Threat Database Trojans TROJ_PONMOCOP


By Domesticus in Trojans

TROJ_PONMOCOP is a Trojan that induces the unwanted printing routine on the corrupted PC and displays disturbing pop-up ads. TROJ_PONMOCOP code encompasses an encrypted portion, which is loaded and decrypted into memory. When decrypted, it becomes a new binary file that is UPX-packed, and will corrupt the routines from then on. This new binary also encompasses an encrypted code, which needs decryption keys from parameters found in the corrupted PC, for instance, ftCreationTime & ftLastAccessTime of %Windows%\system32 and System Volume Information folder, and the serial number of the hard drive in order to decrypt itself. If the decrypted code is a legitimate binary file, it again sends the control to this newly-created binary. If not, then the routine of TROJ_PONMOCOP will not continue which means that the binary may be unique for each of the targeted computer. All these actions are performed in memory, which means there are no downloaded files. Then, the certain registry keys are being checked by TROJ_PONMOCOP to decrypt additional binaries in memory. These registry keys are based on the infected computer's processor/OS.

SpyHunter Detects & Remove TROJ_PONMOCOP

File System Details

TROJ_PONMOCOP may create the following file(s):
# File Name MD5 Detections
1. %System%\{RANDOM FILE NAME}.dll
2. %Users\{USER NAME}\Appdata\Roaming\{RANDOM FILE NAME}.dll
3. %Documents and Settings\{USER NAME}\Application Data\{RANDOM FILE NAME}.dll
4. %Program Files\{RANDOM FOLDER}\{RANDOM FILE NAME}.dll
5. %Windows%\SysWOW64\{RANDOM FILE NAME}.dll
6. file.exe 7a6d4f0a99e60144eb46dc2c4ad99a26 0
7. file.exe 2cfdf5e345875c7d6f0a7d9c389808e4 0
8. file.exe d80b81a1d63a6c43e85a2c62cabfe133 0
9. file.exe d469fcc0a1299c3e34d78387baeb01d7 0

Registry Details

TROJ_PONMOCOP may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run “msse”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Stats\{RANDOM CHARACTERS}\{RANDOM CHARACTERS}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run “Windows Defender”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Stats\{RANDOM CHARACTERS}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings


Most Viewed
