Home Malware Programs Backdoors Backdoor.Gaertob.A

Backdoor.Gaertob.A

Posted: April 13, 2011

Threat Metric

Threat Level: 6/10
Infected PCs: 66
First Seen: November 30, 2010
OS(es) Affected: Windows

Backdoor.Gaertob.A is a backdoor trojan that enables unauthorized access and control of an infected computer. Backdoor.Gaertob.A enters a computer system and runs stealthily without your consent or knowledge. Backdoor.Gaertob.A opens up a backdoor to enable remote access to the affected computer. Once the attackers get access to the targeted computer system through the assistance of Backdoor.Gaertob.A, they can use the compromised PC to propagate Backdoor.Gaertob.A through peer to peer file sharing and will make changes to essential settings of the system. Backdoor.Gaertob.A can update itself over the web and result in a huge security breach for the corrupted computer.

Aliases

Generic Backdoor [Panda]Dropper.Generic6.ABR [AVG]W32/Injector.QVE!tr [Fortinet]Backdoor.Win32.Gaertob [Ikarus]Win32/Palevo.worm.139264.UL [AhnLab-V3]Worm/Win32.Palevo.gen [Antiy-AVL]BDS/Gaertob.A.90 [AntiVir]Trojan.DownLoader6.5307 [DrWeb]UnclassifiedMalware [Comodo]P2P-Worm.Win32.Palevo.eqzx [Kaspersky]Win32:Malware-gen [Avast]WS.Reputation.1 [Symantec]P2PWorm [K7AntiVirus]PWS-Zbot.gen.acn [McAfee]I-Worm.Palevo.eqzx [CAT-QuickHeal]
More aliases (117)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%COMMONPROGRAMFILES%\System\klass.exe File name: klass.exe
Size: 85.5 KB (85504 bytes)
MD5: 27e26578db37b4d7218b7bf6b454f02c
Detection count: 99
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\System
Group: Malware file
Last Updated: November 21, 2011
%USERPROFILE%\M-15-7327-473783-3695\winsrvd.exe File name: winsrvd.exe
Size: 139.26 KB (139264 bytes)
MD5: e0d7bbc2d389462e83cfa03d234653ce
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\M-15-7327-473783-3695
Group: Malware file
Last Updated: December 20, 2012
%PROGRAMFILES%\winlogon.exe File name: winlogon.exe
Size: 303.1 KB (303104 bytes)
MD5: 3389c851a2457a7e3978404fcd02bea2
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%
Group: Malware file
Last Updated: November 30, 2010
%PROGRAMFILES%\winlogon.exe File name: winlogon.exe
Size: 45.05 KB (45056 bytes)
MD5: 4b63cf0d28d932c3aab062220bebb045
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%
Group: Malware file
Last Updated: October 22, 2012
%WINDIR%\ie.exe File name: ie.exe
Size: 93.23 KB (93234 bytes)
MD5: 7f17cbeffc648f2efaa547ab2206dc63
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: December 15, 2010
Loading...