Home Malware Programs Trojans BackDoor-AWQ.b!djn

BackDoor-AWQ.b!djn

Posted: February 15, 2010

BackDoor-AWQ.b!djn is a backdoor Trojan which provides a hacker with remote-administration on compromised machines. BackDoor-AWQ.b!djn can be instructed to send, receive, execute and delete files while extracting confidential data from the computer. BackDoor-AWQ.b!djn may log activity on the computer and perform many more malicious operations without knowledge to the computer user. BackDoor-AWQ.b!djn is a definite threat to the security of any PC and should be removed once detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Common Files\Microsoft Shared\MSInfo\systems32.exe
    2 %SystemDrive%\AutoRun.inf
    3 %SystemDrive%\systems32.exe
    4 %WinDir%\system32\_systems32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\systems32HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\systems32\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\systems32HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\systems32\Security
Loading...