Home Malware Programs Trojans Trojan.Antivar

Trojan.Antivar

Posted: September 10, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 5
First Seen: September 10, 2012
Last Seen: May 5, 2023
OS(es) Affected: Windows

Trojan.Antivar is a Trojan that opens a backdoor on the affected computer. Once executed, Trojan.Antivar copies itself to the certain location. Trojan.Antivar creates files and registry entries on the compromised PC. Trojan.Antivar connects to several remote domains. Trojan.Antivar allows attackers to gain remote access and control over the infected computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%System%\[RANDOM CHARACTERS].exe File name: %System%\[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServerNabs4\"Start" = "2"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServerNabs4\"ObjectName" = "LocalSystem"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServerNabs4\Security\"Security" = [BINARY NUMBERS]HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServerNabs4\"Type" = "272"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SERVERNABS4\0000\"Legacy" = "1"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SERVERNABS4\0000\"DeviceDesc" = "ServerNabs4"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServerNabs4\"DisplayName" = "ServerNabs4"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SERVERNABS4\0000\"Service" = "ServerNabs4"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServerNabs4\"ImagePath" = "%System%\[RANDOM CHARACTERS].exe"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ServerNabs4\"ErrorControl" = "1"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SERVERNABS4\0000\"Class" = "LegacyDriver"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SERVERNABS4\"NextInstance" = "1"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SERVERNABS4\0000\"ConfigFlags" = "0"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SERVERNABS4\0000\"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
Loading...