Home Malware Programs Trojans Simda.B

Simda.B

Posted: February 4, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 14
First Seen: February 4, 2013
Last Seen: July 30, 2018
OS(es) Affected: Windows

Simda.B, also known as Win32/Simda.B, is a Trojan that can interfere with the operation of certain programs. Simda.B serves as a proxy server and disguises its existence in the targeted computer system. Simda.B uses rootkits techniques. Once executed, Simda.B creates several potentially malicious files on the compromised PC. Simda.B may create copies of itself using the specific filenames and modifies and deletes the files. Simda.B sets the registry entry so that it can run automatically on every time Windows starts. Simda.B gathers personal information and computer data on the victimized PC and attempts to transfer it to a remote server. Simda.B aims at getting administrative privileges in the attacked computer system. Simda.B exploits the CVE-2010-3338 vulnerability. Simda.B pretends to be a Flash update and displays the fake dialog boxes. Simda.B gets full installation rights and then steals victims' passwords. Simda.B can spread via spam email messages and corrupted social networking accounts that host malware infections and pilfer money from online payment accounts. Simda.B may redirect affected computer users to malicious websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



f89fb2c16484d8af387793eecd4c11cc File name: f89fb2c16484d8af387793eecd4c11cc
Size: 464.89 KB (464896 bytes)
MD5: f89fb2c16484d8af387793eecd4c11cc
Detection count: 43
Group: Malware file
Last Updated: February 11, 2013
fa3477ab269271a875e01af45abc00a0 File name: fa3477ab269271a875e01af45abc00a0
Size: 713.74 KB (713741 bytes)
MD5: fa3477ab269271a875e01af45abc00a0
Detection count: 36
Group: Malware file
Last Updated: February 11, 2013
f4d66194c09a78204148ff9aaf46a5cc File name: f4d66194c09a78204148ff9aaf46a5cc
Size: 1.02 MB (1025024 bytes)
MD5: f4d66194c09a78204148ff9aaf46a5cc
Detection count: 35
Group: Malware file
Last Updated: February 11, 2013
fb2efc0af0badd4c4b9c655dc2074f46 File name: fb2efc0af0badd4c4b9c655dc2074f46
Size: 792.57 KB (792576 bytes)
MD5: fb2efc0af0badd4c4b9c655dc2074f46
Detection count: 32
Group: Malware file
Last Updated: February 11, 2013
e054d4d59b2d25647ba1229e3e2f3aba File name: e054d4d59b2d25647ba1229e3e2f3aba
Size: 1.02 MB (1025024 bytes)
MD5: e054d4d59b2d25647ba1229e3e2f3aba
Detection count: 31
Group: Malware file
Last Updated: February 11, 2013
%APPDATA%\AA7k3.exe File name: AA7k3.exe
Size: 701.44 KB (701440 bytes)
MD5: 090a325b5a13f9509f13682b7f322692
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 7, 2013
%APPDATA%\aA3k793.exe File name: aA3k793.exe
Size: 640 KB (640000 bytes)
MD5: 12184c1fe47256579225e197ae4e2260
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 7, 2013
%Temp%\¬%variable1%-%number%.exe File name: %Temp%\¬%variable1%-%number%.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\¬%number%.sys File name: %Temp%\¬%number%.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%Temp%\¬%variable5%.tmp File name: %Temp%\¬%variable5%.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%Temp%\¬SE%variable6% File name: %Temp%\¬SE%variable6%
Group: Malware file
%AppData%\¬Mozilla\¬Firefox\¬Profiles\¬%variable8%\¬searchplugins\¬search.xml File name: %AppData%\¬Mozilla\¬Firefox\¬Profiles\¬%variable8%\¬searchplugins\¬search.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\¬%variable4%.exe File name: %AppData%\¬%variable4%.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\¬ScanDisc.exe File name: %AppData%\¬ScanDisc.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\¬%variable7%.reg File name: %AppData%\¬%variable7%.reg
Mime Type: unknown/reg
Group: Malware file
%AppData%\¬mcp.ico File name: %AppData%\¬mcp.ico
Mime Type: unknown/ico
Group: Malware file
%AppData%\¬Mozilla\¬Firefox\¬Profiles\¬%variable11%\¬prefs.js File name: %AppData%\¬Mozilla\¬Firefox\¬Profiles\¬%variable11%\¬prefs.js
File type: JavaScript file
Mime Type: unknown/js
Group: Malware file
%UserProfile%\¬%variable2%-%number%.exe File name: %UserProfile%\¬%variable2%-%number%.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Userprofile%\¬Desktop\¬Computer.lnk File name: %Userprofile%\¬Desktop\¬Computer.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%System%\¬c_%variable3%.nls File name: %System%\¬c_%variable3%.nls
Mime Type: unknown/nls
Group: Malware file
%System%\¬tasks\¬task%variable9% File name: %System%\¬tasks\¬task%variable9%
Group: Malware file
%Windir%\¬temp\¬%variable10%.tmp File name: %Windir%\¬temp\¬%variable10%.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
C:\¬Windows\¬system32\¬drivers\¬etc\¬hosts.txt File name: C:\¬Windows\¬system32\¬drivers\¬etc\¬hosts.txt
Mime Type: unknown/txt
Group: Malware file
C:\¬Windows\¬system32\¬drivers\¬etc\¬hosts File name: C:\¬Windows\¬system32\¬drivers\¬etc\¬hosts
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\¬Software\¬Microsoft\¬Windows\¬CurrentVersion\¬Run "Windows Update Server" = "%userprofile%\¬%variable2%-%number%.exe"HKEY_LOCAL_MACHINE\¬SOFTWARE\¬Microsoft\¬Windows\¬CurrentVersion\¬Policies\-System "ConsentPromptBehaviorAdmin" = 0 HKEY_LOCAL_MACHINE\¬SOFTWARE\¬Microsoft\¬Windows\¬CurrentVersion\¬Policies\-System "ConsentPromptBehaviorUser" = 0HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\¬SOFTWARE\¬Microsoft\¬Windows\¬CurrentVersion\¬RunOnce "%appdata%\¬%variable4%.exe opt"
Loading...