Trojan

Trojan:Win32/Medfos.X information

Malware Removal

The Trojan:Win32/Medfos.X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Medfos.X virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Medfos.X?


File Info:

name: 3F80FA3D4E55E8F743CB.mlw
path: /opt/CAPEv2/storage/binaries/2db0f82c06386a37c1732e90b605005cbe51feacc3d069cf8f0ab657c22d4f3d
crc32: A17187C7
md5: 3f80fa3d4e55e8f743cb2c1af45b5522
sha1: f4d4e4601cacb7bbb77e8cc0b9c8477cafde085e
sha256: 2db0f82c06386a37c1732e90b605005cbe51feacc3d069cf8f0ab657c22d4f3d
sha512: 81b2e82c0744416627339e708bcf279cc3491992f5ade52d97aabdc85532ef12d5b31bc07cd21323005443a3acc79db9bd7cd498350f5ce296c248a3e5197df3
ssdeep: 6144:jRcNpBFqYxe7gBb9n5EQgzdSxa+tam0Cx8LcJIjL:jRcZ4aKiV5WIVaJCuE
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T10D645C81D228542AFF6B05F9C8B219716F9C6CE16B2444E3BCE0BA1E51B6DF1333155B
sha3_384: f80fb54457450ecf7f826b406f7e7494affcea49a3eefddd4eb4526f7858eaff3454e23abc0d6b0b0cca56585ca51235
ep_bytes: 837c240801750e8b442404a32ca80310
timestamp: 2004-08-23 10:41:41

Version Info:

0: [No Data]

Trojan:Win32/Medfos.X also known as:

LionicTrojan.Multi.Generic.lVdV
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.16644
FireEyeGeneric.mg.3f80fa3d4e55e8f7
SkyhighMedfos-FAWL!3F80FA3D4E55
McAfeeMedfos-FAWL
SangforTrojan.Win32.Medfos.Vptk
K7AntiVirusTrojan ( 00397bde1 )
AlibabaTrojan:Win32/Medfos.53007f96
K7GWTrojan ( 00397bde1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Medfos.JB
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.16644
NANO-AntivirusTrojan.Win32.Medfos.bfzakd
AvastWin32:Medfos-FA [Trj]
TencentWin32.Trojan.Generic.Uwhl
SophosMal/Medfos-M
F-SecureHeuristic.HEUR/AGEN.1364681
VIPREGen:Variant.Symmi.16644
TrendMicroTROJ_MEDFOS.SMI
EmsisoftGen:Variant.Symmi.16644 (B)
IkarusWin32.Cryptor
MAXmalware (ai score=100)
GDataGen:Variant.Symmi.16644
WebrootTrojan.Medfos.Gen
GoogleDetected
AviraHEUR/AGEN.1364681
VaristW32/Medfos.I.gen!Eldorado
Antiy-AVLTrojan/Win32.Medfos
KingsoftWin32.Trojan.Generic.a
XcitiumMalware@#juwfp5rqrnv8
ArcabitTrojan.Symmi.D4104
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Medfos.X
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Symmi.R51469
BitDefenderThetaGen:NN.ZedlaF.36744.uu8@aWhtxPab
ALYacGen:Variant.Symmi.16644
VBA32BScope.Malware-Cryptor.SB.01725
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_MEDFOS.SMI
RisingMalware.Undefined!8.C (TFE:2:d3Ri3KQ4HIK)
YandexTrojan.GenAsa!M+FMIiJUiPI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Medfos.FAYZ
FortinetW32/Medfos.IQ!tr
AVGWin32:Medfos-FA [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Medfos.X?

Trojan:Win32/Medfos.X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment