Home Malware Programs Backdoors Backdoor.Win32.Agent.bctb

Backdoor.Win32.Agent.bctb

Posted: December 8, 2010

Backdoor.Win32.Agent.bctb (aka Backdoor.VB) is a malicious backdoor Trojan that runs in the background and allows remote access to the compromised system. Backdoor.Win32.Agent.bctb attempts to propagate by exploiting local network shares. Backdoor.VB will also attempt to join a predefined IRC server and channel stolen data in order to participate in distributed denial-of-service (DDoS) attack. The DDoS attacks will attempt to make the computer unavailable to its intended users. It is recommended that Backdoor.Win32.Agent.bctb be removed immediately with a good anti-spyware application.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\Userss\userp\ppw\abc.pps
    2 c:\Userss\userp\ppw\ast.bat
    3 c:\Userss\userp\ppw\dre.vbs
    4 c:\Userss\userp\ppw\Msoffice.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...