Home Malware Programs Trojans Trojan.Madi

Trojan.Madi

Posted: July 18, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 55
First Seen: July 18, 2012
OS(es) Affected: Windows

Trojan.Madi is a Trojan that opens a back door on the affected PC, drops malicious files, and steals personal information from the victim. Once executed, Trojan.Madi copies itself by creating a few potentially malicious files. Trojan.Madi also creates numerous hardcoded file names. Trojan.Madi modifies the certain registry entry so that it can run automatically every time you start Windows. Trojan.Madi can connect to the certain command and control (C&C) server. Trojan.Madi can log keystrokes, capture screenshots and download updates of itself.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



UpdateOffice.exe File name: UpdateOffice.exe
Size: 282.11 KB (282112 bytes)
MD5: 67c6fabbb0534090a079ddd487d2ab4b
Detection count: 88
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: July 19, 2012
file.exe File name: file.exe
Size: 282.62 KB (282624 bytes)
MD5: 3fc8788fd0652e4f930d530262c3d3f3
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: July 19, 2012
%UserProfile%\UpBackup\UpdateOffice.exe (Trojan.Dropper) File name: %UserProfile%\UpBackup\UpdateOffice.exe (Trojan.Dropper)
Mime Type: unknown/Dropper)
Group: Malware file
%UserProfile%\PrintHood\UpdateOffice.exe (Trojan.Dropper) File name: %UserProfile%\PrintHood\UpdateOffice.exe (Trojan.Dropper)
Mime Type: unknown/Dropper)
Group: Malware file
%UserProfile%\PrintHood\mahdi.txt File name: %UserProfile%\PrintHood\mahdi.txt
Mime Type: unknown/txt
Group: Malware file
%UserProfile%\PrintHood\pangtip.bat File name: %UserProfile%\PrintHood\pangtip.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
%UserProfile%\PrintHood\Roze.dll File name: %UserProfile%\PrintHood\Roze.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\PrintHood\SHK.dll File name: %UserProfile%\PrintHood\SHK.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\PrintHood\BIE.dll File name: %UserProfile%\PrintHood\BIE.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\PrintHood\FIE.dll File name: %UserProfile%\PrintHood\FIE.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\PrintHood\SIK.dll File name: %UserProfile%\PrintHood\SIK.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\PrintHood\xdat.dll File name: %UserProfile%\PrintHood\xdat.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\Templates\nam.dll File name: %UserProfile%\Templates\nam.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\My Documents\[ORIGINAL FILE NAME].exe.JPG File name: %UserProfile%\My Documents\[ORIGINAL FILE NAME].exe.JPG
Mime Type: unknown/JPG
Group: Malware file
%UserProfile%\PrintHood\[TEN RANDOM CHARACTERS].dll File name: %UserProfile%\PrintHood\[TEN RANDOM CHARACTERS].dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\PrintHood\[TEN RANDOM CHARACTERS].PRI File name: %UserProfile%\PrintHood\[TEN RANDOM CHARACTERS].PRI
Mime Type: unknown/PRI
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\"Startup" = "%UserProfile%\UpBackup"
Loading...