Home Malware Programs Viruses VBInject.FF

VBInject.FF

Posted: June 13, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 344
First Seen: June 13, 2011
Last Seen: May 5, 2020
OS(es) Affected: Windows

Aliases

Sus/Behav-1021 [Sophos]a variant of Win32/Kryptik.PCO [NOD32]unknown virus Win32/DH.CAFF820373 [AVG]Trojan/Win32.FakeAV [AhnLab-V3]Trojan.FakeAV.6369 [DrWeb]Trojan.Generic.KD.253534 [BitDefender]Hoax.Win32.ExpProc.abiz [Kaspersky]FakeAlert-Rena.n [McAfee]TR/Patched.131072 [AntiVir]PUA.Packed.PECompact-1 [ClamAV]Generic.dx [McAfee]Mal/FakeAV-MQ [Sophos]Gen:Variant.Dropper.49 [BitDefender]Hoax.Win32.ExpProc.abtt [Kaspersky]Downloader.Agent2.AOKS [AVG]
More aliases (182)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\csrss.exe File name: csrss.exe
Size: 195.07 KB (195072 bytes)
MD5: 5ebf216c64cdd599f9bfca46f8fb275d
Detection count: 124
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 16, 2011
%USERPROFILE%\Downloads\Warcraft 3 Reign Of Chaos + The Frozen Throne\WC3 RC\install.exe File name: install.exe
Size: 118.78 KB (118784 bytes)
MD5: bae994f7827a64e3f1cd75c1805b8e0b
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Downloads\Warcraft 3 Reign Of Chaos + The Frozen Throne\WC3 RC
Group: Malware file
Last Updated: June 17, 2011
%USERPROFILE%\Impostazioni locali\Dati applicazioni\yja.exe File name: yja.exe
Size: 344.06 KB (344064 bytes)
MD5: 3cdea7387ef2c5faaae2237b81833a27
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Impostazioni locali\Dati applicazioni
Group: Malware file
Last Updated: June 20, 2011
%TEMP%\DAT56.tmp.exe File name: DAT56.tmp.exe
Size: 65.68 KB (65688 bytes)
MD5: 6f43afe06b2d6a5a7086346500901154
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 14, 2011
%APPDATA%\Microsoft\Windows\Templates\1787_16964\npkusvc.exe File name: npkusvc.exe
Size: 3.56 MB (3564032 bytes)
MD5: 562bb709e72b2df2deff1f7722e52f66
Detection count: 42
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Templates\1787_16964
Group: Malware file
Last Updated: June 16, 2011
%WINDIR%\SysWOW64\destract.exe File name: destract.exe
Size: 1.82 MB (1822208 bytes)
MD5: 500c27d19e50e8ffb15351c5a1d57cf4
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: June 16, 2011
%SystemDrive%\Documents and Settings\NetworkService\Local Settings\Application Data\xxh.exe File name: xxh.exe
Size: 335.87 KB (335872 bytes)
MD5: 835a0181b09dbbdae8a59460699c8cbd
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\NetworkService\Local Settings\Application Data
Group: Malware file
Last Updated: June 20, 2011
Loading...