Home Malware Programs Backdoors Backdoor.Win32.Poison.apdm

Backdoor.Win32.Poison.apdm

Posted: December 24, 2009

Backdoor.Win32.Poison.apdm is a malicious backdoor Trojan horse. Once installed, Backdoor.Win32.Poison.apdm is able to run in the background, undetected and hidden from the computer user and most anti-virus or anti-spyware applications. Backdoor.Win32.Poison.apdm is able to open up a conduit to give hackers remote access to the system. Backdoor.Win32.Poison.apdm should be removed immediately once detected using an effective anti-spyware program.

Aliases

Trojan:Win32/Meredrop (Microsoft)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Xenocode\Sandbox\1.0.0.0\2009.08.01T08.17\Virtual\STUBEXE\@SYSTEM@\Server T0TAL4.exe
    2 %AppData%\Xenocode\Sandbox\1.0.0.0\2009.08.01T08.17\Virtual\XRegistry.bin

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\XenocodeHKEY_CURRENT_USER\Software\Xenocode\SandboxCacheHKEY_CURRENT_USER\Software\Xenocode\SandboxCache\38E87097
Loading...