Home Malware Programs Trojans TrojanSpy:MSIL/VB.C

TrojanSpy:MSIL/VB.C

Posted: December 8, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 279
First Seen: December 8, 2010
OS(es) Affected: Windows

TrojanSpy:MSIL/VB.C is a data theft Trojan infection which can install itself onto your computer without even prompting you about the changes which are about to appear on your PC system. TrojanSpy:MSIL/VB.C can lurk behind flashy advertisements in absolutely innocent blog or media hosting websites. TrojanSpy:MSIL/VB.C might look like a useful application, or even come bundled with a shareware program that you might need. Due to the fact that TrojanSpy:MSIL/VB.C does not have an apparent interface it can conceal itself on your computer for a long time executing its malicious actions until you realize that you have been attacked. TrojanSpy:MSIL/VB.C can collect your personal information such as banking information, logins and passwords from your computer. This information is usually collected by retracing the key stroke patterns and then saving it all in a file deep within your hard drive. TrojanSpy:MSIL/VB.C connects to a remote server and forwards the information gathered to a hacker over the network. Remove TrojanSpy:MSIL/VB.C from your computer as soon as you can.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 19561916_svchost.exe
    2 2283880F-EF87-4aac-8EBD-C9BCC8494AF5_46.avi
    3 ativtmxx32.dll
    4 isass.exe
    5 kim-kardashian-screensaver.exe
    6 msftldr.dll
    7 svhost.exe

Aliases

W32/Agent.BPA!tr [Fortinet]Win-Trojan/Agent.189952.BY [AhnLab-V3]Trojan/MSIL.Agent.gen [Antiy-AVL]Trojan.Generic.5249234 [BitDefender]Win32.TRAgent [eSafe]W32/MalwareF.VOKN [F-Prot]Artemis!603A516F086C [McAfee]Win-Trojan/Agent.183808.CD [AhnLab-V3]Troj/Mdrop-CSD [Sophos]TrojWare.MSIL.Spy.Agent.bpa [Comodo]Trojan.Generic.5303028 [BitDefender]Trojan-Spy.MSIL.Agent.bpa [Kaspersky]Artemis!B34E344C3269 [McAfee]Artemis!218A0883F59C [McAfee-GW-Edition]Trojan.Gen [Symantec]
More aliases (79)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\My Documents\My Pictures\screensavers\kim-kardashian-screensaver.exe File name: kim-kardashian-screensaver.exe
Size: 5.87 MB (5873482 bytes)
MD5: 5db77f68d0668c5e635100b7ce5aeba1
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\My Documents\My Pictures\screensavers
Group: Malware file
Last Updated: December 9, 2010
%APPDATA%\2283880F-EF87-4aac-8EBD-C9BCC8494AF5_46.avi File name: 2283880F-EF87-4aac-8EBD-C9BCC8494AF5_46.avi
Size: 81.13 KB (81130 bytes)
MD5: e4d5cd84a1371fa7bcfa3779adccd95b
Detection count: 33
Mime Type: unknown/avi
Path: %APPDATA%
Group: Malware file
Last Updated: December 9, 2010
%USERPROFILE%\My Documents\SYS\server.exe File name: server.exe
Size: 183.8 KB (183808 bytes)
MD5: b34e344c3269972396b55d18c79b4d0a
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\My Documents\SYS
Group: Malware file
Last Updated: August 15, 2011
%USERPROFILE%\Eigene Dateien\SYS\svhost.exe File name: svhost.exe
Size: 173.56 KB (173568 bytes)
MD5: 5827e711ddf081eb431b09dc6b903679
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Eigene Dateien\SYS
Group: Malware file
Last Updated: December 8, 2010
%USERPROFILE%\Documents\SYS\19561916_svchost.exe File name: 19561916_svchost.exe
Size: 196.09 KB (196096 bytes)
MD5: 218a0883f59c24b119b17b59ff013c6b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Documents\SYS
Group: Malware file
Last Updated: December 21, 2010
%USERPROFILE%\Start Menu\Programs\Startup\eflc.exe File name: eflc.exe
Size: 189.95 KB (189952 bytes)
MD5: 603a516f086c3b95d1f2f89a2396edeb
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: May 21, 2012
Loading...