Home Malware Programs Trojans Negotum

Negotum

Posted: December 8, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 96
First Seen: December 8, 2010
OS(es) Affected: Windows

Aliases

Hiloti.BT [AVG]Hiloti.gen.j [McAfee]Suspicious file [Panda]Sus/UnkPack-C [Sophos]Packed.Win32.Krap.ao [Kaspersky]Win32:FakeSysdef [Avast]Packed.Generic.313 [Symantec]a variant of Win32/Kryptik.IQH [NOD32]Agent2.BVSY [AVG]Trojan.Gen.2 [Symantec]a variant of Win32/Cimag.EO [NOD32]Hiloti.BP [AVG]W32/Tdss.PLT!tr [Fortinet]Mal/Hiloti-D [Sophos]Win32:MalOb-CB [Avast]
More aliases (69)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\Wsperig.dll File name: Wsperig.dll
Size: 88.06 KB (88064 bytes)
MD5: eb64712cf87de6af6bea7be38e403b24
Detection count: 90
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: December 9, 2010
%WINDIR%\mdxtat.dll File name: mdxtat.dll
Size: 57.34 KB (57344 bytes)
MD5: d07224ff889d88103b7ad10d5b037480
Detection count: 71
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%
Group: Malware file
Last Updated: December 10, 2010
%LOCALAPPDATA%\prilprp.dll File name: prilprp.dll
Size: 79.87 KB (79872 bytes)
MD5: 25b21ea902d771e33f556cea92e1f9d3
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: December 9, 2010
%TEMP%\DvdCEPoYRb.exe File name: DvdCEPoYRb.exe
Size: 448.51 KB (448512 bytes)
MD5: a70fd1af9425f5eaba810391622e2ed5
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 9, 2010
%WINDIR%\system32\regedit.exe File name: regedit.exe
Size: 182.78 KB (182784 bytes)
MD5: 5d4444eca39825cfb4702ee59fa4b35c
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 8, 2010
Loading...