Troj/Rimecud-DG

Category: Viruses and Spyware Protection available since:09 Jan 2013 20:14:57 (GMT)
Type: Trojan Last Updated:09 Jan 2013 20:14:57 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/Rimecud-DG include:

Example 1

File Information

Size
107K
SHA-1
018111736ae946e1e48c617d582f050590f9c9da
MD5
6a4863876d56e4050d9e0bef0c5cefaf
CRC-32
348db931
File type
Windows executable
First seen
2013-01-04

Example 2

File Information

File type
Windows executable

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\celp.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Taskman
    c:\Documents and Settings\test user\celp.exe
Processes Created
  • c:\windows\system32\svchost.exe
DNS Requests
  • loca.betrule.com
  • mutta.agesask.net
  • uokwa.agesonest.com

Example 3

File Information

Size
120K
SHA-1
054b6e813daae2d032ecaff58f466e7598d1e8f3
MD5
ed0c6245051c24d96ed52ec8eb8438ef
CRC-32
3659655a
File type
Windows executable
First seen
2012-12-28

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\ttubyp.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Taskman
    c:\Documents and Settings\test user\ttubyp.exe
Processes Created
  • c:\windows\system32\svchost.exe
DNS Requests
  • loca.betrule.com
  • mutta.agesask.net
  • uokwa.agesonest.com

download Try Sophos products for free
Download now