This is the first time I've seen this malware name come up. I'm getting a lot of Facebook spoof spam that leads to a website that tries to download Adobe_Player11.exe by meta refresh.
Virustotal.com is down, but Jotti shows very poor detection rate:
Scan taken on 15 Mar 2009 12:47:02 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found Trojan-PSW:W32/Papras.DL, Trojan-PSW.Win32.Papras.jg
Ikarus Found Trojan-PWS.Win32.Papras
Kaspersky Anti-Virus Found Trojan-PSW.Win32.Papras.jg
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Quick Heal Found nothing
Sophos Antivirus Found Mal/EncPk-HJ
VirusBuster Found nothing
VBA32 Found Malware-Cryptor.Win32.General.3 (probable variant)
Apparently this trojan is a keylogger to steal passwords and other personal information. It also installs a rootkit to make it extremely difficult to remove (see http://en.wikipedia.org/wiki/Rootkit )
Add: googling the MD5 number, someone posted their virustotal results elsewhere:
<http://www.virustotal.com/analisis/56e5b68e9381464e624ab4d43afb12c1>
File Adobe_Player11.exe received on 03.14.2009 19:36:41 (CET)
Current status: finished
Result: 2/38 (5.26%)
Antivirus Version Last Update Result
a-squared 4.0.0.101 2009.03.14 -
AhnLab-V3 5.0.0.2 2009.03.13 -
AntiVir 7.9.0.114 2009.03.13 -
Authentium 5.1.0.4 2009.03.14 -
Avast 4.8.1335.0 2009.03.13 -
AVG 8.0.0.237 2009.03.14 -
BitDefender 7.2 2009.03.14 -
CAT-QuickHeal 10.00 2009.03.14 -
ClamAV 0.94.1 2009.03.14 -
Comodo 1056 2009.03.14 -
DrWeb 4.44.0.09170 2009.03.14 -
eSafe 7.0.17.0 2009.03.12 Suspicious File
eTrust-Vet 31.6.6388 2009.03.09 -
F-Prot 4.4.4.56 2009.03.13 -
F-Secure 8.0.14470.0 2009.03.14 -
Fortinet 3.117.0.0 2009.03.14 -
GData 19 2009.03.14 -
Ikarus T3.1.1.45.0 2009.03.14 -
K7AntiVirus 7.10.671 2009.03.14 -
Kaspersky 7.0.0.125 2009.03.14 -
McAfee 5553 2009.03.14 -
McAfee+Artemis 5553 2009.03.14 -
McAfee-GW-Edition 6.7.6 2009.03.13 -
Microsoft 1.4405 2009.03.14 -
NOD32 3935 2009.03.13 -
Norman 6.00.06 2009.03.13 -
nProtect 2009.1.8.0 2009.03.14 -
Panda 10.0.0.10 2009.03.14 -
PCTools 4.4.2.0 2009.03.14 -
Prevx1 V2 2009.03.14 -
Rising 21.20.52.00 2009.03.14 -
Sophos 4.39.0 2009.03.14 Mal/EncPk-HJ
Sunbelt 3.2.1858.2 2009.03.13 -
Symantec 1.4.4.12 2009.03.14 -
TheHacker 6.3.3.0.281 2009.03.13 -
TrendMicro 8.700.0.1004 2009.03.13 -
ViRobot 2009.3.13.1648 2009.03.13 -
VirusBuster 4.6.5.0 2009.03.14 -
MD5...: 803ab2de5e6c00c86f76ea2b60a5ee4f
So a few vendors have added definitions since that was done.
