Home Malware Programs Backdoors Backdoor.Win32.Small.zf

Backdoor.Win32.Small.zf

Posted: October 21, 2009

Backdoor.Win32.Small.zf is a malicious backdoor trojan running in the background. Backdoor.Win32.Small.zf enables remote access to the corrupted system. Backdoor.Win32.Small.zf may obtain control of the computer and do its chosen form of harm, such as ruining the file allocation table on computer's hard disk. Backdoor.Win32.Small.zf is able to open up a computer to outside attackers.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\arndoe.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DHCPSHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DHCPS\ParametersHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DHCPS\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DHCPSHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DHCPS\ParametersHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DHCPS\Security
Loading...