In this post, I am going to reveal the way the Ponmocup trojan injected into your PC, as well as how to eliminate Ponmocup trojan virus.
What is Ponmocup trojan?
Name | Ponmocup |
Infection Type | Trojan |
Symptoms |
|
Similar behavior | Lunam, Updane, FakeIE, Ropest, Bunitu, Slingshot |
Fix Tool | See If Your System Has Been Affected by Ponmocup trojan |

Trojan viruses are among the leading malware sorts by its injection frequency for quite a long time. And currently, during the pandemic, when malware became tremendously active, trojan viruses boosted their activity, too. You can see a lot of messages on diverse resources, where people are grumbling concerning the Ponmocup trojan virus in their computers, and requesting aid with Ponmocup trojan virus removal.
Trojan Ponmocup is a type of virus that infiltrates into your personal computer, and then performs different destructive functions. These functions depend upon a kind of Ponmocup trojan: it might work as a downloader for additional malware or as a launcher for an additional harmful program which is downloaded along with the Ponmocup trojan. Over the last two years, trojans are additionally dispersed via email attachments, and in the majority of instances used for phishing or ransomware injection.
Ponmocup2 also known as
Bkav | W32.AIDetect.malware1 |
K7AntiVirus | Trojan ( 001118091 ) |
Elastic | malicious (high confidence) |
DrWeb | Trojan.Siggen.461 |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | TrojanDownloader.Ponmocup.A3 |
ALYac | Trojan.Qhosts.AVO |
Cylance | Unsafe |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_100% (D) |
K7GW | Trojan ( 001118091 ) |
Cybereason | malicious.986c12 |
Baidu | Win32.Trojan.QHost.d |
Cyren | W32/Swisyn.E.gen!Eldorado |
Symantec | W32.Changeup!gen |
ESET-NOD32 | Win32/Qhost.NRX.Gen |
APEX | Malicious |
Avast | Win32:Hosts-J [Trj] |
ClamAV | Win.Trojan.VB-1399 |
Kaspersky | Trojan.Win32.Swisyn.jyb |
BitDefender | Trojan.Qhosts.AVO |
NANO-Antivirus | Trojan.Win32.Swisyn.dwxfph |
ViRobot | Trojan.Win32.Swisyn.65024 |
SUPERAntiSpyware | Trojan.Agent/Gen-HackHost |
MicroWorld-eScan | Trojan.Qhosts.AVO |
Ad-Aware | Trojan.Qhosts.AVO |
Sophos | ML/PE-A + Mal/Swisyn-D |
Comodo | TrojWare.Win32.Swisyn.C@1p36px |
F-Secure | Trojan.TR/VB.Downloader.Gen |
BitDefenderTheta | AI:Packer.0AF258401E |
VIPRE | Trojan.Win32.Swisyn.jyb (v) |
TrendMicro | TROJ_FAM_00001e3.TOMA |
McAfee-GW-Edition | BehavesLike.Win32.VBObfus.cc |
FireEye | Generic.mg.f1a1da0986c1226d |
Emsisoft | Trojan.Qhosts.AVO (B) |
SentinelOne | Static AI – Malicious PE |
Jiangmin | Trojan/Swisyn.byr |
Webroot | W32.Trojan.Swisyn.Gen |
Avira | TR/VB.Downloader.Gen |
eGambit | Unsafe.AI_Score_80% |
Kingsoft | Heur.SSC.2666161.0010.(kcloud) |
Microsoft | TrojanDownloader:Win32/Ponmocup.A |
Arcabit | Trojan.Qhosts.AVO |
ZoneAlarm | Trojan.Win32.Swisyn.jyb |
GData | Trojan.Qhosts.AVO |
TACHYON | Trojan/W32.VB-Agent.103424 |
AhnLab-V3 | Trojan/Win32.Swisyn.R1152 |
Acronis | suspicious |
McAfee | Swisyn.s |
MAX | malware (ai score=84) |
VBA32 | SScope.Trojan.VB.0609 |
Malwarebytes | Trojan.Dropper.IMHCN |
Panda | Trj/Qhost.LU |
TrendMicro-HouseCall | TROJ_FAM_00001e3.TOMA |
Rising | Trojan.Win32.Generic.129F1AE2 (C64:YzY0OiowvEw5GJv/) |
Yandex | Trojan.GenAsa!jBsWUinVWKs |
Ikarus | Worm.Win32.Vobfus |
MaxSecure | Trojan.Swisyn.jyb |
Fortinet | W32/Swisyn.CQV!tr |
AVG | Win32:Hosts-J [Trj] |
Domains that associated with Ponmocup:
0 | imagehut4.cn |
What are the symptoms of Ponmocup trojan?
- Executable code extraction;
- A process attempted to delay the analysis task.;
- A process created a hidden window;
- Performs some HTTP requests;
- Uses Windows utilities for basic functionality;
- Attempts to modify proxy settings;
- The sample wrote data to the system hosts file.;
- Anomalous binary characteristics;
The common sign of the Ponmocup trojan virus is a steady entrance of a wide range of malware – adware, browser hijackers, et cetera. Due to the activity of these malicious programs, your computer ends up being very lagging: malware utilizes large quantities of RAM and CPU abilities.
One more noticeable impact of the Ponmocup trojan virus visibility is unfamiliar programs displayed in task manager. Often, these processes might try to simulate system processes, however, you can understand that they are not legit by looking at the source of these processes. Pseudo system applications and Ponmocup trojan’s processes are always specified as a user’s processes, not as a system’s.
How to remove Ponmocup trojan virus?
- Download and install Loaris Trojan Remover.
- Open Loaris and perform a “Standard scan“.
- “Move to quarantine” all items.
- Open “Tools” tab – Press “Reset Browser Settings“.
- Approve the reset pressing “Yes” button in the appeared window.
- Restart your computer.
To clean up Ponmocup trojan and be sure that all extra malware, downloaded with the help of this trojan, will certainly be eliminated, too, I’d recommend you to use Loaris Trojan Remover.

Ponmocup removal guide
To detect and eliminate all viruses on your computer using Loaris, it’s better to make use of Standard or Full scan. Removable scan, as well as Custom, will scan only specified directories, so these checks cannot provide the full information.
You can see the detects till the scan process goes. Nevertheless, to execute any actions against detected malware, you need to wait until the scan is finished, or to interrupt the scanning process.
To designate the specific action for each detected viruses, click the arrow in front of the name of detected malicious items. By default, all malicious programs will be sent to quarantine.
How to remove Ponmocup Trojan?

Name: Ponmocup
Description: Trojan Ponmocup is a kind of virus that infiltrates into your computer, and after that performs different destructive functions. These features depend upon a type of Ponmocup trojan: it can act as a downloader for many other malware or as a launcher for another destructive program which is downloaded in addition to the Ponmocup trojan. During the last two years, trojans are also dispersed via e-mail attachments, and most of situations utilized for phishing or ransomware infiltration.
Operating System: Windows
Application Category: Trojan
User Review
( votes)- What is Trojan Horse: https://en.wikipedia.org/wiki/Trojan_horse_(computing)
- Ponmocup VirusTotal Report: