Troj/Rimecud-DI

Category: Viruses and Spyware Protection available since:12 Feb 2013 02:51:12 (GMT)
Type: Trojan Last Updated:15 Feb 2013 03:48:05 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/Rimecud-DI include:

Example 1

File Information

Size
73K
SHA-1
00139e8c8f23454ff50d261bfaae3b5ad5032756
MD5
7893fc0069358ab14d51f052ccf20576
CRC-32
b286a0de
File type
Windows executable
First seen
2007-07-28

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\mqgka.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Taskman
    c:\Documents and Settings\test user\mqgka.exe
Processes Created
  • c:\windows\system32\svchost.exe
DNS Requests
  • loca.betrule.com
  • mutta.agesask.net
  • uokwa.agesonest.com

Example 2

File Information

Size
94K
SHA-1
0058a517fb0ab2540c4de639a76acd51deab9cbf
MD5
6e56c5a803a9c396475dc27dd14e490a
CRC-32
e3acf2c5
File type
Windows executable
First seen
2013-02-04

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\yoboci.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Taskman
    c:\Documents and Settings\test user\yoboci.exe
Processes Created
  • c:\windows\system32\svchost.exe
DNS Requests
  • loca.betrule.com
  • mutta.agesask.net
  • uokwa.agesonest.com

Example 3

File Information

Size
73K
SHA-1
009b35abe00013908754cc3d3c8884387d77cfcb
MD5
fe8e3967a2cbba2dd8a621b0e1424b75
CRC-32
894609d4
File type
Windows executable
First seen
2013-01-23

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\mqgka.exe
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Taskman
    c:\Documents and Settings\test user\mqgka.exe
Processes Created
  • c:\windows\system32\svchost.exe
DNS Requests
  • loca.betrule.com
  • mutta.agesask.net
  • uokwa.agesonest.com

download Try Sophos products for free
Download now