Home Malware Programs Backdoors Backdoor.Nibu!rem

Backdoor.Nibu!rem

Posted: January 17, 2011

Backdoor.Nibu!rem is a Trojan infection wreaking havoc on the World Wide Web. Backdoor.Nibu!rem is malware designed by hackers to steal sensitive information from the infiltrated computer system, and it may also download alternative potentially malicious files onto the computer system is has infected.

Backdoor.Nibu!rem infiltrates a system via security or browser exploits and is usually unseen once in the system. Backdoor.Nibu!rem will carry out its harmful functionality, and will only compromise the system it has infiltrated. Bear in mind that once Backdoor.Nibu!rem is embedded in the system, it will gather personal, financial and banking information stored on the system, and allow an outside remote controller access to this gathered information.

Remove Backdoor.Nibu!rem immediately once it has been detected or you will soon find yourself cash-strapped and struggling to find your stolen money.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 msauc.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN lsass driverHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ lsass driver
Loading...