Home Malware Programs Trojans DDoS:Win32/Dofoil.A

DDoS:Win32/Dofoil.A

Posted: December 5, 2011

Threat Metric

Ranking: 10,880
Threat Level: 8/10
Infected PCs: 22,618
First Seen: December 5, 2011
Last Seen: October 3, 2023
OS(es) Affected: Windows

DDoS:Win32/Dofoil.A is a Trojan that invades the targeted computer system secretly and can harm it. DDoS:Win32/Dofoil.A spreads via spam emails allegedly coming from the American Airlines. The spam email includes a malicious .zip file attachment which is detected as DDoS:Win32/Dofoil.A. If a recipient opens a malicious attachment, his/her computer is infected with DDoS:Win32/Dofoil.A. DDoS:Win32/Dofoil.A can slow down your computer and block you from accessing Task Manager or registry Editor. DDoS:Win32/Dofoil.A is managed through remote servers and is able to initiate DDoS (distributed denial of service) attacks, used to distribute the Trojan to other machines. DDoS:Win32/Dofoil.A can remove your privileges to monitor PC system's processes via Registry Editor and Task Manager tools. DDoS:Win32/Dofoil.A can also drop and eliminate products in your Registry, record data, connect to the Internet, alter file protection system's services, use your email accounts to deliver the Trojan, and reroute your online searches to unwanted web pages. Get rid of DDoS:Win32/Dofoil.A to protect your computer from damage.

Aliases

Dropper.Generic6.CCOG [AVG]W32/Agent2.MHO!tr [Fortinet]Win32.Carberp [Ikarus]Trojan/Win32.Yakes [AhnLab-V3]Generic.dx!bg3l [McAfee-GW-Edition]DDoS/Dofoil.A.88 [AntiVir]Gen:Variant.Graftor.45038 [BitDefender]Trojan.Win32.Agent2.mho [Kaspersky]Win32:Carberp-AJG [Trj] [Avast]Generic Downloader.rm [McAfee]Trj/Genetic.gen [Panda]Cryptic [AVG]W32/ZeroAccess.B!tr [Fortinet]Worm.Win32.Cridex [Ikarus]Trojan/Win32.PornoAsset [AhnLab-V3]
More aliases (362)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\FS\Desktop\MAESTRIA\GESTION PROYECTOS\Microsoft Project Pro 2010 Espanol\Activador office 2010\mini-KMS_Activator_v1.2_Office2010_VL_ENG.exe File name: mini-KMS_Activator_v1.2_Office2010_VL_ENG.exe
Size: 1.05 MB (1057280 bytes)
MD5: 797429180c8c307b2a5d5ecf7ac77c8b
Detection count: 7,741
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\FS\Desktop\MAESTRIA\GESTION PROYECTOS\Microsoft Project Pro 2010 Espanol\Activador office 2010\mini-KMS_Activator_v1.2_Office2010_VL_ENG.exe
Group: Malware file
Last Updated: October 15, 2023
%LOCALAPPDATA%\NetMailTmp.bin File name: NetMailTmp.bin
Size: 1.02 KB (1021 bytes)
MD5: 50d9697937d20e15b585dccdc2a188b3
Detection count: 3,441
File type: Binary File
Mime Type: unknown/bin
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: September 4, 2023
%LOCALAPPDATA%\NetMailTmp.bin File name: NetMailTmp.bin
Size: 939B (939 bytes)
MD5: 988586fda185394c0d9efe09cd50a790
Detection count: 1,422
File type: Binary File
Mime Type: unknown/bin
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: September 6, 2023
%LOCALAPPDATA%\NetMailTmp.bin File name: NetMailTmp.bin
Size: 1.06 KB (1064 bytes)
MD5: e92c85d796bfa7ce3b27e84502000636
Detection count: 956
File type: Binary File
Mime Type: unknown/bin
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: July 7, 2023
F:\ASUS\usb yekll\WIFI CRACK\Wirless\WirelessNetView.exe File name: WirelessNetView.exe
Size: 40.96 KB (40960 bytes)
MD5: 89fc7fe878a249ae7da46a8fb5b06f3e
Detection count: 487
File type: Executable File
Mime Type: unknown/exe
Path: F:\ASUS\usb yekll\WIFI CRACK\Wirless\WirelessNetView.exe
Group: Malware file
Last Updated: September 15, 2023
%SystemDrive%\Documents and Settings\garciaju\Application Data\2EC795.exe File name: 2EC795.exe
Size: 34.81 KB (34816 bytes)
MD5: e9a4bf03daa1254d8bc05c4170d4c926
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\garciaju\Application Data
Group: Malware file
Last Updated: January 23, 2012
%USERPROFILE%\Application Data\90434F.exe File name: 90434F.exe
Size: 47.1 KB (47104 bytes)
MD5: e61aa54f4544a401ddc9f6dd468fe237
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: January 17, 2012
%TEMP%\oskb.exe File name: oskb.exe
Size: 61.38 KB (61387 bytes)
MD5: febfc8c59f384003780d67d88403f3cb
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 25, 2012
%SystemDrive%\Documents and Settings\hrad.e_aldosuky\Application Data\E3BB7F.exe File name: E3BB7F.exe
Size: 197.12 KB (197120 bytes)
MD5: e0d7bd6e8b2e678d25b69b1469ca2bdb
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\hrad.e_aldosuky\Application Data
Group: Malware file
Last Updated: January 5, 2013
%SystemDrive%\Documents and Settings\Chief\Application Data\9CB732.exe File name: 9CB732.exe
Size: 46.08 KB (46080 bytes)
MD5: d06af556a1dabee547b6642aa1d049f9
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\Chief\Application Data
Group: Malware file
Last Updated: January 24, 2012
%TEMP%\Rar$EX46.552\eCalendar 6.5\eCalendar.exe File name: eCalendar.exe
Size: 1.58 MB (1583616 bytes)
MD5: 7b8958fab7ffb6e7cf21d34b4fc066c4
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Rar$EX46.552\eCalendar 6.5
Group: Malware file
Last Updated: March 23, 2020
%PROGRAMFILES(x86)%\WinApps\msmsgs.exe File name: msmsgs.exe
Size: 167.93 KB (167936 bytes)
MD5: 03f8efe9796bb03ec9ed971d56d4397f
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\WinApps
Group: Malware file
Last Updated: June 22, 2012
%USERPROFILE%\Application Data\E602DF.exe File name: E602DF.exe
Size: 35.32 KB (35328 bytes)
MD5: 1e44263928bfb9ede59584079011eac1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: May 11, 2012
%APPDATA%\9A9D63.exe File name: 9A9D63.exe
Size: 47.61 KB (47616 bytes)
MD5: a683f6f5473765de4fd6a0dc2ad01499
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 16, 2012
%USERPROFILE%\Application Data\16F747.exe File name: 16F747.exe
Size: 45.56 KB (45568 bytes)
MD5: 6daf575428118663fc7d90219067c864
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: January 17, 2012
%TEMP%\dhdaehe File name: dhdaehe
Size: 400.89 KB (400896 bytes)
MD5: f12c7d55c9304311b3e06a4dae577ffc
Detection count: 5
Path: %TEMP%
Group: Malware file
Last Updated: June 22, 2012
%APPDATA%\61B329\61B329.exe File name: 61B329.exe
Size: 43.52 KB (43520 bytes)
MD5: 2fb4c2855aac21f8ae59a1d5498c47e1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\61B329
Group: Malware file
Last Updated: March 6, 2013
Loading...