Home Malware Programs Backdoors Backdoor.IRCBot!sd6

Backdoor.IRCBot!sd6

Posted: August 31, 2011

Backdoor.IRCBot!sd6 is a backdoor Trojan that is usually downloads and installs stealthily onto a compromised PC system. Backdoor.IRCBot!sd6 may disguise itself as a low level system process. Once installed on a targeted computer system, Backdoor.IRCBot!sd6 is able to record and transmit its victim's personal information to a remote attacker. Backdoor.IRCBot!sd6 will also download infected files to an affected computer without a user's consent, which will lead to a security risk. Delete Backdoor.IRCBot!sd6 immediately upon detection to keep your PC safe.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%System%\csrsc.exe File name: %System%\csrsc.exe
File type: Executable File
Mime Type: unknown/exe
%System%\system.exe File name: %System%\system.exe
File type: Executable File
Mime Type: unknown/exe
%System%\1415430 File name: %System%\1415430
%System%\3260653 File name: %System%\3260653
%System%\6258612 File name: %System%\6258612

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSpoolSvcHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSpoolSvc\SecurityHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinSpoolSvc\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINSPOOLSVCHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINSPOOLSVC\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINSPOOLSVC\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSpoolSvcHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSpoolSvc\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSpoolSvc\EnumHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINSPOOLSVCHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINSPOOLSVC\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINSPOOLSVC\0000\Control
Loading...