Threats report from 7.4521 up to 7.5166– 1/17/2010

Newly Added Threat List

bifrost\ggg.exe
Bifrost\Server.exe
cisvc.exe
csrss.exe
dllhst3g.exe
epaojo\qckfsysguard.exe
ErrorView\Bags grey.exe
ErrorView\EACH MESS HEART SECT.exe
ikrelh\uiucsysguard.exe
inetinfo.exe
lsass.exe
mhamol\owumsysguard.exe
Microsoft\comrepl.exe
Microsoft\mstinit.exe
Microsoft\svchost.exe
Microsoft\winlog.exe
PC\agent.exe
rmeckq\dioisysguard.exe
services.exe
shsyed\ehlxsysguard.exe
smss.exe
spoolsv.exe
vigaze\2497.exe
winlogon.exe
70501.exe
78554949.exe
Brengkolang.com
data.tmp
.pif
11122007.exe
40.exe
AutoRun.vbs
backupuser.exe
Classified.exe
classified\Classified.exe
Documents and Settings.exe
Extracted\by-bin-althani .exe
Extracted\SERVER.exe
HoT.pif
Inetpub.exe
Inetpub\Inetpub.exe
Inetpub\wsock32.dll
Inetpub\wwwroot.exe
Inetpub\wwwroot\wsock32.dll
Inetpub\wwwroot\wwwroot.exe
Program Files.exe
q9.cmd
Read1st.exe
system.exe
WINDOWS.exe
yudald.bat
Adobe.exe
Adobe\wsock32.dll
auto.exe
Classified.exe
Common Files.exe
designer.exe
MSSoap.exe
MSSoap\wsock32.dll
ODBC.exe
ODBC\wsock32.dll
Services.exe
SpeechEngines.exe
System.exe
System\admin.obj
System\QQjiji.exe
System\wsock32.dll
wsock32.dll
Adobe.exe
Bifrost\antyvirus.exe
bifrost\ggg.exe
Bifrost\Image.exe
Bifrost\Server.exe
Cheat Engine\dbk32.sys
Classified.exe
ComPlus Applications.exe
d\4300_1.exe
iexplorer\iexplorer.exe
ik\dat2txt.exe
ik\ik.exe
Internet Explorer.exe
Internet Explorer\HSfRt.exe
Internet Explorer\OyLwJUt.exe
Internet Explorer\wsock32.dll
InternetSecurity2010\IS2010.exe
Legion\Legion.exe
Legion\NETTOOLS.DLL
Malware Professional\Malware
Massenger Live\server.exe
Messenger.exe
Messenger\wsock32.dll
micro\hosts.exe
Microsoft Common\svchost.exe
microsoft frontpage.exe
microsoft frontpage\version3.0
microsoft frontpage\wsock32.dll
Microsoft Office\WINWORD.EXE
mIRC\IRC Bot\services.exe
mIRC\IRC Bot\svchost.exe
mouser.exe
Movie Maker.exe
Movie Maker\wsock32.dll
MSN Gaming Zone.exe
MSN Gaming Zone\OzMwJv.dll
MSN Gaming Zone\wsock32.dll
MSN.exe
MSN\MSNCoreFiles\wsock32.dll
MSN\MSNIA\wsock32.dll
MSN\MsnInstaller\ws2help.dll
MSN\MsnInstaller\wsock32.dll
MSN\wsock32.dll
MySearch\bar\1.bin\NPMYSRCH.DLL
MySearch\bar\1.bin\S42NS.EXE
MySearch\bar\1.bin\S4BAR.DLL
MyWebSearch\bar\1.bin\M3MSG.DLL
MyWebSearch\bar\2.bin\M3MSG.DLL
NetMeeting.exe
NetMeeting\NetMeeting.exe
NetMeeting\wsock32.dll
Online Services.exe
Online Services\wsock32.dll
Outlook Express.exe
Outlook Express\wsock32.dll
Program Files.exe
server.exe
setup SoftCam new.exe
SiLeNtt\server.exe
skaypey\server.exe
VMware.exe
Web Publish.exe
Web Publish\LOGFILES.exe
Web Publish\Web Publish.exe
Web Publish\wsock32.dll
win32GI\win24.exe
wincrak\payload.exe
Windows Media Player.exe
Windows Media Player\Sample
Windows Media Player\Skins.exe
Windows Media Player\Windows
Windows NT.exe
Windows NT\Pinball\wsock32.dll
windows\system32.exe
WinPcap.exe
WinPcap\ws2help.dll
xerox.exe
xerox\csrss.exe
xerox\ntldll.dll
zzToolBar\ToolBand.dll
zzToolBar\Toolbar_bho.dll
zzToolBar\Uninstall.exe
1025.exe
1028.exe
1031.exe
1033.exe
1037.exe
1041.exe
1042.exe
1054.exe
12520850o.exe
13E92A\internet.fne
13E92A\RegEx.fnr
13E92A\shell.fne
13E92A\spec.fne
1CB5AD\AA2E5E.EXE
2052.exe
3.exe
306A39\00C3AC.EXE
306A39\com.run
306A39\dp1.fne
306A39\eAPI.fne
306A39\internet.fne
306A39\RegEx.fnr
306A39\shell.fne
306A39\spec.fne
306A39\spec_a.fne
3076.exe
3com_dmi.exe
90C331\1066BA.EXE
9el9.dll
aa.dll
acleditz.exe
actskin4.ocx
afmain0.dll
algs.exe
AMC.exe
ar12A40097dll.dll
ar12B309dll.dll
ar12B309exe.gho
av_md.exe
bdfjb.dll
bEvtService.exe
bfwc.bwo
Bifrost\server.exe
blastclnn.exe
c60ax.exe
CatRoot.exe
CbEvtSvc.exe
Cerberus\iexplorer.exe
cltmon.exe
cmsetac.dll
Com\comadmine.dll
cpcp.cpo
critical_warning.html
crss.exe
CstbsKaRI.exe
DD33D3\00C3AC.EXE
ddoskey.exe
dfefa.dll
DirectX\SVCHOST.EXE
djaeb.dll
djzu2m2k.exe
dllcache\explorer.exe
dlllhost.exe
dnscon70.dll
driverrs\adv9n5.dll.exe
drivers\b8ddb52d.sys
drivers\e8152736.sys
drivers\fio32.sys
drivers\H8SRTldgxbvpuyi.sys
drivers\oha4e70.sys
drivers\tkkobe.sys
drivers\ziucvugkdjiut7.sys
drivers\zrqpwlydsdqdn9.sys
europa.exe
EXPLORER.EXE
f3PSSavr.scr
fbfjb.dll
fft.dll
fio32.dll
firewal.exe
flashcpx.dll
flk.dll
fservice.exe
ftdutil.exe
Gfocx\01.swf
GtOEvNEuMC.exe
hf0008.exe
hsv.dll
iexplore.exe
ik.dll
ilv.dll
imgrt.com
jdv.dll
jpk.dll
kb014201044.dll
kb016181219.dll
kb816181218.dll
lncom.exe
lncom_.exe
logon.exe
lynknd.kll
mjk.dll
mmbank.exe
mmmsawcbk.dll
mmmshbvzj.dll
mpor.yuo
msconfigser.exe
msilojzb.dll
msmsgs.exe
msn.exe
mstcpcon20.dll
MsTecs.exe
msxslt3.exe
netmanage.dll
netused.dll
nmdfgds0.dll
nmdfgds1.dll
nmdfgds2.dll
notepad.dll
ntdtcstp.dll
ntos.exe
ntvxdc.exe
nvcpl.exe
olhrwef.exe
owner.exe
ozccmc.fdf
pNpI5xKliFgHD.vbs
poye.exe
pozpjy.dll
qbt.dll
qtplugin.exe
rdkewti.exe
rdshost.dll
reader_s.exe
reginv.dll
rswpscfg.dll
s.exe
sarah.dll
ScPbNtKv.exe
scvhost.exe
sdra64.exe
server.exe
sfc32.dll
skype.exe
spooIsv.exe
spool\prtprocs\w32×86\1.tmp
Spy-Net\server.exe
SR1000R.DLL
ss12C40088dll.dll
ss12C704dll.dll
stub.dll
svc.exe
svchost\svchost.exe
syste2.dll
system.exe
t320038.dll
t322023.dll
t329078.dll
taskmrg.exe
tbtKc.exe
TfmktrD.dll
tftp.nfo
twk.dll
ucv.dll
urt.dll
vigaze\2497.exe
vtt.dll
wbem\proquota.exe
wcsydrv.exe
wfmngr.exe
winamp.exe
windows.exe
windows\cpu1x.exe
winfiles.exe
winkey.dll
winlogon86.exe
winnet.dll
winserv.exe
winsfdx.exe
wintgtsv.exe
winupdate86.exe
wmimgr32.dll
wmitpfs.dll
wuauclt.dll
wupmgr.exe
xm1985.dll
Xx\sys.exe
.txt
_A00F1A17B.exe
_A00F1A41A.exe
_A00F1A4B7.exe
_A00F1A795.exe
_A00F1A92B.exe
_A00F33EB0.exe
_A00F33F8B.exe
_A00F34334.exe
_A00F3442E.exe
_A00F3445D.exe
_A00F3446D.exe
_A00F3447C.exe
0.7055475.exe
0001A60E_Rar\00C3AC.EXE
00033B93_Rar\00c3ac.exe
00033CCB_Rar\00c3ac.exe
000340F2_Rar\00C3AC.EXE
00034111_Rar\00C3AC.EXE
1.exe
1.tmp
195617333.dll
2.exe
2.tmp
283899.exe
3.tmp
4.tmp
4tddfwq0.dll
4tddfwq1.dll
992115.exe
A.tmp
admin6.exe
aimbot v1.0.exe
alcoholic.exe
Avira License gen v2.exe
avp.exe
bot.exe
clspackxq.exe
cmcfg3.dll
CPA_311.exe
CryptedFile.exe
dbmsadsnm.dll
dcgwhpoh.exe
Del2.tmp
dhdhtrdhdrtr5y
djzu2m2k.exe
E_4\dp1.fne
E_4\eAPI.fne
E_4\internet.fne
E_4\shell.fne
E_4\spec.fne
E_N4\dp1.fne
E_N4\internet.fne
E_N4\shell.fne
E_N4\spec.fne
EULA.exe
Expor.exe
FileTmp.exe
firefox-update.exe
gsf2\5yn.udp
gsf2\servces.exe
ibaynllxdly.exe
iexplorer.exe
is-FQ3AN.tmp\killdll.dll
is-N6BPQ.tmp\killdll.dll
IXP000.TMP\1.exe
IXP000.TMP\3.exe
IXP000.TMP\BIFROS~1.EXE
IXP000.TMP\CRYPTE~1.EXE
IXP000.TMP\hgo-fr7p.exe
IXP000.TMP\KEYGEN~1.EXE
IXP000.TMP\play.exe
keygen.exe
lsass.exe
mbcox32.exe
msgygnsb.dll
MvNetdhcp.exe
ntload.dll
Out.exe
pdvwd.exe
PI2.3.2_2\Poison Ivy 2.3.2.exe
player006.exe
POSTAL.EXE
ppp.exe
Private exe Protector.exe
qqa2.tmp
questservice.dll
RarSFX0\admin.exe
RarSFX0\apdfpr.exe
RarSFX0\config.exe
RarSFX0\Dr.MOT.exe
RarSFX0\RAS.exe
RarSFX0\RockXp_.exe
RarSFX0\xpkey.exe
resumindo.exe
server.exe
server1.exe
services
SignatureZero\SignatureZero.exe
snebar.exe
sta1.exe
sta2.exe
Steam.dll
tdlclk.dll
tdlcmd.dll
tdu.tmp
tempfile.exe
tmp.tmp
trikfx\spomenar.exe
udhkiixx.exe
up.exe
Urinal.exe
winhelper86.dll
winlogon86.exe
winupdate86.exe
wscript.exe
wscsvc32.exe
xqa1.tmp
xsa1.tmp
xvassdf.exe
y16\pic7020.pif
y16\r.lnk
y16\rr.lnk
zpskon_1260756872.exe
zpskon_1260767977.exe
Adobe Gamma Loader.com
Empty.pif
isqsys32.exe
kav7.0.1.325en.exe
kav7.0.1.325fr.exe
rarype32.exe
scandisk.dll
101.exe
11122007.exe
11122oo7.exe
123.exe
360safe.exe
addins.exe
addins\HSeQb.dll
alg.exe
apocalyps32.exe
AppPatch.exe
AvastSS.com
Bifrost\server.exe
Cache.exe
Cache\Cache.exe
cam\sys.exe
Classified.exe
cmsetac.dll
Config.exe
Connection Wizard.exe
Cursors.exe
Debug.exe
dns.exe
Driver Cache.exe
e7df.exe
ehome.exe
eksplorasi.exe
explorer.new
Help.exe
Help\F3C74E3FA248.dll
Help\F3C74E3FA248.exe
hinhem.scr
ieocx.dll
ime.exe
ini\ini.exe
ini\shit.vbs
java.exe
just1241664.exe
ld16.exe
lsass.exe
Media.exe
Microsoft.NET.exe
mPsvc64.exe
msagent.exe
msagent\bibinho.exe
msagent\msnwab.exe
msagent\sendto.exe
msapps.exe
mstwain32.exe
mui.exe
ntdtcstp.dll
Offline Web Pages.exe
Offline Web Pages\Offline Web
open cam 1.7.exe
pchealth.exe
pchealth\1.exe
PeerNet.exe
PPlayer.2.1.58130.251.(508).dll
Prefetch.exe
Provisioning.exe
rdr_1260741674.exe
rdr_1260741758.exe
rdr_1260745677.exe
rdr_1260745767.exe
Registration.exe
repair.exe
repair\repair.exe
repair\samKwITFR.dll
Resources.exe
scssrr.exe
scvhost.exe
security.exe
services.exe
ShellNew\sempalong.exe
SoftwareDistribution.exe
spoolsv.exe
srchasst.exe
srchasst\srchasst.exe
srsdllpro.exe
SVCHOST.EXE
sysblt.exe
system.exe
system\sservice.exe
system\svchost.exe
system32:lzx32.sys
system32:skype.exe
Temp\_ISTMPI.DIR\autorun.inf
Temp\_ISTMPI.DIR\mmc32.exe
Temp\_ISTMPI.DIR\template.tmp
Temp\8.tmp
Temp\ntload.dll
Temp\spoolsv\a.reg
Temp\spoolsv\mirc.ini
Temp\spoolsv\run.bat
Temp\spoolsv\spoolsv.exe
Temp\wpv051260187840.exe
userinit.exe
virscan.exe
WIN_UPD32.exe
win32trxf.exe
WINDOWS.exe
Windows32.dll
winfiles.exe
winhelp32.exe
winlogonn.exe
winnt.exe
winvdll.exe
xcopy.exe
xmac\xmac.exe
xxxxxxx.x1x
iexplo.exe
services.exe