Home Malware Programs Viruses Obfuscator.KH

Obfuscator.KH

Posted: December 1, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 206
First Seen: December 1, 2010
OS(es) Affected: Windows

Aliases

Cryptic.BJF [AVG]W32/Drooptroop.BW!tr [Fortinet]Dropper/Win32.Drooptroop [AhnLab-V3]Trojan/Win32.Drooptroop.gen [Antiy-AVL]BackDoor.DarkNess.17 [DrWeb]Trojan.Generic.KDV.76016 [BitDefender]Trojan-Dropper.Win32.Drooptroop.iwm [Kaspersky]Trojan.Gen.2 [Symantec]a variant of Win32/Kryptik.ING [NOD32]TrojanDropper.Drooptroop.iwm [CAT-QuickHeal]TR/Crypt.ULPM.Gen [AntiVir]Mal/FakeAV-CX [Sophos]SHeur3.AZBH [AVG]W32/Krypt.A!tr.dldr [Fortinet]Trojan.Win32.Scar [Ikarus]
More aliases (85)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\drivers\enternublad.exe File name: enternublad.exe
Size: 173.05 KB (173056 bytes)
MD5: 700dd5157449f185fc70f27d8436fcc7
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: December 28, 2010
%WINDIR%\system32\svrwsc.exe File name: svrwsc.exe
Size: 64 KB (64000 bytes)
MD5: c54516d42b76dfeb7702d7c7141edab0
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 9, 2010
%WINDIR%\system\lssas32.exe File name: lssas32.exe
Size: 51.2 KB (51200 bytes)
MD5: 661697e0799374d8b7c15a48110e343a
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: December 1, 2010
%APPDATA%\Microsoft-Update-Service-8758-8428-8530\winrnsmgr.exe File name: winrnsmgr.exe
Size: 56.32 KB (56320 bytes)
MD5: 96da215e231a6de8f447c3d74e6a5e4a
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft-Update-Service-8758-8428-8530
Group: Malware file
Last Updated: December 9, 2010
%WINDIR%\system\lssas32.exe File name: lssas32.exe
Size: 51.2 KB (51200 bytes)
MD5: 8f3389bba5a36e2d6e1ba719ec30281d
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: December 1, 2010
%WINDIR%\TEMP\ipbt\setup.exe File name: setup.exe
Size: 56.32 KB (56320 bytes)
MD5: e81826d375840feeb7e997fc9e246741
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\ipbt
Group: Malware file
Last Updated: December 1, 2010
%APPDATA%\Microsoft-Driver-5858-2574\winsvcrn.exe File name: winsvcrn.exe
Size: 54.27 KB (54272 bytes)
MD5: 01a1f5ae055c32cc7053a46eeefce9b9
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft-Driver-5858-2574
Group: Malware file
Last Updated: December 1, 2010
%WINDIR%\system\dwm.exe File name: dwm.exe
Size: 54.78 KB (54784 bytes)
MD5: 5dcdd917d1a8b09954e45e88a3a5134e
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: February 10, 2011
%WINDIR%\system32\inetsrv\svchost.exe File name: svchost.exe
Size: 74.92 KB (74924 bytes)
MD5: 097721e7530182822b7f77cf9597231a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\inetsrv
Group: Malware file
Last Updated: December 22, 2010
Loading...