Home Malware Programs Worms Worm.Mefir.R

Worm.Mefir.R

Posted: November 22, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 19
First Seen: November 22, 2012
OS(es) Affected: Windows

Aliases

FakeAV_s.SP [AVG]W32/FakeAlert.D!tr [Fortinet]Troj/Zbot-DDW [Sophos]Suspicious.Cloud [Symantec]Artemis!39DC44C4275B [McAfee]Trj/CI.A [Panda]TR/Crypt.ZPACK.Gen [AntiVir]Artemis!C343BDEAA5EF [McAfee]W32/FakeAV.SEB!tr [Fortinet]Heuristic.LooksLike.Win32.Suspicious.F!85 [McAfee-GW-Edition]Mal/FakeAV-OY [Sophos]FakeAlert-SecurityTool.gf [McAfee]Trj/Genetic.gen [Panda]Win32/Cryptor [AVG]W32/Kryptik.ZOW!tr [Fortinet]
More aliases (40)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Users\<username>\AppData\Roaming\1027.exe File name: 1027.exe
Size: 21.5 KB (21504 bytes)
MD5: d7edabfc2db90c2a4bbfa287f1f6d4c7
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: November 22, 2012
%WINDIR%\Temp\temp95.exe File name: temp95.exe
Size: 769.53 KB (769536 bytes)
MD5: 4debb6c25b87987e841d3b4fdfe44332
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: December 11, 2012
%WINDIR%\qjbjooha.exe File name: qjbjooha.exe
Size: 66.04 KB (66048 bytes)
MD5: 39dc44c4275b057fc9094e41a59de1ed
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: November 26, 2012
%TEMP%\ntvdm.exe File name: ntvdm.exe
Size: 768.51 KB (768512 bytes)
MD5: b43ae53b160faa682fde725b833eddf3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: November 26, 2012
%APPDATA%\3ED3BA\3ED3BA.exe File name: 3ED3BA.exe
Size: 33.21 KB (33216 bytes)
MD5: c343bdeaa5ef0d19c76a2772629b45dd
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\3ED3BA
Group: Malware file
Last Updated: November 26, 2012
Loading...