In this message, I am going to explain the way the Pteranodon trojan infused right into your system, and also how to eliminate Pteranodon trojan virus.
What is Pteranodon trojan?
Name | Pteranodon |
Infection Type | Trojan |
Symptoms |
|
Similar behavior | RootkitDrv, Cryptbot, SpySnake, Lowzones, Vastloust, Phdet |
Fix Tool | See If Your System Has Been Affected by Pteranodon trojan |
Trojan viruses are among the leading malware types by its injection rate for quite a long period of time. And currently, during the pandemic, when malware became significantly active, trojan viruses raised their activity, too. You can see a lot of messages on various resources, where users are grumbling concerning the Pteranodon trojan virus in their computer systems, and also requesting assisting with Pteranodon trojan virus elimination.
Trojan Pteranodon is a sort of virus that infiltrates into your personal computer, and then performs a wide range of malicious functions. These features rely on a kind of Pteranodon trojan: it might function as a downloader for additional malware or as a launcher for an additional destructive program which is downloaded together with the Pteranodon trojan virus. Over the last two years, trojans are additionally distributed through email attachments, and most of cases utilized for phishing or ransomware infiltration.
Pteranodon2 also known as
Lionic | Trojan.Win32.Badur.m658 |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.GenericKD.34129137 |
FireEye | Generic.mg.ca84499e96eae4e1 |
McAfee | GenericR-PBW!CA84499E96EA |
Cylance | Unsafe |
K7AntiVirus | Trojan ( 00552a461 ) |
Alibaba | Trojan:BAT/Pteranodon.79d8e8fc |
K7GW | Trojan ( 00552a461 ) |
CrowdStrike | win/malicious_confidence_100% (W) |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | Win32/Pterodo.QO |
APEX | Malicious |
Paloalto | generic.ml |
ClamAV | Win.Malware.Vaultcrypt-7536195-0 |
Kaspersky | HEUR:Trojan.Win32.Generic |
BitDefender | Trojan.GenericKD.34129137 |
Avast | Win32:Malware-gen |
Ad-Aware | Trojan.GenericKD.34129137 |
Emsisoft | Trojan.GenericKD.34129137 (B) |
DrWeb | Trojan.DownLoader27.48055 |
TrendMicro | TROJ_GEN.R002C0DKN21 |
McAfee-GW-Edition | GenericR-PBW!CA84499E96EA |
Sophos | Mal/Generic-S |
SentinelOne | Static AI – Suspicious PE |
GData | Trojan.GenericKD.34129137 |
Jiangmin | Trojan.Generic.dmbkj |
Avira | HEUR/AGEN.1123656 |
Gridinsoft | Ransom.Win32.Sabsik.sa |
Arcabit | Trojan.Generic.D208C4F1 |
Microsoft | Trojan:BAT/Pteranodon.A |
Cynet | Malicious (score: 99) |
AhnLab-V3 | Trojan/Win32.Agent.R259494 |
VBA32 | Trojan.Downloader |
ALYac | Trojan.GenericKD.34129137 |
MAX | malware (ai score=84) |
Malwarebytes | Malware.AI.4142408651 |
TrendMicro-HouseCall | TROJ_GEN.R002C0DKN21 |
Yandex | Trojan.Agent!zVJ3pBPbHGA |
Ikarus | Trojan.Win32.Pterodo |
MaxSecure | Trojan.Malware.300983.susgen |
Fortinet | W32/Pterodo.QO!tr |
AVG | Win32:Malware-gen |
Panda | Trj/Genetic.gen |
Domains that associated with Pteranodon:
0 | wpad.local-net |
What are the symptoms of Pteranodon trojan?
- SetUnhandledExceptionFilter detected (possible anti-debug);
- Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution;
- Yara rule detections observed from a process memory dump/dropped files/CAPE;
- Creates RWX memory;
- Guard pages use detected – possible anti-debugging.;
- A process attempted to delay the analysis task.;
- Dynamic (imported) function loading detected;
- Performs HTTP requests potentially not found in PCAP.;
- A named pipe was used for inter-process communication;
- Reads data out of its own binary image;
- A process created a hidden window;
- CAPE extracted potentially suspicious content;
- Unconventionial language used in binary resources: Russian;
- Authenticode signature is invalid;
- Uses Windows utilities for basic functionality;
- Collects and encrypts information about the computer likely to send to C2 server;
- Creates a hidden or system file;
- Detects Bochs through the presence of a registry key;
- Anomalous binary characteristics;
- Uses suspicious command line tools or Windows utilities;
The frequent sign of the Pteranodon trojan virus is a gradual appearance of different malware – adware, browser hijackers, and so on. As a result of the activity of these harmful programs, your system becomes really slow: malware consumes large amounts of RAM and CPU capabilities.
One more detectable impact of the Pteranodon trojan virus existence is unidentified programs showed off in task manager. Often, these processes may try to mimic system processes, however, you can understand that they are not legit by checking out the genesis of these processes. Pseudo system applications and Pteranodon trojan’s processes are always listed as a user’s processes, not as a system’s.
How to remove Pteranodon trojan virus?
- Download and install Loaris Trojan Remover.
- Open Loaris and perform a “Standard scan“.
- “Move to quarantine” all items.
- Open “Tools” tab – Press “Reset Browser Settings“.
- Approve the reset pressing “Yes” button in the appeared window.
- Restart your computer.
To clean up Pteranodon trojan and also ensure that all added malware, downloaded with the help of this trojan, will be eliminated, as well, I’d recommend you to use Loaris Trojan Remover.
Pteranodon removal guide
To spot and remove all viruses on your computer using Loaris, it’s better to use Standard or Full scan. Removable scan, as well as Custom, will scan only specified folders, so such checks cannot provide the full information.
You can see the detects till the scan process lasts. Nonetheless, to execute any actions against detected malware, you need to wait until the process is over, or to interrupt the scanning process.
To choose the special action for each detected malicious programs, choose the knob in front of the detection name of detected malicious programs. By default, all malware will be sent to quarantine.
How to remove Pteranodon Trojan?
Name: Pteranodon
Description: Trojan Pteranodon is a kind of virus that infiltrates into your computer, and after that performs different destructive functions. These features depend upon a type of Pteranodon trojan: it can act as a downloader for many other malware or as a launcher for another destructive program which is downloaded in addition to the Pteranodon trojan. During the last two years, trojans are also dispersed via e-mail attachments, and most of situations utilized for phishing or ransomware infiltration.
Operating System: Windows
Application Category: Trojan
User Review
( votes)- What is Trojan Horse: https://en.wikipedia.org/wiki/Trojan_horse_(computing)
- Pteranodon VirusTotal Report: https://www.virustotal.com/api/v3/files/113cd8002383282ecb78355fe3a81d90b45b997a84c7cfa2fd5361aa5067084f