Home Malware Programs Backdoors Tixanbot

Tixanbot

Posted: March 28, 2006

Tixanbot is an extremely dangerous backdoor that gives the remote attacker full unauthorized access to a compromised PC. The attacker can manage the entire computer and files, download and install arbitrary softwares, update the backdoor, change Internet Explorer default home page, attack remote hosts and obtain computer information. Tixanbot terminates running essential computer services and security-related processes, closes active malware removers and removes registry entries related with firewalls, antivirus and anti-malware software in order to prevent them from running on Windows startup. The spyware also blocks access to reputable security-related web resources. Tixanbot can spread. It sends messages with certain links to all MSN contacts. Clicking on such a link downloads and installs the backdoor. The spyware automatically runs on every computer startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 svshost.exe
    2 svshost.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunsvshostHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsvshostHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessrStart=4HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessrserviceStart=4
Loading...