Home Malware Programs Backdoors Backdoor:Win32/Poisonivy.I

Backdoor:Win32/Poisonivy.I

Posted: November 25, 2009

Threat Metric

Threat Level: 8/10
Infected PCs: 9
First Seen: July 24, 2009
Last Seen: July 31, 2021
OS(es) Affected: Windows

Backdoor:Win32/Poisonivy.I (or Backdoor.Win32.PoisonIvy) is a generic detection name for a Trojan that opens a backdoor and allows the attacker to issue commands to control the infected PC. Unlike viruses, Trojans are spread manually and do not self replicate. Backdoor:Win32/Poisonivy.I worms its way into the system using security exploits. Once the server component is unwittingly installed on the victim's machine, Backdoor:Win32/Poisonivy.I opens a port to send a notification to the hacker. The hacker can then connect to the machine using the client component. Distribution channels include emails, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc. Symptoms include the presence of unknown files and registries and unexpected network traffic. Backdoor:Win32/Poisonivy.I is severely dangerous to your PC and should be removed without hesitation.

Backdoor:Win32/Poisonivy.I

Aliases

Suspicious file [Panda]Generic25.RYP [AVG]W32/Swisyn.BWIL!tr [Fortinet]Trojan.Win32.Spy [Ikarus]Trojan.Win32.Swisyn.bwil [Kaspersky]Artemis!CD4F50BDB581 [McAfee]Trojan.Swisyn.bwil [CAT-QuickHeal]TSPY_SPATET.SMT [TrendMicro]W32.Spyrat [Symantec]Trojan.Win32.Generic!BT [Sunbelt]Mal/Behav-328 [Sophos]Trj/CI.A [Panda]a variant of Win32/Spatet.A [NOD32]Backdoor:Win32/Poisonivy.H [Microsoft]Heuristic.BehavesLike.Win32.Dropper.C [McAfee-GW-Edition]
More aliases (42)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



tty.exe File name: tty.exe
Size: 876.54 KB (876544 bytes)
MD5: 56bdbf573815f4f7a4ca3182721b3729
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
drsmartload.exe, drsmartload1.exe File name: drsmartload.exe, drsmartload1.exe
Size: 1.57 KB (1577 bytes)
MD5: 6d08cfa84753b4f9eee4cf40fb60e0f8
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%PROGRAMFILES%\OneUpIndustries\Bins\v0.9.8.189\Bins32on64.exe File name: Bins32on64.exe
Size: 404.48 KB (404480 bytes)
MD5: cd4f50bdb58192c618943e173cc012ff
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\OneUpIndustries\Bins\v0.9.8.189
Group: Malware file
Last Updated: December 27, 2011
Loading...