Skip to main content

Backdoor:W32/Ptsnoop

Classification

Category:

Malware

Type:

Backdoor

Aliases:

  • Backdoor:W32/Ptsnoop
  • Backdoor:W32/Ptsnoop
  • Backdoor.Ptsnoop

Summary

A remote administration utility that bypasses normal security mechanisms to secretly control a program, computer or network.

Removal

Technical Details

Ptsnoop is a simple backdoor program written in Visual Basic.

Please note that certain software packages for certain modems contain PTSNOOP.EXE files, but these are not trojans. If you are not sure if that file is a trojan or not, use F-Secure Anti-Virus to check it out.

Installation

When activated it first looks for active RAS connections and exits immediately if none is found.

If a connection is present, the backdoor installs itself to system by copying itself as PTSNOOP.EXE file to \Windows\System\ directory and modifying WIN.INI file. The backdoor adds its execution string after LOAD= variable in [Windows] section of WIN.INI file.

During this operation, the WIN.INI file is copied to the WIN.ANA file. The backdoor's execution string is then added and WIN.INI file is deleted. Then WIN.ANA file is renamed to WIN.INI file. This way the backdoor will become active every time Windows starts.

Activity

Being active the backdoor tries to connect to the following websites:

  • http://setway.cjb.net
  • http://setway1.cjb.net
  • http://setone.cjb.net

When the connection succeeds, the backdoor clips cursor to a certain area and allows a hacker or script on these websites to control mouse movement and window positions. It is not clear why this is done and it is impossible to check any more because the contents of the above mentioned websites were changed or removed.

The idea might have been to make a user click on certain areas of a website to download or run a script or binary from there. In any case, this backdoor should be deleted from a system and WIN.INI file should be cleaned from backdoor's execution string after LOAD= variable.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.