Troj/Comame-E

Category: Viruses and Spyware Protection available since:08 Feb 2013 17:12:43 (GMT)
Type: Trojan Last Updated:08 Feb 2013 17:12:43 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Comame-E exhibits the following characteristics:

File Information

Size
176K
SHA-1
c4e2036213666f84127edcdf4ec2252cb01747c4
MD5
5a609d0179c8cd953eb3b829584b3fe7
CRC-32
6784e429
File type
Windows executable
First seen
2013-01-27

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Temp\Del2.tmp
Dropped Files
  • C:\WINDOWS\Tasks\conime.exe
    Size
    15M
    SHA-1
    363225cebd97cb705ffbc8fabf64dad3ce6d763b
    MD5
    7a44e230e9b453ec3156a8445ab4cc80
    CRC-32
    4728aa01
    File type
    Windows executable
    First seen
    2013-01-27
  • C:\WINDOWS\Tasks\svchost.exe
    Size
    19K
    SHA-1
    c82b81d0d3c186c465814726523ee5461f48410e
    MD5
    8863751434d7f8e125b392c50f854a98
    CRC-32
    e61fbb00
    File type
    Windows executable
    First seen
    2013-01-27
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    taskday
    C:\WINDOWS\tasks\conime.exe
Processes Created
  • c:\docume~1\support\locals~1\temp\del2.tmp
  • c:\windows\system32\rundll32.exe
  • c:\windows\tasks\conime.exe
  • c:\windows\tasks\svchost.exe
HTTP Requests
  • http://nssmc2013.4pu.com/a.asp
DNS Requests
  • nssmc2013.4pu.com

download Try Sophos products for free
Download now