Home Malware Programs Backdoors Cycbot

Cycbot

Posted: October 1, 2010

Threat Metric

Threat Level: 6/10
Infected PCs: 30,593
First Seen: October 1, 2010
Last Seen: July 7, 2022
OS(es) Affected: Windows

Aliases

Win32/Cryptor [AVG]Backdoor.Win32.Gbot [Ikarus]Backdoor/Win32.Gbot [AhnLab-V3]Troj/CycBot-R [Sophos]TR/Kazy.48327 [AntiVir]BackDoor.Gbot.1851 [DrWeb]Gen:Variant.Kazy.48327 [BitDefender]Backdoor.Win32.Gbot.qvo [Kaspersky]Win32:Cycbot-PM [Trj] [Avast]a variant of Win32/Kryptik.XGT [NOD32]Backdoor [K7AntiVirus]BackDoor-EXI.gen.aa [McAfee]PWS.Win32 [Ikarus]BackDoor.Gbot.53 [DrWeb]Trojan.Win32.Jorik.Gbot.cql [Kaspersky]
More aliases (82)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Users\<username>\Application Data\java.exe File name: java.exe
Size: 284.16 KB (284160 bytes)
MD5: 1529e457137f7d1b0ffd9d7fb538ad37
Detection count: 253
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\Application Data
Group: Malware file
Last Updated: November 10, 2016
C:\Users\<username>\Desktop\file.exe File name: file.exe
Size: 166.91 KB (166912 bytes)
MD5: e1bb90ddf62072afea134bfc0f6fe7b1
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop
Group: Malware file
Last Updated: June 4, 2018
%PROGRAMFILES%\LP\0494\AE4.exe File name: AE4.exe
Size: 294.4 KB (294400 bytes)
MD5: f4086ebc9edb0957dff0d4f836cfbab6
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\LP\0494
Group: Malware file
Last Updated: March 19, 2012
%APPDATA%\Microsoft\conhost.exe File name: conhost.exe
Size: 285.18 KB (285184 bytes)
MD5: db884b05bebde8c010d917dd91e37e72
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft
Group: Malware file
Last Updated: July 11, 2011

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\conhost.exe%APPDATA%\Microsoft\conhost.exe

Related Posts

Loading...