Home Malware Programs Trojans TrojanDownloader:MSIL/Demibot.A

TrojanDownloader:MSIL/Demibot.A

Posted: May 7, 2013

Threat Metric

Ranking: 16,318
Threat Level: 8/10
Infected PCs: 4,637
First Seen: May 7, 2013
Last Seen: February 15, 2025
OS(es) Affected: Windows

Aliases

Inject.MUJ [AVG]Trojan.Winlock.3333 [DrWeb]Trojan-Dropper.Win32.Injector.ifih [Kaspersky]Win32:Dropper-MOI [Drp] [Avast]Adware/SoftonicDownloader [Fortinet]Generic PUP.x!b2q [McAfee]Riskware/BitCoinMiner [Fortinet]not-a-virus:RiskTool.Win32 [Ikarus]Artemis!0BA2A3891D30 [McAfee]W32/Medfos.ALI!tr [Fortinet]Virus.Win32.Cryptor [Ikarus]Trojan/Win32.Midhos [AhnLab-V3]Trojan.Packed.2530 [DrWeb]TrojWare.Win32.Medfos.BR [Comodo]Gen:Variant.Zusy.15974 [BitDefender]
More aliases (630)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Pictures\fungames.exe File name: fungames.exe
Size: 1.61 MB (1611344 bytes)
MD5: 73e1a21086182446a8ebb38df2594518
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Pictures
Group: Malware file
Last Updated: May 13, 2013
%USERPROFILE%\impostazioni locali\dati applicazioni\lollipop\lollipop_04150927.exe File name: lollipop_04150927.exe
Size: 2.48 MB (2487808 bytes)
MD5: 01c6ad3945d63ea9d4e1826b607fc18b
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\impostazioni locali\dati applicazioni\lollipop
Group: Malware file
Last Updated: May 13, 2013
%APPDATA%\Adobe\Flash Player\File Cache\Defrag.exe File name: Defrag.exe
Size: 133.63 KB (133632 bytes)
MD5: d486fee61a5d755ff113ac2b054eef59
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Adobe\Flash Player\File Cache
Group: Malware file
Last Updated: May 13, 2013
%TEMP%\005cab2e.exe File name: 005cab2e.exe
Size: 204.8 KB (204800 bytes)
MD5: 5c14357127548b68b98c054392b7c79b
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: May 13, 2013
%APPDATA%\Flash Update 022013.exe File name: Flash Update 022013.exe
Size: 240.64 KB (240640 bytes)
MD5: 1ebb5f9f5b90455a3be4b3820c0307c5
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 13, 2013
%WINDIR%\winsvchosts.exe File name: winsvchosts.exe
Size: 43.44 KB (43444 bytes)
MD5: c563033382f9655950ba1a68aab5ddbb
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: May 13, 2013
%WINDIR%\system32\xfqfkwodettv.exe File name: xfqfkwodettv.exe
Size: 111.61 KB (111616 bytes)
MD5: d65afd49b3bad00576e981665252803f
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: May 13, 2013
C:\Temporary\iehighutil.exe File name: iehighutil.exe
Size: 526.22 KB (526229 bytes)
MD5: 0ba2a3891d3069ad4564ab8bb3eaae63
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: C:\Temporary\iehighutil.exe
Group: Malware file
Last Updated: March 8, 2024
%SystemDrive%\Documents and Settings\Marv\Local Settings\Application Data\kov.exe File name: kov.exe
Size: 242.17 KB (242176 bytes)
MD5: d399a49bc7c1871a4c8dbad096ec5fdc
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\Marv\Local Settings\Application Data
Group: Malware file
Last Updated: May 13, 2013
%SystemDrive%\64670bfb4cb1da1d12f46b408026f014\vshost.exe File name: vshost.exe
Size: 9.72 KB (9728 bytes)
MD5: 9e341431e1c768cf522aef0c2d9c9005
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\64670bfb4cb1da1d12f46b408026f014
Group: Malware file
Last Updated: May 13, 2013
C:\Users\<username>\AppData\Roaming\360F.exe File name: 360F.exe
Size: 88.8 KB (88800 bytes)
MD5: 6d19d563688d69cfec3a45fc28ceca60
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\360F.exe
Group: Malware file
Last Updated: March 15, 2022
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\lrescfrq.exe File name: lrescfrq.exe
Size: 160.25 KB (160256 bytes)
MD5: ef70046e5350d05a08dc14435a9d2291
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: May 13, 2013
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\oqvEjf1n3gs.exe File name: oqvEjf1n3gs.exe
Size: 274.43 KB (274432 bytes)
MD5: 8e11764c01e81f28fb95014a680a6396
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: May 13, 2013
%APPDATA%\Nbt\nbt.exe File name: nbt.exe
Size: 765.95 KB (765952 bytes)
MD5: 8d18b75def96b090e7bfcde70d29ec62
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Nbt
Group: Malware file
Last Updated: May 13, 2013
%ALLUSERSPROFILE%\New.exe File name: New.exe
Size: 1.96 MB (1966991 bytes)
MD5: d31b723109ca1a079f45532f71cd571d
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: May 13, 2013
%WINDIR%\serwos.exe File name: serwos.exe
Size: 152.06 KB (152064 bytes)
MD5: 7cc7b992cf80e4d7cc723fd027e08a9c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: May 13, 2013
%APPDATA%\CG3MEWZJ5CWaddd.exe File name: CG3MEWZJ5CWaddd.exe
Size: 194.56 KB (194560 bytes)
MD5: 2ea6477d5b7395d3060d54ad097e7d12
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 13, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\skype.dat File name: skype.dat
Size: 102.4 KB (102400 bytes)
MD5: e842853b32cf1692ba74c32e701e604c
Detection count: 5
File type: Data file
Mime Type: unknown/dat
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: May 13, 2013
%ALLUSERSPROFILE%\dobr4.dat File name: dobr4.dat
Size: 122.88 KB (122880 bytes)
MD5: 6fd43ea7604f2c7c979fd73d627c371c
Detection count: 5
File type: Data file
Mime Type: unknown/dat
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: May 13, 2013
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\rpeulaaql.exe File name: rpeulaaql.exe
Size: 470.01 KB (470016 bytes)
MD5: 56d1cb0d811c8c6d879a1b4e09af508f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: May 13, 2013

More files
Loading...