This application requires Javascript for optimal performance.

W32/VBKrypt.FP!tr - Released Mar 05, 2010 - Last Updated Mar 10, 2010

Alias/es

Trojan.Win32.VBKrypt.fp, Worm:Win32/Prolaco.M, trojan/Injector.awn

Detection Availability

Active DatabaseExtended Database
FortiGate
low
high
FortiClient
FortiMail N/A

Visible Symptoms

  • The following file exist:
    • %system%\googleupdtr.exe

    Detailed Analysis


    • It drops a copy of itself at the %system% folder with a filename "googleupdtr.exe."


    • It adds the following registry:
      • key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
      • value: GoogleUpdaterv3
      • data: "C:\WINDOWS\system32\googleupdtr.exe"


    • The following strings can be found inside the malware code:
      • pharma
      • casino
      • finance
      • mortgage
      • insurance
      • gambling
      • health
      • hotel
      • travel
      • antivirus
      • antivir
      • pocker
      • poker
      • video
      • vocations
      • design
      • graphic
      • football
      • footbal
      • estate
      • baseball
      • books
      • gifts
      • money
      • spyware
      • credit
      • loans
      • dating
      • myspace
      • virus
      • verizon
      • amazon
      • iphone
      • software
      • movie
      • mobile
      • music
      • craigslist
      • sport
      • medical
      • school
      • wallpaper
      • military
      • weather
      • twitter
      • fashion
      • spybot
      • trading
      • tramadol
      • flower
      • cigarettes
      • doctor
      • flights
      • airlines
      • comcast
      • Explorer
      • Opera
      • Chrome


    • There is also a chance that any of following filenames can be used for dropped files.
      • YouTubeGet 5.6.exe
      • Youtube Music Downloader 1.3.exe
      • WinRAR v3.x keygen [by HiXem].exe
      • Windows2008 keygen and activator.exe
      • [+ MrKey +] Windows XP PRO Corp SP3 valid-key generator.exe
      • Windows Password Cracker + Elar3 key.exe
      • [Eni0j0 team] Windows 7 Ultimate keygen.exe
      • Windows 2008 Enterprise Server VMWare Virtual Machine.exe
      • Winamp.Pro.v7.xx.PowerPack.Portable+installer.exe
      • Website Hacker.exe
      • [Eni0j0 team] Vmvare keygen.exe
      • VmWare 7.x keygen.exe
      • UT 2003 KeyGen.exe
      • Twitter FriendAdder 2.3.9.exe
      • Tuneup Ultilities 2010.exe
      • [antihack tool] Trojan Killer v2.9.4173.exe
      • Total Commander7 license+keygen.exe
      • Super Utilities Pro 2009 11.0.exe
      • Sub7 2.5.1 Private.exe
      • Sophos antivirus updater bypass.exe
      • sdbot with NetBIOS Spread.exe
      • [fixed]RapidShare Killer AIO 2010.exe
      • Rapidshare Auto Downloader 3.8.6.exe
      • Power ISO v4.4 + keygen milon.exe
      • [patched, serial not needed] PDF Unlocker v2.0.5.exePDF-XChange Pro.exe
      • [patched, serial not needed] PDF to Word Converter 3.4.exe
      • PDF password remover (works with all acrobat reader).exe
      • Password Cracker.exe
      • Norton Internet Security 2010 crack.exe
      • Norton Anti-Virus 2010 Enterprise Crack.exe
      • Norton Anti-Virus 2005 Enterprise Crack.exe
      • NetBIOS Hacker.exe
      • NetBIOS Cracker.exe
      • [patched, serial not need] Nero 9.x keygen.exe
      • Myspace theme collection.exe
      • MSN Password Cracker.exe
      • Mp3 Splitter and Joiner Pro v3.48.exe
      • Motorola, nokia, ericsson mobil phone tools.exe
      • Microsoft.Windows 7 ULTIMATE FINAL activator+keygen x86.exe
      • Microsoft Visual Studio KeyGen.exe
      • Microsoft Visual C++ KeyGen.exe
      • Microsoft Visual Basic KeyGen.exe
      • McAfee Total Protection 2010 [serial patch by AnalGin].exe
      • Magic Video Converter 8.exe
      • LimeWire Pro v4.18.3 [Cracked by AnalGin].exe
      • L0pht 4.0 Windows Password Cracker.exe
      • K-Lite Mega Codec v5.2 Portable.exe
      • K-Lite Mega Codec v5.2.exe
      • Keylogger unique builder.exe
      • Kaspersky Internet Security 2010 keygen.exe
      • Kaspersky AntiVirus 2010 crack.exe
      • IP Nuker.exe
      • Internet Download Manager V5.exe
      • Image Size Reducer Pro v1.0.1.exe
      • ICQ Hacker Trial version [brute].exe
      • Hotmail Hacker [Brute method].exe
      • Hotmail Cracker [Brute method].exe
      • Half-Life 2 Downloader.exe
      • Grand Theft Auto IV [Offline Activation + mouse patch].exe
      • Google SketchUp 7.1 Pro.exe
      • G-Force Platinum v3.7.6.exe
      • FTP Cracker.exe
      • DVD Tools Nero 10.x.x.x.exe
      • Download Boost 2.0.exe
      • Download Accelerator Plus v9.2.exe
      • Divx Pro 7.x version Keymaker.exe
      • DivX 5.x Pro KeyGen generator.exe
      • DCOM Exploit archive.exe
      • Daemon Tools Pro 4.8.exe
      • Counter-Strike Serial key generator [Miona patch].exe
      • CleanMyPC Registry Cleaner v6.02.exe
      • Brutus FTP Cracker.exe
      • Blaze DVD Player Pro v6.52.exe
      • BitDefender AntiVirus 2010 Keygen.exe
      • Avast 5.x Professional.exe
      • Avast 4.x Professional.exe
      • Ashampoo Snap 3.xx [Skarleot Group].exe
      • AOL Password Cracker.exe
      • AOL Instant Messenger (AIM) Hacker.exe
      • AnyDVD HD v.6.3.1.8 Beta incl crack.exe
      • Anti-Porn v13.x.x.x.exe
      • Alcohol 120 v1.9.x.exe
      • Adobe Photoshop CS4 crack by M0N5KI Hack Group.exe
      • Adobe Illustrator CS4 crack.exe
      • Adobe Acrobat Reader keygen.exe
      • Ad-aware 2010.exe
      • [patched, serial not needed] Absolute Video Converter 6.2-7.exe

    Recommended Action

      FortiGate Systems

    • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

      FortiClient Systems

    • Quarantine/delete files that are detected and replace infected files with clean backup copies.

    Reference: ID - 1613476