Home Malware Programs Backdoors Backdoor.PoisonIvy.j

Backdoor.PoisonIvy.j

Posted: February 13, 2007

PoisonIvy is a backdoor Trojan that gives the attacker unauthorized remote access to a compromised PC. PoisonIvy runs a web server that shows the directory structure of any specified local hard disk. The intruder can steal any file using a web-based interface. PoisonIvy automatically runs on every Windows startup. This places any financial or banking information stored on your computer in severe jeopardy and represents a serious security risk.

File System Modifications

  • The following files were created in the system:
    # File Name File Size (bytes) File Hash
    1 buhtrojan.exe 10,240 1de8213dce05fd80bea50ca1e3aba430
    2 msswcx.exe 10,240 1de8213dce05fd80bea50ca1e3aba430
Loading...