Home Malware Programs Spyware Malware.Slackor

Malware.Slackor

Posted: March 17, 2011

Malware.Slackor is a malicious backdoor trojan that runs in the background and enables remote access to the targeted computer system. Malware.Slackor will download files to the com,puter without a user's consent, which will resulti in security risk. Malware.Slackor installs itself to the computer and searches for a local network for vulnerable nachines with shared resources. Malware.Slackor just simulates computer scans and shows many fraudulent warning messages that usually declare your computer is in serious security danger

.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\27371_100001367119654_1746_q.jpg
    2 %System%\fservice.exe
    3 %System%\reginv.dll
    4 %System%\winkey.dll
    5 %Temp%\sys93589.bat
    6 %Windir%\ktd32.atm
    7 %Windir%\services.exe
    8 %Windir%\system\sservice.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT Script HostHKEY_CURRENT_USER\Software\Microsoft\Windows NT Script Host\Microsoft DxDiagHKEY_CURRENT_USER\Software\Microsoft\Windows NT Script Host\Microsoft DxDiag\WinSettingsHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5Y99AE78-58TT-11dW-BE53-Y67078979Y}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ExplorerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Loading...