Home Malware Programs Backdoors Backdoor.Ofnipon.A

Backdoor.Ofnipon.A

Posted: December 28, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 487
First Seen: December 28, 2012
Last Seen: November 21, 2021
OS(es) Affected: Windows

Backdoor.Ofnipon.A is a backdoor Trojan that affects Windows computer systems. Backdoor.Ofnipon.A opens a back door on a compromised PC and allows attackers to steal personal information from a victimized computer user. The main aim of Backdoor.Ofnipon.A is to take over the targeted computer in an effort to distribute more malicious programs. Backdoor.Ofnipon.A puts the attacked computer at risk of being damaged. Backdoor.Ofnipon.A spreads via encrypted applications, social engineering scams, spam email attachments or security vulnerabilities. Removal of Backdoor.Ofnipon.A is rather difficult because the malicious file uses the name of a legitimate Windows component. The malicious file may be used to compromise system processes, install BHO, steal passwords, record keystrokes, disable Windows Security Center, use personal accounts for distribution of spam emails and downloads of malware infections. Backdoor.Ofnipon.A also drops another malicious component, the rootkit file and other harmful files of Backdoor.Ofnipon.A.

Aliases

Adware/BaiduBar [Panda]Downloader.Generic2.TCQ [AVG]TROJ_DLOADER.FTX [TrendMicro]Trojan.DownLoader.13908 [DrWeb]Downloader.Delf.azm [eWido]Trojan.Downloader.Delf.UO [BitDefender]Trojan-Downloader.Win32.Delf.azm [Kaspersky]New Malware.ab [McAfee]BackDoor.Generic16.ZAR [AVG]W32/ZAccess.AOWV!tr.bdr [Fortinet]Gen:Variant.Kazy.130966 [BitDefender]Backdoor.Win32.ZAccess.aowv [Kaspersky]ZeroAccess-FARJ!20D7E4048694 [McAfee]W32/Agent.GEA!tr [Fortinet]Win32.Malware [Ikarus]
More aliases (196)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\STW Installer\InstallAssist.exe File name: InstallAssist.exe
Size: 112.12 KB (112128 bytes)
MD5: 1626a2cac422f9ec60400be6595ce6d2
Detection count: 246
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\STW Installer
Group: Malware file
Last Updated: March 5, 2020
%APPDATA%\Update\svchost.exe File name: svchost.exe
Size: 107 KB (107008 bytes)
MD5: cdc522b7a18d7ace94021c17c196f933
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Update
Group: Malware file
Last Updated: December 28, 2012
%APPDATA%\Microsoft\Windows\AdvService.exe File name: AdvService.exe
Size: 421.88 KB (421888 bytes)
MD5: f00d771fb5bba4fb4cf1d2efe03abad4
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows
Group: Malware file
Last Updated: January 5, 2013
%LOCALAPPDATA%\Diagnostics\CrashDumps\xdbkdu.dll File name: xdbkdu.dll
Size: 339.45 KB (339456 bytes)
MD5: a06aa3818cbfb1226ff0319636435083
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Diagnostics\CrashDumps
Group: Malware file
Last Updated: January 5, 2013
%PUBLIC%\Public Documents\Windows Movie Player\players.exe File name: players.exe
Size: 679.93 KB (679936 bytes)
MD5: 333ad557ed81ce213164caecf763f28f
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PUBLIC%\Public Documents\Windows Movie Player
Group: Malware file
Last Updated: April 2, 2020
%APPDATA%\svchost64.exe File name: svchost64.exe
Size: 794.11 KB (794112 bytes)
MD5: 9390381d7e6668b1cb8e608ead4aa501
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 5, 2013
%WINDIR%\svchost\svchost.exe File name: svchost.exe
Size: 1.69 MB (1695744 bytes)
MD5: 3e4525c1a48e7da49b81f83f4d242d52
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\svchost
Group: Malware file
Last Updated: January 5, 2013
%allusersprofile%\Documents\svchast.exe File name: svchast.exe
Size: 786.7 KB (786705 bytes)
MD5: 0e10df45b74afe64843d6c2a222f6195
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %allusersprofile%\Documents
Group: Malware file
Last Updated: January 5, 2013
%WINDIR%\system32\WINL0GON.exe File name: WINL0GON.exe
Size: 18.43 KB (18432 bytes)
MD5: 63dd9c545ff6ff7dd9a4359d75c84cb6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: January 21, 2013
%APPDATA%\nMNtfaARw2l97e30p5ev.exe File name: nMNtfaARw2l97e30p5ev.exe
Size: 1.12 MB (1125699 bytes)
MD5: e7b55d16a5e907f1a2e7f52989547446
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 5, 2013
Loading...