Home Malware Programs Trojans Backdoor.Win32.Rbot.hyj

Backdoor.Win32.Rbot.hyj

Posted: November 23, 2009

Backdoor.Win32.Rbot.hyj is a malicious Trojan horse that deviously enters a PC or network and attacks the Internet by producing outbound traffic. Backdoor.Win32.Rbot.hyj creates a fake startup registry entry for another trojans to gain illegal access to the infected computer. Backdoor.Win32.Rbot.hyj will then attempt to self-propagate by exploiting local network shares. Backdoor.Win32.Rbot.hyj will also attempt to join a predefined IRC server and channel in order to participate in DDoS attacks. Backdoor.Win32.Rbot.hyj shows characteristics of a highly severe security risk and should be ruthlessly executed.

Aliases

Mal/Generic-E (Sophos)
TrojanDropper:Win32/Agent.BAD (Microsoft)
Win32/IRCBot.worm.variant (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\addons.dat
    2 %Temp%\a.exe
    3 %Temp%\ff.Exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost]
Loading...