Home Malware Programs Backdoors Trojan.Midgare.hhn

Trojan.Midgare.hhn

Posted: November 23, 2009

Threat Metric

Threat Level: 6/10
Infected PCs: 326
First Seen: February 14, 2011
Last Seen: March 30, 2020
OS(es) Affected: Windows

Trojan.Midgare.hhn is a backdoor Trojan that attempts to propagate by exploiting local network shares. Trojan.Midgare.hhn will also attempt to join a predefined IRC server and channel in order to allow hackers to participate in dangerous distributed denial-of-service attacks (DDoS attack). DDoS is an attempt by hackers to make a computer resource unavailable to its intended users. Trojan.Midgare.hhn poses a severe security threat to any PC and should be removed upon detection.

Aliases

BackDoor.Generic15.HAH [AVG]Virus.Win32.Crypted [Ikarus]BDS/Bifrose.AE.1121 [AntiVir]Trojan.Win32.Agent.uwyk [Kaspersky]SuspiciousR-Mytob3 [eSafe]PSW.ILSpy [AVG]W32/Generic!tr [Fortinet]Artemis!EBE4C74F6F85 [McAfee]Suspicion: unknown virus [AVG]Trojan-Downloader.Win32.Banload [Ikarus]Heuristic.BehavesLike.Win32.Suspicious-BAY.K [McAfee-GW-Edition]BDS/Bifrose.AE.1680 [AntiVir]Trojan.Packed.196 [DrWeb]TrojWare.Win32.VB.GE [Comodo]Mal/Scribble-D [Sophos]
More aliases (600)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Bifrost\server.exe File name: server.exe
Size: 173.33 KB (173338 bytes)
MD5: 4f7a6c89d72c2e41a47b1ac5c30757df
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Bifrost
Group: Malware file
Last Updated: January 1, 2012
%APPDATA%\Java\Server.exe File name: Server.exe
Size: 186.48 KB (186481 bytes)
MD5: 194401c789a440033700c05181bcf109
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Java
Group: Malware file
Last Updated: July 4, 2011
%WINDIR%\system32\Update\Java.exe File name: Java.exe
Size: 536.07 KB (536077 bytes)
MD5: f468d6547de26c5bd4bb75ad1ab64f3b
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\Update
Group: Malware file
Last Updated: May 13, 2013
%WINDIR%\system32\AppPathchi\AcAdProc.exe File name: AcAdProc.exe
Size: 338.81 KB (338813 bytes)
MD5: 4e2104b0efa75b44866af739b51c968c
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\AppPathchi
Group: Malware file
Last Updated: December 28, 2012
%WINDIR%\system32\explorer\iexplorer.exe File name: iexplorer.exe
Size: 178.99 KB (178992 bytes)
MD5: f67a0c39477e1e7fc4569e4295c6c14b
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\explorer
Group: Malware file
Last Updated: December 22, 2011
%WINDIR%\system32\java\wondoiz.exe File name: wondoiz.exe
Size: 676.57 KB (676573 bytes)
MD5: 3b083db9aaf7d6209821e4d1af10dee5
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\java
Group: Malware file
Last Updated: May 15, 2013
%PROGRAMFILES%\Svchost_mi\svchost.exe File name: svchost.exe
Size: 61.77 KB (61774 bytes)
MD5: 7eab42f30180cf07d4c715460de71e4e
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Svchost_mi
Group: Malware file
Last Updated: April 22, 2013
%WINDIR%\system32\Bifrost\server.exe File name: server.exe
Size: 505.78 KB (505789 bytes)
MD5: 2f4986c6af7aa552c924dff11eaa050c
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\Bifrost
Group: Malware file
Last Updated: May 2, 2013
%APPDATA%\Bifrost\server.exe File name: server.exe
Size: 187.44 KB (187444 bytes)
MD5: 6db04c71ad6e1e0d7da884cdbaf91545
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Bifrost
Group: Malware file
Last Updated: April 26, 2011
%APPDATA%\Bifrost\server.exe File name: server.exe
Size: 46.33 KB (46333 bytes)
MD5: 727448d8eebdfd11e2db5d40e8fe7f92
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Bifrost
Group: Malware file
Last Updated: October 29, 2012
%WINDIR%\J_Y.CuRsE.exe File name: J_Y.CuRsE.exe
Size: 371.94 KB (371943 bytes)
MD5: 0e506dcd30d2f61bb2e47d443bf36ea3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: February 14, 2011
%WINDIR%\system32\drivers\updater.exe File name: updater.exe
Size: 1.22 MB (1226052 bytes)
MD5: 423d97ad942fa42337eab55e985bca9b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: April 16, 2013
%PROGRAMFILES%\Casino770\casino.exe File name: casino.exe
Size: 30.14 KB (30141 bytes)
MD5: c155e2aa357e14ada163ca26291e2a59
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Casino770
Group: Malware file
Last Updated: September 7, 2012
%PROGRAMFILES%\Bifrost\server.exe File name: server.exe
Size: 370.81 KB (370811 bytes)
MD5: 25da3ba6f0365ec79ba0605f5b31a0df
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Bifrost
Group: Malware file
Last Updated: February 25, 2013
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.exe File name: Microsoft Office.exe
Size: 267.57 KB (267578 bytes)
MD5: 4de74dceebaf630a175e10cd9b1aeb43
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: May 2, 2013
%WINDIR%\system32\system32\winlog.exe File name: winlog.exe
Size: 1.52 MB (1527808 bytes)
MD5: 8cb157ddc5ddcef687c16c74f7976886
Detection count: 4
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\system32
Group: Malware file
Last Updated: November 24, 2011
Loading...