Backdoor.Ofnipon.A Description

Backdoor.Ofnipon.A is a backdoor Trojan that corrupts Windows PCs. Backdoor.Ofnipon.A opens a back door on an infected computer and enables cybercriminals to steal confidential information from a target PC user. The main purpose of Backdoor.Ofnipon.A is to hijack the affected PC in an attempt to drop other harmful programs. Backdoor.Ofnipon.A sets the victimized PC in danger of being destroyed. Backdoor.Ofnipon.A circulatesvia encrypted applications, social engineering scams, spam emails or security vulnerabilities. Uninstallations of Backdoor.Ofnipon.A is quite hard because the malevolent file uses the name of a genuine Windows file. The malevolent file may be used to hijack system processes, install BHO, steal passwords, rlog keystrokes, disable Windows Security Center, use personal accounts to distribute spam email messages and download various security threats. Backdoor.Ofnipon.A also downloads another damaging rootkit file and malicious files of Backdoor.Ofnipon.A.

Aliases: Adware/BaiduBar [Panda], Downloader.Generic2.TCQ [AVG], TROJ_DLOADER.FTX [TrendMicro], Trojan.DownLoader.13908 [DrWeb], Downloader.Delf.azm [eWido], Trojan.Downloader.Delf.UO [BitDefender], Trojan-Downloader.Win32.Delf.azm [Kaspersky], W32/Delf.SNI, Trojan.DL.Delf.TSH, New Malware.ab [McAfee], BackDoor.Generic16.ZAR [AVG], W32/ZAccess.AOWV!tr.bdr [Fortinet], a variant of Win32/Kryptik.ARCN, Gen:Variant.Kazy.130966 [BitDefender] and Backdoor.Win32.ZAccess.aowv [Kaspersky].

Technical Information

File System Details

Backdoor.Ofnipon.A creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES(x86)%\STW Installer\InstallAssist.exe 112,128 1626a2cac422f9ec60400be6595ce6d2 105
2 %SystemDrive%\RECYCLER\S-1-5-21-1659004503-2049760794-1801674531-1003\$5e219a1619177abc63898bbc03db2a06\n. 53,760 20d7e40486944ff57faabc617bbdff52 19
3 %APPDATA%\xasncfzyulxqhlraknwctes1axthnudg2\svcnost.exe 94,063 8b9d84c0070df016785f4c6d5918271b 17
4 %APPDATA%\Microsoft\Windows\AdvService.exe 421,888 f00d771fb5bba4fb4cf1d2efe03abad4 8
5 %LOCALAPPDATA%\Diagnostics\CrashDumps\xdbkdu.dll 339,456 a06aa3818cbfb1226ff0319636435083 8
6 %PUBLIC%\Public Documents\Windows Movie Player\players.exe 679,936 333ad557ed81ce213164caecf763f28f 7
7 %APPDATA%svchost64.exe 794,112 9390381d7e6668b1cb8e608ead4aa501 3
8 %WINDIR%Explorer.exe 1,879,447 5b223ca94631a54d4248a7ea7e167f63 3
9 %SystemDrive%\Users\Admin\wgsdgsdgdsgsd.dll 192,512 177c1fa92f2485c34955cfc680c9f06f 3
10 %allusersprofile%\Documents\svchast.exe 786,705 0e10df45b74afe64843d6c2a222f6195 2
11 %WINDIR%\system32\WINL0GON.exe 18,432 63dd9c545ff6ff7dd9a4359d75c84cb6 2
12 %APPDATA%nMNtfaARw2l97e30p5ev.exe 1,125,699 e7b55d16a5e907f1a2e7f52989547446 2
13 %SystemDrive%\Users\Brenton\AppData\Roaming\Protector-mowh.exe 2,125,824 66a7d12847817b0ada797222a0ab787b 1
14 %APPDATA%\Update\svchost.exe 107,008 cdc522b7a18d7ace94021c17c196f933 1
More files

Site Disclaimer is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.

HTML is not allowed.