pobmyr.exe

The executable pobmyr.exe has been detected as malware by 26 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Microsoft Update Machine’.
MD5:
b10ee3c429c17d64196d38215cebd9f3

SHA-1:
1cbc3e6cadb8e27107fcccdcae1d9ab4bb97421a

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/30/2024 2:01:10 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Xema.variant
2010.05.26

Avira AntiVirus
Worm/Rbot.210944
8.2.1.242

Emsisoft A-Squared
Backdoor.Rbot!IK
4.5.0.50

avast!
Win32:Rbot-CSN
2014.9-170305

AVG
BackDoor.RBot
2018.0.2448

Bitdefender
Backdoor.Agent.1
1.0.20.320

Clam AntiVirus
Exploit.DCOM.Gen
0.98/170.3

Comodo Security
Backdoor.Win32.Rbot.~AB
4942

Dr.Web
Win32.HLLW.MyBot.based
9.0.1.064

ESET NOD32
Win32/Rbot (variant)
11.5146

F-Prot
W32/Ircbot.1!Generic
v6.4.6.0.103

F-Secure
Backdoor.Agent.1
11.2017-05-03_1

G Data
Backdoor.Agent
17.3.21

IKARUS anti.virus
Backdoor.Rbot
t3scan.1.1.84.0

Kaspersky
Backdoor.Win32.Rbot
14.0.0.-1265

McAfee
W32/Sdbot.worm.gen.g
5600.6104

Microsoft Security Essentials
Backdoor:Win32/Rbot.gen
1.163.1557.0

Norman
W32/Obfuscated.FA
11.20170305

nProtect
Backdoor/W32.RBot.287852.B
10.05.26.01

Panda Antivirus
W32/Gaobot.gen.worm
17.03.05.11

Quick Heal
Win32.Backdoor.Rbot.gen.5
3.17.10.00

Rising Antivirus
Backdoor.Win32.Rbot.GEN
23.00.65.17303

Sophos
W32/Rbot-Gen
4.53

Trend Micro House Call
WORM_SPYBOT.GEN
7.2.64

Trend Micro
WORM_SPYBOT.GEN
10.465.05

Vba32 AntiVirus
OScope.Backdoor.Sdbot.Cgen
3.12.12.5

File size:
281.1 KB (287,852 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\pobmyr.exe

File PE Metadata
Compilation timestamp:
1/6/2010 10:19:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1A980

Entry point:
55, 8B, EC, 6A, FF, 68, F0, 3C, 43, 00, 68, 44, E0, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, C4, A4, 53, 56, 57, 89, 65, E8, FF, 15, 84, 13, 47, 00, A3, 50, EF, 46, 00, A1, 50, EF, 46, 00, C1, E8, 08, 25, FF, 00, 00, 00, A3, 5C, EF, 46, 00, 8B, 0D, 50, EF, 46, 00, 81, E1, FF, 00, 00, 00, 89, 0D, 58, EF, 46, 00, 8B, 15, 58, EF, 46, 00, C1, E2, 08, 03, 15, 5C, EF, 46, 00, 89, 15, 54, EF, 46, 00, A1, 50, EF, 46, 00, C1, E8, 10, 25, FF, FF, 00, 00, A3, 50, EF, 46, 00, 6A, 01, E8, 9D...
 
[+]

Entropy:
6.4984

Developed / compiled with:
Microsoft Visual C++

Code size:
196.5 KB (201,216 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Microsoft Update Machine

Command:
pobmyr.exe


Remove pobmyr.exe - Powered by Reason Core Security