Home Malware Programs Backdoors Backdoor.Win32.Kbot.s

Backdoor.Win32.Kbot.s

Posted: January 11, 2011

Backdoor.Win32.Kbot.s is a backdoor Trojan that operates undetected and opens a conduit for hackers to gain remote access to the targeted system. Backdoor.Win32.Kbot.s contains a hacktool that could be used by attackers to gain access to the system. Backdoor.Win32.Kbot.s can change Windows Explorer settings to download other malicious files from external servers. Backdoor.Win32.Kbot.s also has the ability to monitor user activities to obtain valuable personal information, especially usernames and passwords for online banking. Backdoor.Win32.Kbot.s poses is a threat to computer systems and should be removed when detected.

Aliases

Mal/Dropper-K (Sophos)
TrojanDownloader:Win32/Chksyn.gen!A (Microsoft)
Backdoor.Win32.Kbot.aq (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\mssrv32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msupdate][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msupdate]
Loading...