Home Malware Programs Backdoors Backdoor:Win32/Kelihos.A

Backdoor:Win32/Kelihos.A

Posted: January 3, 2011

Threat Metric

Threat Level: 6/10
Infected PCs: 44
First Seen: December 20, 2010
OS(es) Affected: Windows

Backdoor:Win32/Kelihos.A is a Windows platform backdoor Trojan which opens doors through which additional malware can access compromised PCs. Backdoor:Win32/Kelihos.A can be distributed via spammed e-mail or drive by downloads. Backdoor:Win32/Kelihos.A is a security threat that should be removed with a good malware removal tool soon after detection.

Aliases

Cryptic.BXV [AVG]Email-Worm.Win32.Hlux [Ikarus]Worm/Win32.Hlux.gen [Antiy-AVL]Win32/Renos.BYX [eTrust-Vet]Mal/FakeAV-HU [Sophos]TR/MailBot.B [AntiVir]Trojan.Packed.21335 [DrWeb]TrojWare.Win32.Kryptik.VG [Comodo]Email-Worm.Win32.Hlux.c [Kaspersky]Worm.Hlux [ClamAV]Win32.WormHlux.C [eSafe]Win32:MalOb-EW [Avast]Packed.Generic.315 [Symantec]W32/SuspPack.DA.gen!Eldorado [F-Prot]Win32/Kelihos.B [NOD32]
More aliases (127)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\Temp\b9sjo.exe File name: b9sjo.exe
Size: 720.54 KB (720546 bytes)
MD5: 34b2c67de706ae94402a2fc27a5673b8
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: February 11, 2011
%WINDIR%\Temp\_ex-08.exe File name: _ex-08.exe
Size: 714.96 KB (714961 bytes)
MD5: 99af7c4deca261a2c252bfda2c25422a
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: March 8, 2011
%WINDIR%\Temp\_ex-68.exe File name: _ex-68.exe
Size: 485.88 KB (485888 bytes)
MD5: df0ae12f30617da7a2b76282360fc2b0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Temp
Group: Malware file
Last Updated: October 13, 2011

More files
Loading...