Home Malware Programs Backdoors Backdoor.Libnut

Backdoor.Libnut

Posted: October 5, 2011

Threat Metric

Threat Level: 6/10
Infected PCs: 5
First Seen: October 5, 2011
OS(es) Affected: Windows

Backdoor.Libnut is a hazardous Trojan infection that opens a back door on the infected computer and then connects to certain IP addresses and ports. Once installed, Backdoor.Libnut adds some malicious system files and modifies the registry. Backdoor.Libnut enables evil attackers to obtain remote access to the corrupted PC and to execute malicious actions. Backdoor.Libnut allows remote attackers to upload, download, and delete system files on the compromised machine. Backdoor.Libnut also allows to collect PC system information and transmit it to remote attackers. Uninstall Backdoor.Libnut as early as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 251.98 KB (251980 bytes)
MD5: 6530718bc4d62c7b4063db9d80f1b337
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 6, 2011
%Temp%\STZC_47D8B6F.TMP File name: %Temp%\STZC_47D8B6F.TMP
File type: Temporary File
Mime Type: unknown/TMP
Group: Malware file
%CommonProgramFiles%\System\STRUNLIB.DLL File name: %CommonProgramFiles%\System\STRUNLIB.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
%CommonProgramFiles%\System\STRUNLIB.DLLbk File name: %CommonProgramFiles%\System\STRUNLIB.DLLbk
Mime Type: unknown/DLLbk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_STORAGEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\"storage" = "storage,"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\storage
Loading...