Home Malware Programs Backdoors Backdoor.Moudoor

Backdoor.Moudoor

Posted: October 9, 2012

Threat Metric

Ranking: 2,232
Threat Level: 2/10
Infected PCs: 49,247
First Seen: October 9, 2012
Last Seen: October 17, 2023
OS(es) Affected: Windows

Backdoor.Moudoor is a Trojan that opens a back door on the compromised PC. Once executed, Backdoor.Moudoor may create several potentially malicious files. Backdoor.Moudoor may also create several registry entries so that it can run automatically every time you start Windows. Backdoor.Moudoor connects to one of the several locations. Backdoor.Moudoor allows attackers to gain remote access and control over the affected computer system. Backdoor.Moudoor may collect the victim's personal information and send it to a remote server.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramFiles%\Symantec\LiveUpdate\VPTray.exe File name: %ProgramFiles%\Symantec\LiveUpdate\VPTray.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%System%\KB1035627.dat File name: %System%\KB1035627.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%Temp%\VPTray.exe File name: %Temp%\VPTray.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\svohost.exe File name: %Temp%\svohost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Windir%\up.bak File name: %Windir%\up.bak
Mime Type: unknown/bak
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft Update" = "%TEMP%\svohost.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\"SymantecLiveUpdate" = "%PROGRAMFILES%\Symantec\LiveUpdate\VPTray.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\"SymantecLiveUpdate" = "%PROGRAMFILES%\Symantec\LiveUpdate\VPTray.exe"

Additional Information

The following URL's were detected:
allactualstories.com
Loading...