Home Malware Programs Backdoors Generic BackDoor!csb

Generic BackDoor!csb

Posted: June 29, 2011

Generic Backdoor!csb is a backdoor Trojan that attacks your security and performs spyware functions like keylogging, to steal passwords and other personal information. Recent variants of Generic Backdoor!csb can also be worms that create copies of themselves that spread with the help of networks and removable drives. Both the worm version of Generic Backdoor!csb and its standard Trojan version are extremely dangerous and advanced violations of your PC security; you should remove Generic Backdoor!csb threats from your PC with a sophisticated and fully-updated security program.

Generic Backdoor!csb – a Stealthy Threat with Flexible Propagation Plans

Generic Backdoor!csb was first seen in 2010 and can also be detected by some of the following aliases: W32.IRCBot, Win32/Injector.AZJ, Trojan.Win32.Buzus.dity and Win32.HLLW.SpyNet. There are two major forms of Generic Backdoor!csb – a worm that can copy its files to new locations, and a Trojan that's incapable of propagating in this fashion.

The worm variant of Generic Backdoor!csb may create copies of itself in network-shared locations or removable drives such as CDs or USB drives. Generic Backdoor!csb worms have also been seen exploiting Autorun.inf loopholes that let Generic Backdoor!csb install itself whenever a new computer accesses a device or folder where Generic Backdoor!csb files are stored. You may not see any visible Generic Backdoor!csb files, since Generic Backdoor!csb may give its files the Hidden or System attributes to conceal them.

Both the worm and Trojan form of Generic Backdoor!csb are equipped with backdoor and keylogging functions. Backdoor functionality lets Generic Backdoor!csb create holes in your security by disabling security programs or creating exceptions for itself in them. This is often associated with remote attacks by criminals for DDoS crimes and other illegal activities.

Meanwhile, keylogging allows Generic Backdoor!csb to steal any information that involves keyboard input effortlessly, including credit card numbers, account user names, passwords and other private information. Some keyloggers are also equipped with more sophisticated spying functions, including the ability to take screenshots.

Don't Feed the Generic Backdoor!csb 'Sea Monkey'

Standard versions of Generic Backdoor!csb have also been seen engaging in other harmful behavior:

  • Generic Backdoor!csb can install Mozilla SeaMonkey (a no-charge Internet suite that works on multiple platforms) and then inject Generic Backdoor!csb 's own malicious code into the SeaMonkey process. This lets Generic Backdoor!csb ignore firewalls and other security programs.
  • Alternately, Generic Backdoor!csb may opt to disable your firewall and your anti-virus software to render the potential barrier a moot issue.
  • Generic Backdoor!csb can also install a Remote Administration Tool or RAT that allows remote attackers to gather information about your PC and exert control over it
  • .

  • Finally, Generic Backdoor!csb can steal passwords and contact information from instant messaging programs, web browsers and the Steam gaming application.

Since all forms of Generic Backdoor!csb can launch themselves automatically and may result in even more dangerous remote attacks, Generic Backdoor!csb should be considered an extreme threat. The recommended method of removing Generic Backdoor!csb is to use a fully-updated anti-malware program that can run to delete Generic Backdoor!csb components and any related threats in Safe Mode.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Microsoft\Crypto\RSA\S-1- [Varies]\f9992b1ed3cdc054077ba50d8115ad69_e8d86675-b8d2-4ee6-876c-55cb6f7c0018 [Data file]
    2 %AppData%\SQLite3.dll [Data file]
    3 %Temp%\29514437.tmp [Data file]
    4 %Temp%\UuU.uUu [Data file]
    5 %Temp%\XxX.xXx [Data file]
    6 %Userprofile%\Cookies\[User Name]@server[1].txt [Data file]
    7 %Userprofile%\Local Settings\Temporary Internet Files\Content.IE5\JRPRBYW8\sqlite3[1].dll [Data file]

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3846A813-G1PX-GP34-W10Y-73675R5K48GI}HKEY_USERS\S-1-[Varies]\Software\vima[HKEY_USERS\S-1-[Varies]\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\][HKEY_USERS\S-1-[Varies]\Software\Microsoft\Windows\CurrentVersion\Run\]HKEY..\..\..\..{RegistryKeys}HKCU = "%WinDir%\system32\install\server.exe"HKLM = "%WinDir%\system32\install\server.exe"Policies = "%WinDir%\system32\install\server.exe"StubPath = "%WinDir%\system32\install\server.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\]
Loading...