Home Malware Programs Viruses VirTool:Win32/VBInject.gen!DQ

VirTool:Win32/VBInject.gen!DQ

Posted: May 7, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 222
First Seen: November 30, 2010
Last Seen: March 24, 2022
OS(es) Affected: Windows

VirTool:Win32/VBInject.gen!DQ is a malicious backdoor trojan horse that runs in the background and allows remote access to the compromised system. VirTool:Win32/VBInject.gen!DQ attempts to propagate by exploiting local networks. VirTool:Win32/VBInject.gen!DQ will also attempt to join a predefined IRC server and channel stolen data in order to participate in distributed denial-of-service (DDoS) attack. The DDoS attacks will attempt to make the computer unavailable to its intended users. Remove VirTool:Win32/VBInject.gen!DQ immediately using a reliable anti-spyware application.

Aliases

Trj/Agent.NPK [Panda]Dropper.Generic2.DRM [AVG]Trojan.Win32.VBKrypt [Ikarus]Trojan.MulDrop1.16663 [DrWeb]TrojWare.Win32.Trojan.Generic.39126140 [Comodo]Mal/VB-BL [Sophos]Trojan.Generic.4981203 [BitDefender]Trojan.Win32.VBKrypt.mm [Kaspersky]Trojan.VB-23556 [ClamAV]Win32.Trojan [eSafe]Win32:VB-OWZ [Drp] [Avast]W32/Trojan2.MMWO [F-Prot]Generic.dx!sin [McAfee]Trojan.VBKrypt.mm.cw4 [CAT-QuickHeal]Injector.SE [AVG]
More aliases (171)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\Common Files\Audio\snddrv.exe File name: snddrv.exe
Size: 503.93 KB (503939 bytes)
MD5: 137942c28269ab23067db0678d2bb8c5
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Common Files\Audio\snddrv.exe
Group: Malware file
Last Updated: March 24, 2022
%WINDIR%\system32\scdll.exe File name: scdll.exe
Size: 147.45 KB (147456 bytes)
MD5: cb6d2f3c6af2ee950c46af129556deec
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 30, 2010
C:\RECYCLER\S-1-5-21-5010821107-7099913342-267133025-5847\syscr.exe File name: syscr.exe
Size: 167.93 KB (167936 bytes)
MD5: f246ab35008652fd4d40ebd334348e40
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-5010821107-7099913342-267133025-5847
Group: Malware file
Last Updated: December 8, 2010
%WINDIR%\SysWOW64\haspemul\hasp.exe File name: hasp.exe
Size: 380.97 KB (380978 bytes)
MD5: be4e860fdb84e8e59ee3bcf4cc46e4cc
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\haspemul
Group: Malware file
Last Updated: December 17, 2012
%WINDIR%\system32\msvmcls64.exe File name: msvmcls64.exe
Size: 303.1 KB (303104 bytes)
MD5: 7aeb64f70940f105e22bec95b4acb071
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 8, 2010
C:\RECYCLER\S-1-5-21-0837735750-8924754812-092540086-6641\syscr.exe File name: syscr.exe
Size: 147.45 KB (147456 bytes)
MD5: b786ad96a1dfb330e05595e4657d8a61
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-0837735750-8924754812-092540086-6641
Group: Malware file
Last Updated: December 8, 2010
%WINDIR%\xsdll.exe File name: xsdll.exe
Size: 81.92 KB (81920 bytes)
MD5: cc2d8454df698b67544eafb0057e6e09
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: December 8, 2010
%WINDIR%\xsdll.exe File name: xsdll.exe
Size: 110.59 KB (110592 bytes)
MD5: ba4509e1dc9b36a5ffdf0a032006dd58
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: December 8, 2010
%WINDIR%\system32\drivers\CztF.exe File name: CztF.exe
Size: 94.2 KB (94208 bytes)
MD5: 5f0b844020b16d7178e0b6ac9c070c9e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: November 14, 2011
Loading...