Home Malware Programs Trojans Backdoor:Win32/Poison.AV

Backdoor:Win32/Poison.AV

Posted: November 17, 2010

Backdoor:Win32/Poison.AV is a malicious backdoor Trojan that allows remote access to a compromised system. Backdoor:Win32/Poison.AV can change Windows Explorer settings to download other malicious files from external servers. Backdoor:Win32/Poison.AV also monitors user activities to obtain valuable personal information. This Trojan poses a dangerous threat to any computer or system and should be terminated immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\system32:msSontheist.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{61669912-4786-3077-067F-E0D1F727C370}]
Loading...