Home Malware Programs Worms Worm.Koobface.AW

Worm.Koobface.AW

Posted: November 1, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 133
First Seen: November 1, 2011
Last Seen: October 8, 2019
OS(es) Affected: Windows

Aliases

Trojan.Generic.7085756 [BitDefender]Trojan.Generic.7082907 [BitDefender]Trojan.Win32.Patched [Ikarus]Trojan/Win32.Patched.gen [Antiy-AVL]W32/Footle-A [Sophos]Trojan.Generic.7083678 [BitDefender]Trojan.Win32.Patched.nn [Kaspersky]Win32:Patched-ADQ [Trj] [Avast]W32/FakeAV.OZ!tr [Fortinet]Mal/FakeAV-OZ [Sophos]Trojan-FakeAV.Win32.SystemRestore.d [Kaspersky]a variant of Win32/Kryptik.UVJ [NOD32]Generic FakeAlert.fc [McAfee]Trojan/Win32.Agent [AhnLab-V3]Trojan.Win32.Agent.pymt [Kaspersky]
More aliases (117)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\ftppost2.exe File name: ftppost2.exe
Size: 57.34 KB (57344 bytes)
MD5: 5a964755038c5c0a9008177967f1a730
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: November 1, 2011
%TEMP%\netiepad.dll File name: netiepad.dll
Size: 54.27 KB (54272 bytes)
MD5: adaa4a0d2f7309bd69769af09a669a01
Detection count: 53
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: November 3, 2011
%WINDIR%\system32\vmusbw32.dll File name: vmusbw32.dll
Size: 161.79 KB (161792 bytes)
MD5: fc9ef34a204535d1c40dbebeafaefb1a
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 8, 2011
%WINDIR%\aadrive32.exe File name: aadrive32.exe
Size: 90.11 KB (90112 bytes)
MD5: ab3cb543390d53531a866fb9a6c74866
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: November 8, 2011
%ALLUSERSPROFILE%\Application Data\6DSS92c31Apgjk.exe File name: 6DSS92c31Apgjk.exe
Size: 303.09 KB (303096 bytes)
MD5: bf47034c58f0c268037af2588d5be73f
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: November 10, 2011
%ALLUSERSPROFILE%\Datos de programa\drops\Photoshop.exe File name: Photoshop.exe
Size: 1.77 MB (1772544 bytes)
MD5: b24f090f200f720a4a2c2abc3a08603e
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Datos de programa\drops
Group: Malware file
Last Updated: November 3, 2011
%WINDIR%\system32\winlogon.exe File name: winlogon.exe
Size: 507.9 KB (507904 bytes)
MD5: f1b853e906761fe4ee4356ad61cf5057
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 3, 2011
%ALLUSERSPROFILE%\Application Data\rundll32.exe File name: rundll32.exe
Size: 368.64 KB (368640 bytes)
MD5: 52c1b257f9e6f29f834d6729063f2d86
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: November 3, 2011
%ALLUSERSPROFILE%\Application Data\MgKPyEORiQUvGj.exe File name: MgKPyEORiQUvGj.exe
Size: 400.88 KB (400880 bytes)
MD5: 81be2832d96176835fae74530d6d0d5d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: November 8, 2011
%WINDIR%\Explorer.exe File name: Explorer.exe
Size: 1.05 MB (1058816 bytes)
MD5: 2f58e8791c7a1f61fd35baeb73b0e9be
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: January 10, 2012
Loading...