Home Malware Programs Backdoors Backdoor.Usinec.A

Backdoor.Usinec.A

Posted: January 18, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 717
First Seen: November 18, 2011
OS(es) Affected: Windows

Backdoor.Usinec.A is a backdoor Trojan that has been generated to steal personal information and transmit it to a remote server. Backdoor.Usinec.A can connect to a remote server to receive instructions, and then later download other malicious files and install them onto your computer system. Backdoor.Usinec.A infiltrates into your PC system stealthily and hides its existence on the computer system. Backdoor.Usinec.A drops malicious system files in the Windows system folder. Backdoor.Usinec.A allows other malware threats to access your PC system. Backdoor.Usinec.A modifies the registry so that it can run automatically every time you start Windows. Backdoor.Usinec.A is installed as a Winlogon notification package which means that it is executed in the same address as 'winlogon.exe'. Winlogon.exe is a legitimate Windows executable that runs all of the time, and thus it can be inferred that by using the same address space as a legitimate process Backdoor.Usinec.A attempts to disguise its existence and evade detection by security software. Uninstall Backdoor.Usinec.A immediately after detection.

Aliases

Agent3.BKDW [AVG]BDS/Usinec.A.42 [AntiVir]BackDoor.Pigeon.64498 [DrWeb]Trojan.Win32.Agent.rpnf [Kaspersky]Trojan.Agent.rpnf [CAT-QuickHeal]Agent3.AVZJ [AVG]Mal/Agent-AFJ [Sophos]TR/Refpron.1.3 [AntiVir]BackDoor.Pigeon.62680 [DrWeb]Trojan.Win32.Agent.pyut [Kaspersky]Win32.TRRefpron [eSafe]Win32:Delf-RFE [Trj] [Avast]Suspicious file [Panda]BackDoor.Generic15.TJ [AVG]TR/Refpron.1.52 [AntiVir]
More aliases (168)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\NEUSBw32.dll File name: NEUSBw32.dll
Size: 156.67 KB (156672 bytes)
MD5: e4f4e5b99946c1777f6fa2a4d62afc62
Detection count: 148
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: September 25, 2012
%WINDIR%\system32\USB3Sw32.dll File name: USB3Sw32.dll
Size: 38.4 KB (38400 bytes)
MD5: 6ee7fd99355485122764b7dacf091bb7
Detection count: 28
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: October 8, 2012
%WINDIR%\system32\inusbw32.dll File name: inusbw32.dll
Size: 162.3 KB (162304 bytes)
MD5: e3559f201a91484a23549e06ae5d2096
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 24, 2011
ntusbw32.dll File name: ntusbw32.dll
Size: 37.88 KB (37888 bytes)
MD5: 3d4d4cf498c512cda6e6ba81360b1c00
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 5, 2011
%WINDIR%\system32\usbniw32.dll File name: usbniw32.dll
Size: 37.88 KB (37888 bytes)
MD5: ea110a7ea46995c9de4fc6b01b30b5c0
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: August 27, 2012

More files
Loading...