Home Malware Programs Trojans Backdoor:Win32/Idicaf.gen!A

Backdoor:Win32/Idicaf.gen!A

Posted: November 16, 2009

Backdoor:Win32/Idicaf.gen!A is a malicious backdoor Trojan that runs in the background and enables hackers with remote access to a corrupted computer system. Backdoor:Win32/Idicaf.gen!A has been found to produce outbound traffic and create a startup registry entry that loads once Windows is booted. By using Backdoor:Win32/Idicaf.gen!A, hackers can remotely control the machine without a user's knowledge. Have Backdoor:Win32/Idicaf.gen!A removed from the system immediately to prevent further damages.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\xinstall.log

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IRMON\0000\Control][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IRMON\0000][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IRMON][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Irmon\Enum][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Irmon\Parameters][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Irmon\Security][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Irmon][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IRMON\0000\Control][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IRMON\0000][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IRMON][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Irmon\Enum][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Irmon\Security][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Irmon]
Loading...