Troj/Medfos-BH

Category: Viruses and Spyware Protection available since:18 Nov 2012 05:32:34 (GMT)
Type: Trojan Last Updated:18 Nov 2012 05:32:34 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Medfos-BH exhibits the following characteristics:

File Information

Size
161K
SHA-1
c78300cc569a5f48f9f92034d42097e3535218d5
MD5
34614d47031ae601e4efe445c4c4d971
CRC-32
bbf648f0
File type
Windows executable
First seen
2012-11-17

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Application Data\npalmg.dll
    Size
    161K
    SHA-1
    d00380a57cbea7121163e72bce63a944623bb570
    MD5
    0129ff1b2d1693d19317b979c4fadc29
    CRC-32
    24fb06b6
    File type
    Windows executable
    First seen
    2012-11-18
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    npalmg
    rundll32.exe "c:\Documents and Settings\test user\Application Data\npalmg.dll",FInitializeRichEdit
Processes Created
  • c:\windows\system32\rundll32.exe
HTTP Requests
  • http://megaupload.com/upload/fid=BwCRAAEAhg8CAAEFCAAAAAAAAAAAAAAAAAAAAABnDAsPCwAAAKHze-niEWIwrLhxgiZvmW-__aZQAABVVVVVVVVVVVVVVVVVVVVVJcXNAWBrLS-GDwIAdHdzdHR4dX5zZwUGAQIDBAUGAQITkSInGkWqQwAAAAAAAQcAAAAHAAAANFYA
IP Connections
  • 172.0.16.2:80
DNS Requests
  • 11un9m1.cdn103.uploadetchosting.com

download Try Sophos products for free
Download now