Trojan

What is “Trojan:Win32/Ontonphu.B”?

Malware Removal

The Trojan:Win32/Ontonphu.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ontonphu.B virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself

Related domains:

yzf-r250.co.cc

How to determine Trojan:Win32/Ontonphu.B?


File Info:

crc32: A50DFEFF
md5: 79eac03e262f3d4dc1cd5a1cb0ea26ff
name: 79EAC03E262F3D4DC1CD5A1CB0EA26FF.mlw
sha1: 48156c17690b08908607d33fdee1417f07ed141c
sha256: 56b3a76c2231b4ced66267974c99f7b6637e436c3de0e52470f0513e9194dadc
sha512: 6014b97487fa39dab6f8b7c32c111d6565c38a78cea0cc65494d9a119a01b7e7cbb9f59c8a37ebf7e6316a0cb313ab63c52e1aac75181f2b5517fae63dde9739
ssdeep: 384:QeGd2B/zP4RIR6rHpkNggt7dNifOzsNtBk5VmLuQhOBMT1dv8RENIoUkxuc75Qi:Ek/zPc8YJkXtTi2YPOBMT1UhoUCei
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ontonphu.B also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader5.21548
CynetMalicious (score: 100)
ALYacGen:Trojan.ShellStartup.cKW@aaUs7eb
CylanceUnsafe
ZillyaTool.Ramagedos.Win32.3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Blocker.591090a2
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.e262f3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Flooder.Ramagedos.E
APEXMalicious
AvastWin32:Virtu-F [Inf]
ClamAVWin.Trojan.Agent-616693
KasperskyTrojan-Ransom.Win32.Blocker.jeyp
BitDefenderGen:Trojan.ShellStartup.cKW@aaUs7eb
NANO-AntivirusTrojan.Win32.Dwn.ouwwk
MicroWorld-eScanGen:Trojan.ShellStartup.cKW@aaUs7eb
TencentWin32.Trojan.Blocker.Alje
Ad-AwareGen:Trojan.ShellStartup.cKW@aaUs7eb
SophosML/PE-A + Mal/Onton-A
ComodoMalware@#203dn7zn5ty6t
BitDefenderThetaAI:Packer.717C528D1E
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.nh
FireEyeGeneric.mg.79eac03e262f3d4d
EmsisoftGen:Trojan.ShellStartup.cKW@aaUs7eb (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.rfla
WebrootW32.Malware.Heur
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.F0CE74
MicrosoftTrojan:Win32/Ontonphu.B
ArcabitTrojan.ShellStartup.EAA762
GDataGen:Trojan.ShellStartup.cKW@aaUs7eb
AhnLab-V3Trojan/Win32.Agent.R51633
McAfeeArtemis!79EAC03E262F
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Blocker
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.83 (RDML:0rTi19SL6LmgK1HVm600vg)
YandexTrojan.GenAsa!ikTQWPnJtjA
IkarusTrojan.Flooder.JBO
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/CoinMiner.F
AVGWin32:Virtu-F [Inf]
Paloaltogeneric.ml

How to remove Trojan:Win32/Ontonphu.B?

Trojan:Win32/Ontonphu.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment