Home Malware Programs Worms Worm.Nuqel.BE

Worm.Nuqel.BE

Posted: December 20, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 1,272
First Seen: December 20, 2012
Last Seen: January 10, 2022
OS(es) Affected: Windows

Aliases

W32/Sality.AF [Panda]Win32/Autorun.worm.267089 [AhnLab-V3]Worm/Win32.AutoIt.gen [Antiy-AVL]Win32/Yahlover.CU [eTrust-Vet]Mal/Sohana-A [Sophos]Win32.Trojan [eSafe]AutoIt:AutoRun-B2 [Wrm] [Avast]W32.SillyFDC [Symantec]Trojan.Autoit.Malformed [CAT-QuickHeal]Worm/Autoit.VQV [AVG]Worm/Win32.Sohaned [AhnLab-V3]Packed.Win32.MUPX.Gen [Comodo]W32/Sohana-BI [Sophos]HEUR:Trojan.Win32.Generic [Kaspersky]Win32:AutoIt-FK [Wrm] [Avast]
More aliases (305)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Documents and Settings\NetworkService\Local Settings\Application Data\hipomea.dll File name: hipomea.dll
Size: 10.75 KB (10752 bytes)
MD5: 4e8eef683f7076711d2acb15f4fc9b16
Detection count: 614
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Documents and Settings\NetworkService\Local Settings\Application Data
Group: Malware file
Last Updated: December 24, 2012
%WINDIR%\system32\config\systemprofile\AppData\Local\niaxama.dll File name: niaxama.dll
Size: 11.26 KB (11264 bytes)
MD5: d2a4e6dd658ba6feef3b21e5c0276756
Detection count: 136
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32\config\systemprofile\AppData\Local
Group: Malware file
Last Updated: December 24, 2012
%SystemDrive%\Users\<username>\AppData\Local\Skype\SkypePM.exe File name: SkypePM.exe
Size: 51.2 KB (51200 bytes)
MD5: 7075e56e803966247419a2d3cb9cdcba
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\Skype
Group: Malware file
Last Updated: December 24, 2012
%WINDIR%\System32\DM_Update.exe File name: DM_Update.exe
Size: 135.17 KB (135178 bytes)
MD5: cf81a9518e3a380ea6eea83e7b9cd347
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\System32\DM_Update.exe
Group: Malware file
Last Updated: October 16, 2020
%APPDATA%\bflixdaobcmnysminwx.exe File name: bflixdaobcmnysminwx.exe
Size: 1.09 MB (1094056 bytes)
MD5: ec48f829202368c97bf0fbdd2ae120b3
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 24, 2012
%APPDATA%\advantage\AdVantage.exe File name: AdVantage.exe
Size: 221.18 KB (221184 bytes)
MD5: 7690242eb8befd81d39f2f476bc8cd94
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\advantage
Group: Malware file
Last Updated: January 5, 2013
C:\Program Files (x86)\Magenta_Dictionary_Greek-English_v2010_Gold_Edition\SPASIMO\MgDE2.exe File name: MgDE2.exe
Size: 2.06 MB (2068480 bytes)
MD5: e8d741f7a970b4c7cc39d5bec69d71ed
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Magenta_Dictionary_Greek-English_v2010_Gold_Edition\SPASIMO\MgDE2.exe
Group: Malware file
Last Updated: January 30, 2022
%SystemDrive%\sooi832.bin\CA0A498245E.exe File name: CA0A498245E.exe
Size: 164.86 KB (164864 bytes)
MD5: f0cf81671f2e54071246878ccf9c70f9
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\sooi832.bin
Group: Malware file
Last Updated: January 14, 2013
%ALLUSERSPROFILE%\jdqtjacu.exe File name: jdqtjacu.exe
Size: 57.34 KB (57344 bytes)
MD5: 57507b8ebe688e4071f09d7fb0495dde
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: December 24, 2012
%SystemDrive%\system32\explorer.exe File name: explorer.exe
Size: 546.16 KB (546161 bytes)
MD5: a0557acfb3770787101c9ed1eba89383
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\system32
Group: Malware file
Last Updated: December 24, 2012
%APPDATA%\FastPing\fpNChecker.exe File name: fpNChecker.exe
Size: 477.18 KB (477184 bytes)
MD5: 6aa1b1dcbc5c8da4debce4f9362337d6
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\FastPing
Group: Malware file
Last Updated: December 24, 2012
%WINDIR%\system32\gphone.exe File name: gphone.exe
Size: 336.89 KB (336896 bytes)
MD5: 785a055364495effce9fe3b278e6ebd9
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 22, 2013
%WINDIR%\system32\gphone.exe File name: gphone.exe
Size: 1.63 MB (1636961 bytes)
MD5: 907621990d792286298d4acc2ba1a6c1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 8, 2013
%USERPROFILE%\Desktop\gphone.exe File name: gphone.exe
Size: 721.74 KB (721745 bytes)
MD5: 759ca80274db9600865f98dd29ea7d5a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: February 26, 2013
Loading...