OS(es) Affected: Windows

Aliases

Heuristic.BehavesLike.Win32.Rootkit.H [McAfee-GW-Edition]Trojan/Win32.Agent.gen [Antiy-AVL]TR/Dldr.Agent.cbzw.7 [AntiVir]Win32.TRDldr.Agent.C [eSafe]Trojan.Pandex [Symantec]TrojanDownloader.Agent.ici [CAT-QuickHeal]Trojan-PSW.Win32.Yaludle.a [Kaspersky]Trojan-PWS.Win32.Yaludle [Ikarus]SHeur3.APRI [AVG]Int/DDT [Sophos]Minimal.2 [ClamAV]a variant of Win32/Kryptik.FCW [NOD32]Cryptic.AIO [AVG]Suspicious.Vundo.5 [Symantec]Artemis!F9272A870CD2 [McAfee-GW-Edition]
More aliases (143)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\System32\Drivers\SysLib6.sys File name: SysLib6.sys
Size: 1.72 MB (1724416 bytes)
MD5: 8d697d7b9798c726fa452f6c65c3bdbb
Detection count: 550
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\Drivers
Group: Malware file
Last Updated: December 1, 2010
%TEMP%\sln5ftn4y.exe File name: sln5ftn4y.exe
Size: 60 KB (60000 bytes)
MD5: edb99a9e21613d9bfe39e85728d9906f
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 1, 2010
%WINDIR%\Fonts\8sgp61.com File name: 8sgp61.com
Size: 100.86 KB (100864 bytes)
MD5: b7e07e19e6cf996a340d03a1a094b38d
Detection count: 84
File type: Command, executable file
Mime Type: unknown/com
Path: %WINDIR%\Fonts
Group: Malware file
Last Updated: December 1, 2010
%WINDIR%\System32\drivers\Pua04.sys File name: Pua04.sys
Size: 34.17 KB (34176 bytes)
MD5: 64d3724fed69579f0a5db513691f3068
Detection count: 83
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: April 15, 2011
%TEMP%\mtfsys32.exe File name: mtfsys32.exe
Size: 79.87 KB (79873 bytes)
MD5: 2b6a437537d4f9e26bd0d5b5164b0054
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 1, 2010
%APPDATA%\Adobe\Update\flacor.dat File name: flacor.dat
Size: 135.16 KB (135168 bytes)
MD5: 4da749615b8b8c809226af8d5910900f
Detection count: 52
File type: Data file
Mime Type: unknown/dat
Path: %APPDATA%\Adobe\Update
Group: Malware file
Last Updated: December 1, 2010
%WINDIR%\System32\Drivers\SysLib.sys File name: SysLib.sys
Size: 294.47 KB (294471 bytes)
MD5: be7669250e0bb223cec86880ad4dd33c
Detection count: 33
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\Drivers
Group: Malware file
Last Updated: December 1, 2010
D:\Documents and Settings\All Users\Application Data\WSTB\ver64b.exe File name: ver64b.exe
Size: 322.9 KB (322907 bytes)
MD5: 1813364aa741f05c6fc25788fd88dc9b
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: D:\Documents and Settings\All Users\Application Data\WSTB
Group: Malware file
Last Updated: December 1, 2010
%WINDIR%\System32\drivers\Flq27.sys File name: Flq27.sys
Size: 34.17 KB (34176 bytes)
MD5: 0d2e812141e7fb96a9ca4012bb4027bd
Detection count: 16
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: November 30, 2010
%WINDIR%\system32\javawhelper.dll File name: javawhelper.dll
Size: 2.4 MB (2408960 bytes)
MD5: 18b7c00ffa42ed873385adcd8b73ad0b
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 1, 2010
%APPDATA%\Adobe\Update\flacor.dat File name: flacor.dat
Size: 40.66 KB (40663 bytes)
MD5: cbe312eec69102e380e2b5fbc2677c99
Detection count: 9
File type: Data file
Mime Type: unknown/dat
Path: %APPDATA%\Adobe\Update
Group: Malware file
Last Updated: December 8, 2010
%WINDIR%\System32\Drivers\Cmv33.sys File name: Cmv33.sys
Size: 34.17 KB (34176 bytes)
MD5: 9661ba4a7fc616573265da49ed4990fc
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\Drivers
Group: Malware file
Last Updated: December 9, 2010
%PUBLIC%\U-2535-6853-8747\winusbmgr.exe File name: winusbmgr.exe
Size: 143.36 KB (143360 bytes)
MD5: 650fdaa73d93fd4e435393dc1b6306d7
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PUBLIC%\U-2535-6853-8747
Group: Malware file
Last Updated: December 1, 2010
%USERPROFILE%\Desktop\BHome2830.exe File name: BHome2830.exe
Size: 17.24 MB (17246720 bytes)
MD5: ef85a1cde46e44af1e066cbf203697bb
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: December 7, 2010
D:\Dung Xoa\BHome2865.exe File name: BHome2865.exe
Size: 20.48 MB (20486656 bytes)
MD5: 7c9eed4ac1b71f365884e2ff6497a372
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: D:\Dung Xoa
Group: Malware file
Last Updated: December 7, 2010
%WINDIR%\system32\tusrol.dll File name: tusrol.dll
Size: 81.4 KB (81408 bytes)
MD5: f9272a870cd2f2eda1d63d6c271dc988
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 7, 2010
%WINDIR%\system32\gedbby.dll File name: gedbby.dll
Size: 95.74 KB (95744 bytes)
MD5: 133128a84759e7c9fc3a4f8fa72a4956
Detection count: 2
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 7, 2010
Loading...