Home Malware Programs Backdoors Backdoor.Pontoeb.P

Backdoor.Pontoeb.P

Posted: August 31, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 178
First Seen: August 31, 2012
OS(es) Affected: Windows

Aliases

Trojan/Win32.Swisyn [AhnLab-V3]Trojan.Win32.Swisyn.aflh!A2 [a-squared]Trojan/Win32.Swisyn.gen [Antiy-AVL]Suspicious:W32/Malware!Gemini [F-Secure]Trojan.Win32.Swisyn.aflh [Kaspersky]Trojan.Swisyn.afen [CAT-QuickHeal]Suspicious file [Panda]Trojan-Ransom.Win32.Gimemo.aogl [Kaspersky]Downloader.Generic13.BIP [AVG]W32/Androm.DW!tr [Fortinet]Trojan-Downloader.Win32.Cutwail [Ikarus]Trojan/Win32.Jorik [AhnLab-V3]TR/Dldr.Cutwail.BS.5 [AntiVir]Mal/NecursDrp-A [Sophos]Gen:Variant.Kazy.89920 [BitDefender]
More aliases (178)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\ReGBe.Bin\071BAAF894C.exe File name: 071BAAF894C.exe
Size: 289.79 KB (289792 bytes)
MD5: b01312211a02bf7b11a6c5a97c08ac04
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\ReGBe.Bin
Group: Malware file
Last Updated: September 10, 2012
%USERPROFILE%\Start Menu\Programs\Startup\dsk.exe File name: dsk.exe
Size: 948.22 KB (948224 bytes)
MD5: 88b2dea5b3c6bd446a3dd8b900d44edc
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: September 14, 2012
%WINDIR%\system32\audiohd.exe File name: audiohd.exe
Size: 111.1 KB (111104 bytes)
MD5: ed933996cf8db387ef1398c84c7baa2b
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: August 31, 2012
%ALLUSERSPROFILE%\lhqom.exe File name: lhqom.exe
Size: 163.77 KB (163772 bytes)
MD5: a1aca3e99fcfabda9734e6f6284053bc
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: September 3, 2012
%APPDATA%\Mozilla\Firefox\Profiles\1ye44dxk.default\extensions\REGEDT32.EXE File name: REGEDT32.EXE
Size: 212.99 KB (212992 bytes)
MD5: efef940fda677d1fa6cde994fde6ab38
Detection count: 14
File type: Executable File
Mime Type: unknown/EXE
Path: %APPDATA%\Mozilla\Firefox\Profiles\1ye44dxk.default\extensions
Group: Malware file
Last Updated: September 3, 2012
%APPDATA%\3E66.exe File name: 3E66.exe
Size: 1.57 MB (1573888 bytes)
MD5: a5f1edcd08574093b156761f7dfb1c57
Detection count: 13
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: September 3, 2012
%LOCALAPPDATA%\{7006D95E-6475-4604-CE3B-8AF9ACAB7760}\syshost.exe File name: syshost.exe
Size: 307.71 KB (307712 bytes)
MD5: a9345212f1e495fdcac36d95bed95fae
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\{7006D95E-6475-4604-CE3B-8AF9ACAB7760}
Group: Malware file
Last Updated: September 3, 2012
%ALLUSERSPROFILE%\Application Data\aLoV2Q38.exe File name: aLoV2Q38.exe
Size: 113.66 KB (113664 bytes)
MD5: cb498d5c413e8118ac3560d24752389d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: September 3, 2012
Loading...