Home Malware Programs Trojans TrojanSpy:MSIL/VB.G

TrojanSpy:MSIL/VB.G

Posted: April 26, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 63
First Seen: April 26, 2011
OS(es) Affected: Windows

TrojanSpy:MSIL/VB.G is a terrible trojan infection which invades your computer system without your awareness or authorization. TrojanSpy:MSIL/VB.G can be delivered via bogus online scanners or spam emails. Sometimes, when a user clicks on a flash advertisement, the download of TrojanSpy:MSIL/VB.G is started without any additional click. TrojanSpy:MSIL/VB.G functions on a targeted PC system secretly. TrojanSpy:MSIL/VB.G can communicate over the network with a third party and enable a hacker access your computer system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 basecryptaction.exe
    2 BestMP.exe
    3 cryptnet32.dll
    4 dmw.exe
    5 k1.exe
    6 mfcvid.exe
    7 ss.exe
    8 sysrun.bin.exe
    9 usxxxxxxxx.exe

Aliases

Generic Trojan__9 [Panda]PSW.Generic8.ARVW [AVG]Trojan/Win32.Gen [AhnLab-V3]TR/Spy.Gen [AntiVir]HEUR:Trojan.Win32.Generic [Kaspersky]Win32.TrojanSpyMSILV [eSafe]a variant of MSIL/Spy.Keylogger.AW [NOD32]Generic PWS.y!cwf [McAfee]TrojanSpy.KeyLogger.aw [CAT-QuickHeal]SHeur3.AZDR [AVG]Trojan.KillProc.1750 [DrWeb]Gen:Trojan.Heur.RP.rmW@a8TDC4i [BitDefender]Artemis!D7119DADA9E0 [McAfee]W32/Injector.fam!tr [Fortinet]TrojWare.Win32.PkdKrap.ai2 [Comodo]
More aliases (97)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\JavaUpdateManager\JavaUpdateManager\1.0.0.0\Microsoft\dmw.exe File name: dmw.exe
Size: 186.88 KB (186880 bytes)
MD5: 56d37e85fa641963c0de656254259c61
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\JavaUpdateManager\JavaUpdateManager\1.0.0.0\Microsoft
Group: Malware file
Last Updated: April 26, 2011
%APPDATA%\Adobe\Update\mfcvid.exe File name: mfcvid.exe
Size: 289.28 KB (289280 bytes)
MD5: d7119dada9e01b2115469254468468db
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Adobe\Update
Group: Malware file
Last Updated: May 9, 2011
%SystemDrive%\usxxxxxxxx\usxxxxxxxx.exe File name: usxxxxxxxx.exe
Size: 370.17 KB (370176 bytes)
MD5: 2599324aa74a4bb44d5e58c1545fda47
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\usxxxxxxxx
Group: Malware file
Last Updated: April 28, 2011
%WINDIR%\system32\k1.exe File name: k1.exe
Size: 3.46 MB (3462144 bytes)
MD5: ad01ae5b947e8a7c23f56f271e2284c2
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 28, 2011
%ALLUSERSPROFILE%\12da4b\BestMP.exe File name: BestMP.exe
Size: 2.43 MB (2438656 bytes)
MD5: 23e69965ec0397f29aaea96b0dd36a74
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\12da4b
Group: Malware file
Last Updated: April 29, 2011
%WINDIR%\system32\basecryptaction.exe File name: basecryptaction.exe
Size: 148.99 KB (148992 bytes)
MD5: 5f284698b16733f5ffc905dc533c3f45
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 29, 2011
%WINDIR%\inf\ss.exe File name: ss.exe
Size: 669.69 KB (669696 bytes)
MD5: 4d9de958be82dee68facd177671d5938
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\inf
Group: Malware file
Last Updated: April 28, 2011
C:\svchoste.exe File name: svchoste.exe
Size: 110.59 KB (110592 bytes)
MD5: efd9f8b1e12053d63b0e993d060eb5b8
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: C:
Group: Malware file
Last Updated: May 2, 2012
%WINDIR%\system32\cryptnet32.dll File name: cryptnet32.dll
Size: 49.15 KB (49152 bytes)
MD5: d5a6aa40d9ae3b689a8b3d7c93aa3f4c
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 28, 2011
Loading...