Packed.Monder.gen

Description: Unclassified Threat
Risk Level: Medium
Date of First Occurence: Monday, April 14, 2008
Software Developer: (unknown)
Brief Info: Unclassified threats are threats that are not properly sorted or threats having an unknown publisher.
Removal: This threat can be removed using "Spyware Terminator"

ELIMINAR SPYWARE »

Geographical Distribution of Threat "Packed.Monder.gen"

Threat Info

View All

Detected Items

  1. Detected Files: %SYSDIR%\dmdmv.exe MD5: 094B3413CBA71B93F04B8A70EE517ACE Size:60416 %SYSDIR%\khfGWQjJ.dll MD5: F94607C76A9ACA21CD6EBEB5D44671B1 Size:36352 %DESKTOP%\Adobe Photoshop CS3 keygen fully working (WTF)\Adobe PhotoShop CS3 keygen WTF.exe MD5: FA969D78B8102D3D8FD00829814C4F16 Size:519168 %SystemDiskRoot%\Downloads\PowerISO v4.0 + [AGAiN keygen]\keygen.exe MD5: 3267F300E618BD10B5501A760E5E7229 Size:119296 %SYSDIR%\efeffec.dll MD5: C721DB9951ACDDE08E0770AF9FEFACBC Size:38400 %SYSDIR%\.5c2435d8\5c2435d8.exe MD5: BBD77BDE2463C10E3ED09B951B91BC87 Size:45056 %TEMP%\nyps4.exe MD5: 6CEE7A78A0CB1F576D8348B8044CCD62 Size:53248 %SYSDIR%\vtUnkkkj.dll MD5: D94AA36F367C09AE05F1260EF215DA63 Size:36864 d:\Downloads\NetLimiter 2 Pro v2.0.10.1 ( SERIAL KEY INCL)\nl_2010_pro.exe MD5: 4D0C4CB8D1A3866EFA7083D849893DCA Size:2813440 f:\INTERNET\Hide IP\05.05.2008=HideIP 3.5\05-05-2008-Hide.IP.Platinum.3.5___KeyGen___Screenshots\Hide.IP.Platinum.3.5 + KeyGen + Screenshots\Keygen\Hide.Ip.Platinum.3.xx.keygen.exe MD5: 98C5EF4FE7B27BDB6AE27A6CD158CF09 Size:224256 f:\INTERNET\Hide IP\05.05.2008=HideIP 3.5\05-05-2008-Hide.IP.Platinum.3.5___KeyGen___Screenshots\Hide.IP.Platinum.3.5 + KeyGen + Screenshots\Hide.IP.Platinum.3.5.EXE MD5: 11076E5567F23630A1601010AAED123C Size:913408 %SYSDIR%\fcccaay.dll MD5: 40D3173C04C6CC1E1C4305EDCED8C51A Size:37376 f:\download\c\cod4 multiplayer.exe MD5: D9357A866B18AEA7E6DCC3269D236DDC Size:158484 %DESKTOP%\windowsxpsp2activationcrack.zip.exe MD5: 0B0BEDE20EC55F1110D9E6AA1FD01E6B Size:196220 %TEMP%\urqNHAst.dll MD5: 9ACF35F40D8E9B8F90A915BC2B7DCB26 Size:36352 %SYSDIR%\wvuvvstr.dll MD5: C5C910EBA4D56469A27279418996C823 Size:38912 %SYSDIR%\tuvwwut.dll MD5: B1CF58705F9889834A2A5862C68F5093 Size:36352 d:\Apa\Progik\DAEMON Tools Pro v4.10.218.0\DTPro4100218Advanced.exe MD5: 2F63D298F6499F639411D19C2A3C8297 Size:7314944 e:\Downloads 2008-04\Garmin Unlock Utility\03 - IMEI Converter v1.0 - Only needed for Cellphones\IMEI converter.exe MD5: D52FED0AAB773018B98DA0DFD007AA48 Size:410112 e:\Downloads 2008-04\Garmin Unlock Utility\02 - Garmin Keygen v1.2\Keygen v1.2.exe MD5: 1ABF6B6FAD90CC28B86869D5D8CCA040 Size:499200 %SYSDIR%\yayxvtRI.dll MD5: A88EE239AC5B7F9D8DC4F425364D9821 Size:36352
  2. Detected Files with variable Filenames: MD5: A6C1556EB3A992B11A2753C91197FD45 Size: 37376 %SYSDIR%\urqOHWoM.dll %SystemDiskRoot%\System Volume Information\_restore{E1867C21-4450-4092-8D00-D65D6D172B70}\RP351\A0086933.dll %SYSDIR%\geBqRhHB.dll %SystemDiskRoot%\Documents and Settings\Internet\Local Settings\Temp\mlJApNge.dll %SYSDIR%\vtUOETmK.dll %SYSDIR%\geBqOhGy.dll %USERPROFILE%\Local\Temp\ddccbccc.dll %SYSDIR%\xxyaywTn.dll MD5: B894569C61E5C110EC2C018802780E20 Size: 39424 %SYSDIR%\wvurrsq.dll %SYSDIR%\efcbbab.dll %SYSDIR%\khfghfg.dll %SYSDIR%\awttrpq.dll %SYSDIR%\nnnligh.dll %SYSDIR%\qomkjji.dll %SYSDIR%\cbxwurr.dll %SYSDIR%\rqrssst.dll c:\Windows\System32\yaywvts.dll c:\Users\GBOR\AppData\Local\Temp\tmp00015714 c:\Users\GBOR\AppData\Local\Temp\tmp0000a1f9 and next 2 variations. MD5: D216D13CA4DC92A45890DA058A4C7984 Size: 327200 %SYSDIR%\pmnOFxvU.dll %SYSDIR%\xxywTLEu.dll %SYSDIR%\tuvUKBtr.dll %SYSDIR%\tuvSkKAQ.dll %SYSDIR%\ssqQkHBr.dll %SYSDIR%\mlJYpNgh.dll %SYSDIR%\iiffCVnN.dll %SYSDIR%\efcBrQKc.dll %SYSDIR%\cbXRKEur.dll %SYSDIR%\awturQii.dll %SYSDIR%\byXQJDvU.dll and next 70 variations. MD5: 9E629EF3BD17ADAC725DF7D4C1851BB6 Size: 36352 %SystemDiskRoot%\System Volume Information\_restore{BFD9F1E8-A6FC-4617-8FCE-593F94FEFFC1}\RP152\A0081766.dll %SYSDIR%\ddcyApMd.dll %SYSDIR%\vtUlJyVP.dll %SYSDIR%\kHASKbbC.dll %SYSDIR%\fcCrOHbc.dll %SYSDIR%\jkkJDtqR.dll %SYSDIR%\ljJAQJCt.dll %SYSDIR%\qoMecYSI.dll %SYSDIR%\qoMeDTnK.dll MD5: 431650888C998B6FD5ADAAD72624F23D Size: 38400 %SYSDIR%\rqRJAsQk.dll %SYSDIR%\opnooLFu.dll %SYSDIR%\efcYrpPi.dll %SYSDIR%\xxywXNhH.dll %SYSDIR%\awtsPFVM.dll %SYSDIR%\fccyvSKb.dll %SYSDIR%\urqPiGVN.dll %SYSDIR%\nnnmmnKB.dll %SYSDIR%\jkkIBUlI.dll %SYSDIR%\wvULccda.dll %SYSDIR%\urqRIyWo.dll and next 27 variations. MD5: 5CF71B4E638138115196914064D4E346 Size: 272896 K:\Installation stuff\keygen.EXE %PROGRAMFILES%\Alwil Software\Avast4\DATA\moved\keygen.EXE %SystemDiskRoot%\torent\Nero Ultra Edition 8.3.2.1 + Key and guide\keygen.EXE MD5: EFB4A6118073BC9785802EB9016378FA Size: 61952 %SystemDiskRoot%\Documents and Settings\Joshua.YOUR-27E1513D96.002\Local Settings\Temp\cd193.tmp.exe %USERPROFILE%\Local Settings\Temp\_A00F33459C.exe %TEMP%\_A00F3A14642.exe %TEMP%\_A00F379CB.exe %TEMP%\_A00F4F6198A.exe %TEMP%\_A00F36BC0.exe %TEMP%\_A00F557369A.exe %TEMP%\_A00F35E05.exe %TEMP%\_A00F92CB0.exe %TEMP%\_A00F63532.exe %TEMP%\_A00F426C02BE.exe and next 21 variations. MD5: 51DF359C88135070D309E2AE43E2C9AD Size: 36864 %USERPROFILE%\Local\Temp\khfGvuVm.dll %SYSDIR%\ddcBRjJA.dll %SYSDIR%\gebrpgdu.dll.ren %SYSDIR%\vtUkkigF.dll %SYSDIR%\byXRkJcD.dll %SYSDIR%\geBroMCV.dll %SYSDIR%\vtUoligf.dll %SYSDIR%\hgGawTnN.dll %SYSDIR%\iiffDUmN.dll %SYSDIR%\pmnkKDwX.dll %SYSDIR%\ssqPhFWN.dll and next 10 variations. MD5: F690C65EFCB4C34131A67494EDDB4292 Size: 35840 %SYSDIR%\fcccdCtS.dll %SYSDIR%\ddcArrsS.dll %SYSDIR%\urqpjbcb.dll.ren %SYSDIR%\vtUooPjh.dll %SYSDIR%\khfGwWND.dll %SYSDIR%\mlJCSmJd.dll %SYSDIR%\iifdaywU.dll MD5: 1957BCB29A53D75706C04E318CBF92DC Size: 36864 %SYSDIR%\ssqOFVNh.dll %SYSDIR%\byXQIxvS.dll %SYSDIR%\yaywtUOH.dll %SYSDIR%\hgGvuSJB.dll %USERPROFILE%\Local\Temp\tmp001c77fd %USERPROFILE%\Local\Temp\tmp0006a4b7 %USERPROFILE%\Local\Temp\tmp0002af51 %USERPROFILE%\Local\Temp\tmp00020859 %USERPROFILE%\Local\Temp\tmp00011ed5 %USERPROFILE%\Local\Temp\tmp0000e55e %USERPROFILE%\Local\Temp\tmp0000b5d6 and next 4 variations. MD5: 699B193C1E69B01DA216E76B3FB0C663 Size: 36864 %SYSDIR%\hgGvwxwU.dll %SYSDIR%\wvUkJcdd.dll %SYSDIR%\opnooOHb.dll %SYSDIR%\nnnlKCSL.dll %SYSDIR%\cbXNGwXR.dll MD5: A0E4CF054A5889C5C8108C5776DE2638 Size: 36864 %SYSDIR%\yayXrOgd.dll %SYSDIR%\hgGxUMdb.dll %SYSDIR%\mljcsjgh.dll.ren %SYSDIR%\vtUKeEWN.dll MD5: 9FE519F65C03932B8B90F8C718130F84 Size: 56832 %TEMP%\s97516.exe %TEMP%\s83666.exe %TEMP%\s78023.exe %TEMP%\s39174.exe MD5: 0ED33895C4E28BE0A6059D9D63B954E3 Size: 36864 %SYSDIR%\vtUnkjIY.dll %SYSDIR%\awtutrqr.dll %SYSDIR%\jkkHbxvv.dll %SYSDIR%\urqQifdE.dll %SYSDIR%\iifecdaA.dll %SYSDIR%\vtuollev.dll.ren %SYSDIR%\jkkKcBuS.dll %SYSDIR%\fccbYpOg.dll %SystemDiskRoot%\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP141\A0026567.dll %SystemDiskRoot%\System Volume Information\_restore{2DB37729-7E03-4F82-ADEF-4057C22A22C7}\RP141\A0026561.dll %SYSDIR%\ddcslicb.dll.ren and next 5 variations. MD5: 1B8EAB184F63158FEDB45F304E3AF3BF Size: 38400 %SYSDIR%\ssqOGvwx.dll %SYSDIR%\cbXOHywX.dll %USERPROFILE%\Local\Temp\xxyywvTk.dll %USERPROFILE%\Local\Temp\tuvSijKd.dll %USERPROFILE%\Local\Temp\ssqQkJaY.dll %USERPROFILE%\Local\Temp\rqRLbxUm.dll %USERPROFILE%\Local\Temp\qoMfeffD.dll %USERPROFILE%\Local\Temp\mlJArpPj.dll %USERPROFILE%\Local\Temp\qoMgFyyX.dll MD5: A480E2C2884A30D8A5824F4B1EA73B5E Size: 37376 %SYSDIR%\qoMgggEw.dll %SYSDIR%\nnnkLefd.dll %SYSDIR%\geBssssP.dll %SYSDIR%\awtUOFYS.dll %SYSDIR%\ddcArRli.dll %SYSDIR%\yayaBUNf.dll %SYSDIR%\efcYpPHY.dll %SYSDIR%\pmnkKbbX.dll %SYSDIR%\yaywWOgG.dll MD5: C08A8447618604EC3E3DE52F05573AB4 Size: 38912 %SYSDIR%\byxyyvw.dll %SYSDIR%\iifdaya.dll.ren %SYSDIR%\opnolig.dll MD5: 83CFD6527B82C5ED197B39F5D025620B Size: 89088 %TEMP%\wqvvtdsj.dll %TEMP%\gxwagaiw.dll %TEMP%\qdbctynv.dll %TEMP%\Temporary Internet Files\Content.IE5\XTWR1TC7\hctp[2] %TEMP%\gcxunnvo.dll %TEMP%\cnxuueyr.dll MD5: 271574E776244E14E2402B09F0A36F7B Size: 92672 %TEMP%\tuataysh.dll %TEMP%\mdkgbbqx.dll %TEMP%\raibfvsh.dll %TEMP%\tdpvslrm.dll %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\RZ0OE28Z\ptch[1] %TEMP%\pyglndgj.dll %TEMP%\ydehxono.dll %USERPROFILE%\Ustawienia lokalne\Temporary Internet Files\Content.IE5\KBM5ULEX\ptch[1] MD5: 7A757B025E13287740542F83F19BDFE6 Size: 89088 %TEMP%\stwslyma.dll %TEMP%\pmrwxuab.dll %TEMP%\xnufocid.dll %TEMP%\wmasbvct.dll %TEMP%\waneisns.dll %TEMP%\onsoghde.dll %TEMP%\odxswify.dll %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\WLQ3O1I3\ptch[8] %SystemDiskRoot%\RECYCLER\S-1-5-21-484763869-879983540-839522115-1003\Dc4397 %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\N7LJ790W\ptch[1] MD5: 35089F8F30953FA68F1A8ED6BB7CCB75 Size: 92672 %TEMP%\ieqdiiaa.dll %TEMP%\laacytyu.dll %TEMP%\qnfrownj.dll %TEMP%\Temporary Internet Files\Content.IE5\9AE0MH9M\iddqd[3] %TEMP%\dpybybqj.dll MD5: 3C131D91504E5AE657AA073D3C9E0BD4 Size: 88576 %TEMP%\ghcdarwt.dll %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\08T445ET\idkfa[1] %TEMP%\ecenhsja.dll %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\WLQ3O1I3\idkfa[1] %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\E7B5UDB7\iddqd[1] %SystemDiskRoot%\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP74\A0044166.dll %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\AC022TZ6\idkfa[1] %TEMP%\xwubjhik.dll %SYSDIR%\lbwdejhb.dll %TEMP%\blagbhno.dll %SYSDIR%\ukhhsomk.dll and next 1 variations. MD5: 259C739A1A313431A2815D2DC66AAD6B Size: 83456 %TEMP%\cxwpmubs.dll %TEMP%\bkxbuhpj.dll %TEMP%\csgqgwck.dll %USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\WLQ3O1I3\hctp[5] %TEMP%\cikrydiu.dll %TEMP%\sioesnyl.dll MD5: F2FCF3868B608CB3406B202DEF28E42B Size: 36352 %SYSDIR%\xxyvsqq.dll %SYSDIR%\urqooon.dll %SYSDIR%\qomljhi.dll %SYSDIR%\pmnnlkk.dll %SYSDIR%\ddccbcc.dll %SYSDIR%\xxyvwtq.dll %SYSDIR%\wvursrq.dll %SYSDIR%\nnnmjig.dll %SYSDIR%\khffcab.dll %SYSDIR%\fccyvsp.dll %SYSDIR%\ddcddec.dll and next 16 variations. MD5: 77BADFE6D7F99BDD5EBD4FAACEEA3D0A Size: 37376 %SYSDIR%\wvuutsp.dll %SYSDIR%\wvurono.dll %SYSDIR%\vtuvuur.dll %SYSDIR%\iifcdby.dll %SYSDIR%\gebbbaa.dll %SYSDIR%\yayyyyx.dll %SYSDIR%\xxywvsq.dll %SYSDIR%\vtuspml.dll %SYSDIR%\urqrrqr.dll %SYSDIR%\ssqoppo.dll %SYSDIR%\opnmnnl.dll and next 22 variations. MD5: 8A7651C7F9CDBE5D5BE8563C4F4190F6 Size: 37376 %SYSDIR%\wvUnLBRI.dll %SYSDIR%\tuvSjHAs.dll %SYSDIR%\cbXNHXPf.dll %SYSDIR%\tuvWmMGy.dll %SYSDIR%\vtUomKcC.dll %SYSDIR%\ddcApnoO.dll %SYSDIR%\nnnMgfeb.dll %SYSDIR%\jkkIbAtS.dll %SYSDIR%\vtUnnllJ.dll %SYSDIR%\rqRkIbxV.dll %SYSDIR%\awtqnkhe.dll MD5: 8950C67966E9F77B8608679C383EFBA6 Size: 36352 %TEMP%\urqQjiFY.dll %SYSDIR%\byXRkIYq.dll MD5: DF438131A1B0E23BE72FAA3B07A03CB8 Size: 38400 %SYSDIR%\vtuurrq.dll %SYSDIR%\rqronnn.dll.ren %SYSDIR%\rqrrqpp.dll MD5: 36AB7D07FAE39A910D950C2FF506D65D Size: 93696 %TEMP%\kkhgeupj.dll %TEMP%\ctksjhuw.dll %TEMP%\Temporary Internet Files\Content.IE5\9AE0MH9M\ptch[1] %TEMP%\wywslnfd.dll MD5: 22D66B07BAB9E5962DC9A6D179698360 Size: 42496 %SYSDIR%\khfDwxwT.dll %SYSDIR%\tuvVLdcB.dll %SYSDIR%\hgGxXrPf.dll %SYSDIR%\jkkLBsPG.dll %SYSDIR%\xxyXPGyA.dll %SYSDIR%\hgGyvwvV.dll %SYSDIR%\opnkljgG.dll %SYSDIR%\mlJAQjIY.dll %SYSDIR%\hgGayaay.dll %SYSDIR%\lJaASMcC.dll MD5: 570B95ED593E049BE5BC8AF3BC776865 Size: 36864 %SYSDIR%\geBrsSLE.dll %SYSDIR%\vtUoMcBt.dll %SYSDIR%\mlJBRlKE.dll %USERPROFILE%\Local\Temp\tmp000e27bb %USERPROFILE%\Local\Temp\tmp000394ee %USERPROFILE%\Local\Temp\tmp00018b4d %USERPROFILE%\Local\Temp\tmp0001818d %USERPROFILE%\Local\Temp\tmp00014da2 %USERPROFILE%\Local\Temp\tmp000132d2 %USERPROFILE%\Local\Temp\tmp0001140c %USERPROFILE%\Local\Temp\tmp00010eaf and next 16 variations.

Detecting items list:

  1. Files by MD5 MD5: A701EB71E0249C9F214DBBBE48F264B9 Size: 85568 MD5: 250DB3D3C6A66FEADE3A01D75A8970A0 Size: 1050624 MD5: 65214B088165A0BBF68651F0E480D088 Size: 268288 MD5: 8612A0714B3C6721F896163AC5C84BEA Size: 85056 MD5: 0CE632453839675E5C698EC5D3AC8CF6 Size: 82496 MD5: 5F58AA850DE382D95067565DD0440988 Size: 83520 MD5: 570B95ED593E049BE5BC8AF3BC776865 Size: 36864 MD5: 9A3B4A5D06E4D74C9D6237A755A1AF1C Size: 87104 MD5: CF1F997843FA3E16B5B956B8615F4406 Size: 89664 MD5: D9357A866B18AEA7E6DCC3269D236DDC Size: 158484

« Go to Software Database