Home Malware Programs Backdoors Backdoor.Darkmoon

Backdoor.Darkmoon

Posted: December 8, 2009

Backdoor.Darkmoon is a malicious backdoor Trojan that deviously gains access to a computer and then runs in the background. Backdoor.Darkmoon also has the ability to grant hackers access to the corrupted computer. Once active, Backdoor.Darkmoon is programmed to send out email messages via a built-in SMTP client engine. Hackers can instruct Backdoor.Darkmoon to send, receive, execute and delete files, thus compromising the security and privacy of personal information. Backdoor.Darkmoon contains all the characteristics of a severe threat and should therefore be removed from the infected computer immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\zdfangyu.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{674C935D-0B6B-119F-04CC-C326C85A93E2}]
Loading...