Home Malware Programs Trojans VirTool:MSIL/Obfuscator.P

VirTool:MSIL/Obfuscator.P

Posted: December 20, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 4,637
First Seen: December 20, 2012
Last Seen: December 22, 2023
OS(es) Affected: Windows

Aliases

AdInstaller.InstallQ [AVG]Riskware/InstallIQ [Fortinet]InstallQ [Sophos]Adware/InstallC.B.1 [AntiVir]Adware.W3i.9 [DrWeb]W32/InstallCore.L.gen!Eldorado [F-Prot]HackTool/NetCat.C [Panda]NetCat.A [AVG]not-a-virus:RemoteAdmin.Win32.NetCat [Ikarus]Win32:Neptunia-BA [GData]Win-AppCare/NTSniff_v111.61440 [AhnLab-V3]RemoteAdmin/Win32.NetCat.gen [Antiy-AVL]NetCat [Sophos]SPR/Tool.NetCat.B [AntiVir]Tool.Netcat.87 [DrWeb]
More aliases (332)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\PoWeR-Script\mIRC.exe File name: mIRC.exe
Size: 2.76 MB (2769988 bytes)
MD5: fca0de333be3df60fdd8e5a5ae1b6937
Detection count: 2,363
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\PoWeR-Script\mIRC.exe
Group: Malware file
Last Updated: February 23, 2025
%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe File name: wins.exe
Size: 2.68 MB (2680832 bytes)
MD5: eaeb69760d56ecb0e56071f57e22051b
Detection count: 108
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service
Group: Malware file
Last Updated: December 24, 2012
%PROGRAMFILES%\KoreanKeyword\WinKeyword_Up.exe File name: WinKeyword_Up.exe
Size: 122.92 KB (122920 bytes)
MD5: 466adfc8c552ad9f8d2140f09fb6df57
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\KoreanKeyword
Group: Malware file
Last Updated: December 24, 2012
C:\Total Commander PowerUser v43\Programm\pspr\psprserv.exe File name: psprserv.exe
Size: 21.5 KB (21504 bytes)
MD5: be2cd89472e0719e42f72da101dd0cb0
Detection count: 89
File type: Executable File
Mime Type: unknown/exe
Path: C:\Total Commander PowerUser v43\Programm\pspr\psprserv.exe
Group: Malware file
Last Updated: December 22, 2023
%SystemDrive%\Users\<username>\AppData\Roaming\_bd_uylzs.exe File name: _bd_uylzs.exe
Size: 237.05 KB (237056 bytes)
MD5: e2ff13d5727736c689d201337842d27d
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: January 5, 2013
%SystemDrive%\AKINSOFT\CafePlus10\Server\CafePlus.exe File name: CafePlus.exe
Size: 13.84 MB (13849088 bytes)
MD5: b4cb7ebc48698e0ad2c47c6ce91889ec
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\AKINSOFT\CafePlus10\Server
Group: Malware file
Last Updated: June 12, 2022
%WINDIR%\system32\KAward\wak.exe File name: wak.exe
Size: 3.38 MB (3383296 bytes)
MD5: 8c3909d97471da7f1ca3402344bd8b44
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\KAward
Group: Malware file
Last Updated: December 24, 2012
%TEMP%\013b2e8c4723.exe File name: 013b2e8c4723.exe
Size: 245.79 KB (245792 bytes)
MD5: 95f0086c5b2d1251da94081a6e58c4b3
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 24, 2012
%ALLUSERSPROFILE%\Start Menu\Programs\Startup\simple worm.exe File name: simple worm.exe
Size: 28.67 KB (28672 bytes)
MD5: 67f9f2a67b6a95d52a4d8969428c46a4
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 24, 2012
%USERPROFILE%\Belgelerim\blog.metin2sozluk.com efsun botu (XP)[TR].dll File name: blog.metin2sozluk.com efsun botu (XP)[TR].dll
Size: 74.24 KB (74240 bytes)
MD5: 2911d401347ff85befcc4bd4c08b4d0d
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\Belgelerim
Group: Malware file
Last Updated: December 24, 2012
%APPDATA%\Microsoft\dwm32.exe File name: dwm32.exe
Size: 2.02 MB (2027008 bytes)
MD5: 971224980f0ed166af3817c9a92cd07f
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft
Group: Malware file
Last Updated: December 24, 2012
C:\Users\<username>\Desktop\Switch_Sicherung\netcat_10053\nc.exe File name: nc.exe
Size: 61.44 KB (61440 bytes)
MD5: 4513eddf539ba4b8dfa3d363a6fe7bbc
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\Switch_Sicherung\netcat_10053\nc.exe
Group: Malware file
Last Updated: May 4, 2023
%APPDATA%\Microsoft\Protect\Credentials\crss.exe File name: crss.exe
Size: 9.72 KB (9728 bytes)
MD5: 5e16a6910136a1cbb78ae59e54c547d7
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Protect\Credentials
Group: Malware file
Last Updated: December 24, 2012
%USERPROFILE%\Start Menu\Programs\Startup\AdobeUpdate.exe File name: AdobeUpdate.exe
Size: 1.2 MB (1204224 bytes)
MD5: 3534f828a722c3da16a8f3c3b1124e4b
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 24, 2012
%LOCALAPPDATA%\dauocwxi\lgmbmwey.exe File name: lgmbmwey.exe
Size: 101.19 KB (101192 bytes)
MD5: 94a409952637ba76977857bf86b3f9d7
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\dauocwxi
Group: Malware file
Last Updated: December 24, 2012
%USERPROFILE%\??????? ????\??????\eg.exe File name: eg.exe
Size: 4.81 MB (4813006 bytes)
MD5: 3e04fcddb735d10d158f52771ef47406
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\??????? ????\??????
Group: Malware file
Last Updated: December 24, 2012
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\.exe File name: .exe
Size: 702.15 KB (702155 bytes)
MD5: 2462e0045953d367a67289fb69f93bdd
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: December 24, 2012
%USERPROFILE%\Downloads\MyApp.exe File name: MyApp.exe
Size: 512.51 KB (512516 bytes)
MD5: 9b955a7844b7952e072923eed422fd96
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Downloads
Group: Malware file
Last Updated: December 24, 2012
Loading...