Home Malware Programs Backdoors Backdoor.Curioso

Backdoor.Curioso

Posted: July 13, 2010

Backdoor.Curioso is a malicious backdoor Trojan horse that runs in the background and allows remote access to the compromised system. Backdoor.Curioso attempts to propagate by exploiting local network shares. Backdoor.Curioso will also attempt to join a predefined IRC server to channel stolen data or participate in distributed denial-of-service (DDoS) attacks. The DDoS attacks will attempt to make the computer unavailable to its intended users. It is recommended that Backdoor.Curioso be removed with a reliable anti-spyware application.

Aliases

Backdoor.Win32.Curioso.hg (Kaspersky Lab)
Mal/Generic-L (Sophos)
Backdoor:Win32/Comdark.A (Microsoft)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\System\System Tools.exe
    2 %Windir%\3.exe
    3 %Windir%\3.jpg

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\WinRAR SFX]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...