Home Malware Programs Backdoors BackDoor-DKI.gen.ak

BackDoor-DKI.gen.ak

Posted: July 2, 2010

BackDoor-DKI.gen.ak is a malicious Trojan that runs in the background and gives hackers remote access to the system. BackDoor-DKI.gen.ak can easily steal passwords, log keystrokes, create screenshots to control the affected computer. BackDoor-DKI.gen.ak compromises system integrity by making modifications that enable the attacker to use it for malicious activities. BackDoor-DKI.gen.ak shows characteristics of a security threat and should be removed from the system immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Xenocode\Sandbox\1.0.0.0\1430.12.21T22.24\Virtual\STUBEXE\@SYSTEM@\server.exe
    2 %AppData%\Xenocode\Sandbox\1.0.0.0\1430.12.21T22.24\Virtual\XRegistry.bin
    3 %System%\cam\klog.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}]
Loading...