Home Malware Programs Backdoors Qakbot.gen!A

Qakbot.gen!A

Posted: December 23, 2010

Threat Metric

Threat Level: 6/10
Infected PCs: 309
First Seen: December 23, 2010
Last Seen: August 31, 2021
OS(es) Affected: Windows

Aliases

TR/PSW.Qbot.bqf [AntiVir]Trojan.Generic.KD.127360 [BitDefender]a variant of Win32/Kryptik.KPK [NOD32]Cryptic.CCH [AVG]TR/PSW.Qbot.bhs [AntiVir]Gen:Variant.Kazy.9722 [BitDefender]Win32:Oficla-BU [Avast]a variant of Win32/Kryptik.KAY [NOD32]Trojan.DownLoader.origin [DrWeb]ApplicUnwnt.Win32.Adware.Agent.~GGS [Comodo]not-a-virus:Downloader.Win32.Agent.dt [Kaspersky]a variant of Win32/SweetIM.A [NOD32]Generic Trojan [Panda]PSW.Generic8.ANRU [AVG]W32/Qbot.AOV!tr.pws [Fortinet]
More aliases (83)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\GabPath\gabpath.exe File name: gabpath.exe
Size: 1.12 MB (1126400 bytes)
MD5: 37605885704af058705b85934e91eaa6
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\GabPath
Group: Malware file
Last Updated: December 28, 2010
%WINDIR%\system32\puwotaw.dll File name: puwotaw.dll
Size: 104.66 KB (104660 bytes)
MD5: 33b9d6b5ee36e0273f1633328118bfd5
Detection count: 36
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: February 14, 2011
%ALLUSERSPROFILE%\uuikid\uuikid.exe File name: uuikid.exe
Size: 56.32 KB (56320 bytes)
MD5: adcc7bc02a23c6e298fe1a1814dc8cba
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\uuikid
Group: Malware file
Last Updated: January 5, 2011
%ALLUSERSPROFILE%\ydaldpu0j\ydaldpu0j.exe File name: ydaldpu0j.exe
Size: 81.4 KB (81408 bytes)
MD5: ed53a9811b838882199dec6a195d0f63
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\ydaldpu0j
Group: Malware file
Last Updated: December 23, 2010

One Comment

  • MikeD says:

    What vulnerability is this taking advantage of? It seems to be authenticating anonymously to infrequently patched systems.

Loading...