Home Malware Programs Trojans Trojan.Medfos.A

Trojan.Medfos.A

Posted: October 22, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 466
First Seen: October 22, 2012
OS(es) Affected: Windows

Aliases

Medfos-FAUM!DF1B6ED19158 [McAfee-GW-Edition]Gen:Variant.Symmi.15986 [BitDefender]Trojan.Win32.Midhos.beuy [Kaspersky]Generic32.QBW [AVG]RDN/Generic.tfr!r [McAfee-GW-Edition]TR/Medfos.A.2277 [AntiVir]Trojan.DownLoader8.24307 [DrWeb]Medfos-FAUM!158FC96B9AB9 [McAfee-GW-Edition]Trojan.Win32.Midhos.aoct [Kaspersky]Injector.EUZ [AVG]Virus.Win32.Vundo [Ikarus]Trojan.Win32.Midhos.xer [Kaspersky]Win32:Agent-AQLR [Trj] [Avast]Medfos.bh [McAfee]Trojan.Midhos.xer [CAT-QuickHeal]
More aliases (481)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Users\<username>\AppData\Roaming\agsqlc.dll File name: agsqlc.dll
Size: 154.62 KB (154624 bytes)
MD5: ea222eba99f858aec1744f35d93f717c
Detection count: 83
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: March 12, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\wasgi.dll File name: wasgi.dll
Size: 155.13 KB (155136 bytes)
MD5: 2a21256f36dcb8316f81ec5a317c9197
Detection count: 75
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: February 11, 2013
%SystemDrive%\Documents and Settings\branka.juran\Application Data\msizci.dll File name: msizci.dll
Size: 185.85 KB (185856 bytes)
MD5: e66c234538e00bc1c77ca16ffafe5f60
Detection count: 71
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Documents and Settings\branka.juran\Application Data
Group: Malware file
Last Updated: January 31, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\tsomr.dll File name: tsomr.dll
Size: 170.49 KB (170496 bytes)
MD5: 04073354af0079f510c824bc0940ebba
Detection count: 64
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: April 16, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\etfgv.dll File name: etfgv.dll
Size: 153.08 KB (153088 bytes)
MD5: 60ae03be0c5f2ce1515cee0d7d84e1d8
Detection count: 64
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: May 1, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\wscmer.dll File name: wscmer.dll
Size: 161.79 KB (161792 bytes)
MD5: f7d38e58e62712bf0c77d2f109c5dd2b
Detection count: 42
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: April 16, 2013
%APPDATA%\dealsi.dll File name: dealsi.dll
Size: 158.72 KB (158720 bytes)
MD5: 1498b93ca2fe76007e06b46dda25eb52
Detection count: 24
File type: Dynamic link library
Mime Type: unknown/dll
Path: %APPDATA%
Group: Malware file
Last Updated: March 21, 2013
%SystemDrive%\Documents and Settings\juana.ramirez.SERVER\Datos de programa\mdlshi.dll File name: mdlshi.dll
Size: 165.88 KB (165888 bytes)
MD5: b32ca0d6e59d2c32d2b870c945308691
Detection count: 24
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Documents and Settings\juana.ramirez.SERVER\Datos de programa
Group: Malware file
Last Updated: April 8, 2013
%APPDATA%\ronui.dll File name: ronui.dll
Size: 161.28 KB (161280 bytes)
MD5: ba2984ab1a23ed15004481de33669547
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %APPDATA%
Group: Malware file
Last Updated: April 8, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\ethap.dll File name: ethap.dll
Size: 152.57 KB (152576 bytes)
MD5: 87332e80f7543043da9f49361350adcf
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: February 11, 2013
%SystemDrive%\Documents and Settings\Owner\Local Settings\Application Data\cbrpnbtm.exe File name: cbrpnbtm.exe
Size: 178.68 KB (178688 bytes)
MD5: d8ab9a6165fa62530489af70a41b5e93
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\Owner\Local Settings\Application Data
Group: Malware file
Last Updated: May 13, 2013
%SystemDrive%\Documents and Settings\KURT\Application Data\ostmg.dll File name: ostmg.dll
Size: 166.91 KB (166912 bytes)
MD5: 83ff87c5776ba5197cd9676400f31826
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Documents and Settings\KURT\Application Data
Group: Malware file
Last Updated: April 16, 2013
C:\Users\<username>\AppData\Roaming\nepork.dll File name: nepork.dll
Size: 168.44 KB (168448 bytes)
MD5: e72d1a363f9c0bd83ee2f3ac9d41be7a
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: March 4, 2013
%SystemDrive%\Documents and Settings\Owner\Application Data\prerv.dll File name: prerv.dll
Size: 150.52 KB (150528 bytes)
MD5: 338f6378f6b99b2d14f3aa8ed2e4f93f
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Documents and Settings\Owner\Application Data
Group: Malware file
Last Updated: March 21, 2013
%SystemDrive%\Documents and Settings\Owner\Application Data\etapev.dll File name: etapev.dll
Size: 176.64 KB (176640 bytes)
MD5: df1b6ed1915881b18f558440db0ad4bd
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Documents and Settings\Owner\Application Data
Group: Malware file
Last Updated: May 15, 2013
%USERPROFILE%\Local Settings\Application Data\tutrkcua.exe File name: tutrkcua.exe
Size: 176.64 KB (176640 bytes)
MD5: ced9f5a50bf78eae133f2ee31c4cfff6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: March 21, 2013
%APPDATA%\bthetx.dll File name: bthetx.dll
Size: 183.29 KB (183296 bytes)
MD5: dd863e7fba895b849e798df08fd67fc0
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %APPDATA%
Group: Malware file
Last Updated: March 29, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\wlapt.dll File name: wlapt.dll
Size: 147.96 KB (147968 bytes)
MD5: 116ee26bec44f6d0154548715446793c
Detection count: 2
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: March 21, 2013
%SystemDrive%\Documents and Settings\Parkshire Apartments\Application Data\wemsdi.dll File name: wemsdi.dll
Size: 150.01 KB (150016 bytes)
MD5: a7f467b820823cf2e82e9750a58c6896
Detection count: 0
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Documents and Settings\Parkshire Apartments\Application Data
Group: Malware file
Last Updated: April 8, 2013

More files
Loading...