Please enable JavaScript to view this site.

Support Site User Guide

Navigation: Malware information

Troj/Pushdo-Gen

Scroll Prev Top Next More

Category:         Viruses and Spyware

Type:                     Trojan

Aliases:           Cutwail Botnet

Affected Operating Systems: Windows

 

Summary

Cutwail is a botnet mostly involved in sending spam e-mails. The bot is typically installed on infected machines by a Trojan component called Pushdo.

 

Symptoms

System changes

The following system changes may indicate the presence of this malware:

The presence of the following files:

c:\documents and settings\administrator\pymqipomukvy.exe

 

Installation

When executed, Backdoor:Win32/Pushdo.A copies itself to c:\documents and settings\administrator\pymqipomukvy.exe.

 

Payload

Allows backdoor access and control

Backdoor:Win32/Pushdo.A allows unauthorized access and control of an affected computer. An attacker can perform any number of different actions on an affected computer using Backdoor:Win32/Pushdo.A. This could include, but is not limited to, the following actions:

Download and execute arbitrary files

Upload files

Spread to other computers using various methods of propagation

Log keystrokes or steal sensitive data

Modify system settings

Run or terminate applications

Delete files

 

Removal

If you are using Sophos please follow the below link for removal instructions.

http://www.sophos.com/en-us/support/knowledgebase/112129.aspx

 

If the Sophos scan does not work you may try using the instructions found at the link provided. (The below guide is not written by Wavenet Education or LGfL so it is used at your own risk)

http://techvts.com/remove-trojan-backdoor-pushdo-a

Return to main page