IM-Worm.Sohanad.bh

Description: Worm
Risk Level: Critical
Date of First Occurence: Friday, May 09, 2008
Software Developer: (unknown)
Brief Info: Computer worm is malicious software application designed to spread via computer networks.
Removal: This threat can be removed using "Spyware Terminator"

SCAN & REMOVE NOW »

Geographical Distribution of Threat "IM-Worm.Sohanad.bh"

Threat Info

View All

Detected Items

  1. Detected Files: %SYSDIR%\SSCVIHOST.exe MD5: CECCB2606F6C834600F7A2381BC38660 Size:613431 MD5: E82BC72E21C01875545D473DE88327D9 Size:251392
  2. Detected Files with variable Filenames: MD5: 58297312FCD984B04F712344A31198AC Size: 250975 f:\F22 Folder\XREF\DAL_xref\DAL_xref.exe f:\F22 Folder\XREF\New Folder (2)\New Folder (2).exe f:\F22 Folder\XREF\New Folder\New Folder.exe f:\F22 Folder\XREF\XREF.exe f:\F22 Folder\XIMAGES\XIMAGES.exe f:\F22 Folder\XIMAGE\XIMAGE.exe f:\F22 Folder\F22_DAL_xref_2007.09.12 Folder\F22_DAL_xref_2007.09.12 Folder.exe f:\F22 Folder\F22_DAL_Additional_ Information_2007.09.12 Folder\F22_DAL_Additional_ Information_2007.09.12 Folder.exe f:\F22 Folder\F22 Folder.exe f:\F21 L\F21.exe f:\LIGHTING-JRA\F22\Drawings\F22_DAL_xref 2008.07.17\F22_DAL_xref 2008.07.17.exe and next 5 variations. MD5: 6E11F5AFB482C45186F9E8551BDF765F Size: 250999 %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP3\A0052343.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP3\A0052342.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP3\A0052341.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP3\A0052340.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP1\A0045621.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP1\A0043346.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP1\A0043345.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP1\A0043344.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP1\A0040210.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP1\A0040209.exe %SystemDiskRoot%\System Volume Information\_restore{2E0E3A98-E240-4C06-963C-E8AF7F64129C}\RP1\A0040208.exe and next 1404 variations. MD5: 7DA74766F1D688425B79F4636675F3CB Size: 250999 %SYSDIR%\SSCVIHOST.exe F:\Microsoft Office\Office12\Office12.exe F:\Microsoft Office\Office12\Groove\Groove.exe F:\Microsoft Office\Office12\Groove\ToolData\ToolData.exe F:\Microsoft Office\Office12\Groove\ToolData\groove.net\groove.net.exe F:\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms4\GrooveForms4.exe F:\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms4\FormsStyles\FormsStyles.exe F:\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms4\FormsStyles\STS2\STS2.exe F:\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms4\FormsStyles\Swirl\Swirl.exe F:\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveForms5\GrooveForms5.exe F:\Microsoft Office\Office12\Groove\ToolData\groove.net\GrooveProjectToolset\GrooveProjectToolset.exe and next 1492 variations.

Detecting items list:

  1. Files by MD5 MD5: 7DA74766F1D688425B79F4636675F3CB Size: 250999 MD5: 58297312FCD984B04F712344A31198AC Size: 250975 MD5: 0D484ECE6B1D8546F8ED9408D91D0437 Size: 251392 MD5: E82BC72E21C01875545D473DE88327D9 Size: 251392 MD5: 02DFD87807112647A809494D62C9123D Size: 250999 MD5: CECCB2606F6C834600F7A2381BC38660 Size: 613431 MD5: 6E11F5AFB482C45186F9E8551BDF765F Size: 250999 MD5: 4F7B0CD9A0A362520452B3A359864DC0 Size: 250999 MD5: C62FF9DA5EA5BD262A0FFF07801E6A5A Size: 369664

« Go to Software Database