Home Malware Programs Backdoors Backdoor.Pihar!gen1

Backdoor.Pihar!gen1

Posted: February 15, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 14
First Seen: February 15, 2012
Last Seen: March 25, 2022
OS(es) Affected: Windows

Backdoor.Pihar!gen1 is a terrible Trojan that opens a back door on the infected computer system. Once executed, Backdoor.Pihar!gen1 may add malicious files. Backdoor.Pihar!gen1 may also modify the registry. Backdoor.Pihar!gen1 may then create the specific registry entry and take over the master boot record (MBR) so that it can run every time you start Windows starts. Backdoor.Pihar!gen1 can download and install additional malware threats. Backdoor.Pihar!gen1 can contact suspicious websites. Remove Backdoor.Pihar!gen1 immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Windir%\Temp\[RANDOM HEXADECIMAL DIGITS].tmp File name: %Windir%\Temp\[RANDOM HEXADECIMAL DIGITS].tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%SystemDrive%\Documents and Settings\Administrator\Local Settings\Temp\[RANDOM HEXADECIMAL DIGITS].tmp File name: %SystemDrive%\Documents and Settings\Administrator\Local Settings\Temp\[RANDOM HEXADECIMAL DIGITS].tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_[RANDOM HEXADECIMAL DIGITS]

Additional Information

The following URL's were detected:
alerts-defenses.com
Loading...