Home Malware Programs Backdoors Backdoor.Kelihos.F

Backdoor.Kelihos.F

Posted: July 23, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 1,728
First Seen: July 23, 2012
Last Seen: March 12, 2023
OS(es) Affected: Windows

Aliases

Generic32.GWI [AVG]Trojan-PSW.Win32.Tepfer.hcvw [Kaspersky]Ransom-FBGF!2D776ED1565F [McAfee]Generic29.BWJE [AVG]W32/Kryptik.AMJC [Fortinet]Trojan.Win32.Bredolab [Ikarus]Backdoor/Win32.Bredolab [AhnLab-V3]BDS/Kelihos.F.390 [AntiVir]Win32:Kryptik-KBY [Trj] [Avast]FakeAlert-SecurityTool.fy [McAfee]Trojan.PWS.Siggen.59404 [DrWeb]Trojan-PSW.Win32.Tepfer.gjos [Kaspersky]Trojan-FBCP!1F5789A69AD9 [McAfee]TR/Winwebsec.998514 [AntiVir]Trojan-PSW.Win32.Tepfer.chmq [Kaspersky]
More aliases (825)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\Temp\temp52.exe File name: temp52.exe
Size: 842.24 KB (842240 bytes)
MD5: c780b3e5876dc0511e7635893199b724
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: January 29, 2013
%WINDIR%\Temp\temp38.exe File name: temp38.exe
Size: 821.76 KB (821760 bytes)
MD5: 7227d508b0c994da1753160a958f0260
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: March 7, 2013
%TEMP%\update.exe File name: update.exe
Size: 862.72 KB (862720 bytes)
MD5: fdcdcd090c203951cce07f22739bfa97
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 26, 2019
%PROGRAMFILES%\ABBYY FineReader 4.0 Sprint\extract.exe File name: extract.exe
Size: 844.8 KB (844800 bytes)
MD5: 9cfe323dd6a6516c2b20f0e97e289fc3
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ABBYY FineReader 4.0 Sprint
Group: Malware file
Last Updated: February 22, 2013
%PROGRAMFILES(x86)%\ATI Technologies\HydraVision\trustedinstaller.exe File name: trustedinstaller.exe
Size: 765.44 KB (765440 bytes)
MD5: daf48782fcd6c6da7fd7607f8d7415ff
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ATI Technologies\HydraVision
Group: Malware file
Last Updated: January 21, 2013
%TEMP%\spoolsv.exe File name: spoolsv.exe
Size: 828.41 KB (828416 bytes)
MD5: 1f5789a69ad98f779126e0c297243373
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: May 13, 2013
%PROGRAMFILES%\IBM ThinkVantage\Rescue and Recovery\unzip.exe File name: unzip.exe
Size: 763.9 KB (763904 bytes)
MD5: dea9bb576ef36eccef2c82ea2870877e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\IBM ThinkVantage\Rescue and Recovery
Group: Malware file
Last Updated: January 21, 2013
%TEMP%\lsass.exe File name: lsass.exe
Size: 765.95 KB (765952 bytes)
MD5: a74e1dfe368cc5f05cef9e5735a8a36b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: February 6, 2013
%PROGRAMFILES%\Microsoft Office\Office12\pctspk.exe File name: pctspk.exe
Size: 763.9 KB (763904 bytes)
MD5: bbd58044220d02f513cda801fd692452
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microsoft Office\Office12
Group: Malware file
Last Updated: February 26, 2013
%WINDIR%\Temp\temp70.exe File name: temp70.exe
Size: 787.96 KB (787968 bytes)
MD5: e84ea24e5d804e97c7e1d5447930f1c6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: February 11, 2013
%WINDIR%\Temp\temp55.exe File name: temp55.exe
Size: 847.36 KB (847360 bytes)
MD5: 36b82a8f13db3f2ffdc6bead6123c389
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: March 21, 2013
%PROGRAMFILES%\Samsung\Kies\External\DeviceModules\agent.exe File name: agent.exe
Size: 827.9 KB (827904 bytes)
MD5: 8119d28d1f3beb3b8445b10a0bfde2c0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Samsung\Kies\External\DeviceModules
Group: Malware file
Last Updated: April 22, 2013
%WINDIR%\update.exe File name: update.exe
Size: 830.46 KB (830464 bytes)
MD5: 2d776ed1565f8a0f7fba007452ba5615
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: May 13, 2013
%COMMONPROGRAMFILES%\microsoft shared\ink\setup.exe File name: setup.exe
Size: 763.9 KB (763904 bytes)
MD5: 424884777412acee825d05bb8a7640ed
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\microsoft shared\ink
Group: Malware file
Last Updated: February 6, 2013

More files
Loading...