Home Malware Programs Backdoors Backdoor.Havar.S

Backdoor.Havar.S

Posted: December 8, 2009

Backdoor.Havar.S is a malicious backdoor Trojan that runs in the background and allows hackers remote access to the compromised system. Backdoor.Havar.S comes armed with a hacktool which hackers use to breach the system. Once unleashed, Backdoor.Havar.S can change Windows Explorer settings to download other malicious files onto the infected computer. Backdoor.Havar.S also has the ability to monitor user activities and steal valuable personal information. Backdoor.Havar.S poses a severe threat to any PC or system and should be terminated on detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Microsoft\Windows Media\9.0\WMSDKNSD.XML

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Tasks\NowPlaying][HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\HTTP][HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\MMS][HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\RTSP][HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\General][HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace]
Loading...