Home Malware Programs Backdoors Backdoor:Win32/Beastdoor.L

Backdoor:Win32/Beastdoor.L

Posted: December 7, 2010

Backdoor:Win32/Beastdoor.L is a backdoor Trojan that operates undetected and opens a conduit for hackers to gain remote access to the targeted system. Backdoor:Win32/Beastdoor.L contains a hacktool that could be used by attackers to gain access to the system. Backdoor:Win32/Beastdoor.L can change Windows Explorer settings to download other malicious files from external servers. Backdoor:Win32/Beastdoor.L also has the ability to monitor user activities to obtain valuable personal information, especially usernames and passwords for online banking. Backdoor:Win32/Beastdoor.L poses is a threat to computer systems and should be removed when detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\msntjq.com
    2 %Windir%\msagent\mssnqi.com
    3 %Windir%\svchost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RunHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E3CC-EA32-40BB12E6015D}HKEY..\..\..\..{RegistryKeys}COM Service = "%Windir%\msagent\mssnqi.com"StubPath = "%System%\msntjq.com"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Loading...