BackDoor-AWQ.gen.r

BackDoor-AWQ.gen.r is a backdoor program. BackDoor-AWQ.gen.r may enter a system via security vulnerabilities or infected internet downloads. The distribution channels forBackDoor-AWQ.gen.r include unsolicited e-mails, hacked web pages and peer-to-peer networks. On entering a PC, BackDoor-AWQ.gen.r will give remote attackers access to an infected computer and the private information stored on it. BackDoor-AWQ.gen.r may also download more malware onto the compromised PC. BackDoor-AWQ.gen.r is a security threat that should be removed upon detection.

Aliases: Backdoor.Gbod, Win32.Hack.Gbod.dv.(kcloud), Trojan.Dropper.UDV (B), Trojan.Agent/Gen-Backdoor, Win.Trojan.Gbod-5 [ClamAV], Win32:Jorik-HP [Trj] [Avast], TROJ_SPNR.07DO13, Malware, Trojan.Win32.Gbod.djhil, Backdoor.Agent, RDN/Generic BackDoor!kv [McAfee], Heuristic.LooksLike.Win32.Suspicious.I [McAfee-GW-Edition], Worm.Zwr!ngBJeLijoIs, Delf.HJDG and W32/Backdoor.AM.gen!Eldorado [F-Prot].

Technical Information

File System Details

BackDoor-AWQ.gen.r creates the following file(s):
# File Name Size MD5 Detection Count
1 %WINDIR%\system32\drivers\etc\svchost.exe 22,528 01a3ab0a7ae19c67deed8685beffdd63 17
2 C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\fresdg.exe 45,575 56c194345f2bb51be3003f2b3c155370 11
3 %WINDIR%\system32\winnt\cssrs.exe 123,392 f3c8ac2f04eb6a686966d2a3eebd0368 4
4 C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1451\games.exe 43,520 e31d59dea9014320947ef9a7ffff9bf6 4
5 %PROGRAMFILES%\Sound Utility\Soundmax.exe 139,264 b3308808c3291c85b845e812fcb3c5e5 3
6 %WINDIR%\Temp\5911470.exe 483,328 efb19e06a994f184b781a3c948e77e6e 3
7 %LOCALAPPDATA%winsvchost.exe 31,744 646a10f134ffc4315f83fe1f14340e32 3
8 %APPDATA%\System32\csrss.exe 85,536 0e39464dfe9616d149556158de299cad 3
9 %TEMP%2743259405.exe 40,448 6fbf43aabaa558b2eb7227270e064ed0 2
10 %WINDIR%\system32\userinit.exe 31,232 3596e383cdcec176e49be321f657a49c 1
11 %USERPROFILE%\Desktop\ek_setup.exe 6,264,876 71082cef20807649757b671d2022b410 1
12 %APPDATA%\Microsoft\winlog.exe 133,632 e3b32da7b24de5e575f0c551cded728a 1
13 %WINDIR%\TEMP\8411338.exe 481,792 20795da70448e36faadd7fafc4198aad 1
14 %WINDIR%\TEMP\9335421.exe 481,792 bb3820f02ebe8b406b5532acd21a8f28 1
15 %WINDIR%\TEMP\7078555.exe 507,904 7bf2d72ecc7d058ab06def55935c051a 1
16 %WINDIR%\TEMP\6337214.exe 502,272 38d7ab4b1d19053b410f17d55f03cc18 1
17 %WINDIR%\Temp\3506435.exe 688,640 ba5232648f07136c5f957844afbcdad8 1
18 %WINDIR%\TEMP\9803075.exe 632,832 0cd76db73f3108cdb413ee8239212ece 1
19 %WINDIR%\Temp\3887270.exe 635,904 739b631acd703db6da144c472796b8a2 1
20 %WINDIR%\Temp\1668578.exe 635,904 5966c5a57e392720dfeb83ecd88c0d6b 1
21 %WINDIR%\TEMP\1016789.exe 1,947,136 3fee1ea8c2240e5892bbf4c32df37193 1
22 %WINDIR%\Temp\5040763.exe 1,944,576 0fb27889e3db78f840e2d6f3eefcdbe8 1
23 %WINDIR%\TEMP\3164874.exe 1,946,624 020c7da3aa19c9b857488c2d34929dc5 1
24 %WINDIR%\Temp\6497268.exe 1,942,528 26f6f7399b732e17eef5c618591c841f 1
25 %SystemDrive%\Users\Jon\AppData\Roaming\cfmvmo.exe 40,960 9f83b8cdfd3493a9e5201132de8d29d6 1
More files

