Pushbot

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 320
First Seen: July 24, 2009
Last Seen: August 27, 2022
OS(es) Affected: Windows

Pushbot is a computer worm that typically spreads via MSN Messenger. Pushbot will infiltrate a system and open an IRC-based backdoor through which a remote attacker can download additional malware onto the system. Pushbot will also send infected messages to a victim's MSN Messenger contacts and gather private data from protected storage. When inside a machine, Pushbot produces outbound traffic and creates a start-up registry entry to prevent its easy removal. A reliable security tool should be able to detect and completely remove Pushbot from an infected PC.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Inject.DBT
AntiVir TR/Agent.196608.4
DrWeb BackDoor.Comet.152
eSafe Win32.Trojan
McAfee W32/Checkout!bi
AntiVir Worm/Pushbot.A.205
McAfee RDN/Generic Dropper!ii
CAT-QuickHeal Worm.Gamarue.B
Panda Trj/OCJ.D
AVG SHeur4.BGGT
Fortinet W32/Agent.HJNE!tr
Ikarus Trojan-Dropper.Win32.Agent
McAfee-GW-Edition PWS-FAVD!5F465959BE6B
AntiVir Worm/Pushbot.A.207
DrWeb Trojan.Packed.24187

SpyHunter Detects & Remove Pushbot

File System Details

Pushbot may create the following file(s):
# File Name MD5 Detections
1. csdrive32.exe 2cdddf024e647be0cdac7cd106bb0dc0 58
2. nvsvc32.exe 20d6b2514ffe727ced75eb03e188f77e 30
3. 35F0.tmp 8cd9856e736a8526b97e6f471cb93c4d 18
4. csdrive32.exe 0058e903630a7cd34c77ae3c758b114c 18
5. 27C8.tmp 4e824d6926163f7163e2f2a25b0c7f69 8
6. 172A.tmp c4580e02273f478c145a970755b1f7ea 7
7. ywdrive32.exe 742151ad4c217f3d5640d31eb8f14a6a 7
8. safari.exe 0d2ece7d0dd44f322e0bca831fb89cf8 7
9. jodrive32.exe 4776d2f0539eb60d3cffc612922805dd 6
10. aadrive32.exe 81e73daae9744e72a9d8182f98240b20 6
11. 148F.tmp d7f61d61d08c277373480eb6a769c224 5
12. tasksvc.exe b4f7542d4f78dae931d1fa8daecd625e 4
13. EB7B.tmp 6a69265924ae440b0cea5a54fc0762ce 4
14. nvsvc32.exe bc4087d173a0c0909cd899a056587348 4
15. 14E7.tmp 9ba537179d59da0902795a338645475d 3
16. mdm.exe 001ffd3acd701db4337cb7c2ed4ab2a6 3
17. yadrive32.exe 37b261855da8001beafb6836ee3fb0ab 3
18. 3F95.exe ed27ae6ea4fb3dfbaa9781cd475996f6 3
19. 410C.tmp 95013fe093be274011ba42f9114b1871 2
20. 6695.tmp e8c4a5ee7c7ecdabd9cee6b10a1c3c42 2
21. 31.exe 559d0888b767ef3a24c4478869a6d85c 2
22. 10.exe d1cc03c551644845e2904974b17b6b02 1
23. 3816.exe 8bda080da1256c2fa345e1927f091e4f 1
24. 6.exe 6004bf5a76eb22d40e92a8f278543213 1
25. 4D.exe 0b22ed62c0b8e0d34e4e21006c662a76 1
More files

Related Posts

Trending

Most Viewed

Loading...