Poinbag

By GoldSparrow in Browser Helper Object

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 6
First Seen: October 3, 2011
Last Seen: September 2, 2021
OS(es) Affected: Windows

Poinbag is a Browser Helper Object (BHO) that communicates with a remote server without a computer user's permission and knowledge. Poinbag may display contextual advertisements while browsing the web and using Yahoo! or Google search. Once Poinbag is installed, it adds some system files and modifies the registry in order to add itself as a BHO so that it can run when Internet Explorer (IE) is started. Remove Poinbag immediately after detection.

File System Details

Poinbag may create the following file(s):
# File Name Detections
1. comparison_pointbag.dll
2. %APPDATA%pointbag_hidden.exe

Trending

Most Viewed

Loading...