Home Malware Programs Viruses Obfuscator.PO

Obfuscator.PO

Posted: June 2, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 515
First Seen: June 2, 2011
OS(es) Affected: Windows

Aliases

Generic22.BAIS [AVG]W32/Yakes.CX!tr [Fortinet]Trojan.Win32.Meredrop [Ikarus]Trojan/Win32.Yakes.gen [Antiy-AVL]Trojan.DownLoader2.60536 [DrWeb]Trojan.Generic.6134154 [BitDefender]Trojan.Win32.Yakes.gf [Kaspersky]W32/Oficla.AI.gen!Eldorado [F-Prot]a variant of Win32/Kryptik.OZI [NOD32]Generic.dx!zux [McAfee]Virus.Win32.Rootkit [Ikarus]Trojan.Rootkit.GEN [Sunbelt]Mal/Generic-A [Sophos]UnclassifiedMalware [Comodo]Win32.GenericBackDoo [eSafe]
More aliases (55)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\TEMP\omwc\setup.exe File name: setup.exe
Size: 32.25 KB (32256 bytes)
MD5: 64de665a831f7eb595420a94f6b6c1ed
Detection count: 337
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\omwc
Group: Malware file
Last Updated: June 30, 2011
%WINDIR%\TEMP\xjgu\setup.exe File name: setup.exe
Size: 33.79 KB (33792 bytes)
MD5: d985f2c34f5cf7d3b0e65a8d2fab0ade
Detection count: 133
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP\xjgu
Group: Malware file
Last Updated: June 2, 2011
%TEMP%\rdfhost.exe File name: rdfhost.exe
Size: 1.17 MB (1171456 bytes)
MD5: e649ce4d2584b8563ee17f384335ffaa
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 6, 2011
%TEMP%\8sbfmh.exe File name: 8sbfmh.exe
Size: 90.11 KB (90112 bytes)
MD5: 6dccf0114e76f4f4ea4922fc3c7d8e27
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 6, 2011
%USERPROFILE%\My Documents\Downloads\Compressed\moonlight\IlvMoney1154.sys File name: IlvMoney1154.sys
Size: 31.87 KB (31872 bytes)
MD5: 2684a6868f5ee43bc1f9147b6e847c66
Detection count: 7
File type: System file
Mime Type: unknown/sys
Path: %USERPROFILE%\My Documents\Downloads\Compressed\moonlight
Group: Malware file
Last Updated: June 6, 2011
Loading...