Home Malware Programs Backdoors Backdoor.Win32.ZZSlash

Backdoor.Win32.ZZSlash

Posted: March 7, 2011

Backdoor.Win32.ZZSlash is a backdoor Trojan that specializes in crippling the firewall, security programs and other security-related aspects of any PC it infects. This may be exploited to allow the non-consensual download of other malware like viruses but is most dangerously used to allow remote attackers to control the computer. This Trojan is capable of eradicating all privacy and control the user has over the infected PC, so it's critical to delete Backdoor.Win32.ZZSlash before the problem worsens to unrecoverable levels.

See Backdoor.Win32.ZZSlash Creaking Your Security Open

A Backdoor.Win32.ZZSlash infection will not show any obvious signs of its presence, although you may notice a new process running in Task Manager or inexplicable RAM allocation. Widely-distributed files in P2P networks and pirating sites are the main means by which Backdoor.Win32.ZZSlash gets around, though some dangerous websites can directly force you to download it.

The Windows registry will be changed so that Backdoor.Win32.ZZSlash can run undetectably whenever Windows boots in a normal mode. Although experts may be able to notice an infection by looking through the registry, it's inadvisable to try to delete Backdoor.Win32.ZZSlash's registry entries by hand; deleting the wrong thing in your Registry can damage Windows instead of the Trojan!

Backdoor.Win32.ZZSlash may alter your firewall settings and other security-based preferences, as well as stopping your anti-virus programs from working. This allows a remote attacker to control your computer for his or her own purposes.

Backdoor.Win32.ZZSlash may also download other malware which can aid in remote attacks or perform completely unrelated but still malicious activities. The damage caused by remote attackers or malware downloads doesn't necessarily correspond to the visibility of the attacks; spyware like keyloggers can steal passwords and cause immense damage while showing little sign of their existence.

Nailing Shut That Back Door

Deleting Backdoor.Win32.ZZSlash and backdoor Trojans like it should be done quickly, before remote attackers or other dropped malware make the process more difficult. Resorting to Safe Mode will usually prevent the Trojan from running and let you access security applications that can scan for and delete Backdoor.Win32.ZZSlash with less trouble on your part.

In some cases, Trojans like Backdoor.Win32.ZZSlash may use rootkit-based functions to hide themselves in memory. To stop the Trojan from running to get rid of it can become difficult, if not impossible through this. Disabling the system restore function on a temporary basis may help sidestep this tricky self-preservation tactic and let you remove Backdoor.Win32.ZZSlash properly.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\Uudbu.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSDTCSHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSDTCS\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSDTCS\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msdtcsHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msdtcs\EnumHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msdtcs\ParametersHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msdtcs\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDTCSHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDTCS\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSDTCS\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msdtcsHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msdtcs\ParametersHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msdtcs\Security
Loading...