Home Malware Programs Backdoors Backdoor.Nineblog

Backdoor.Nineblog

Posted: August 7, 2013

Threat Metric

Ranking: 7,571
Threat Level: 2/10
Infected PCs: 11,547
First Seen: August 7, 2013
Last Seen: September 30, 2023
OS(es) Affected: Windows

Backdoor.Nineblog is a backdoor Trojan that opens a back door on the infected computer. When Backdoor.Nineblog is executed, it creates the potentially malicious files. Backdoor.Nineblog creates the registry entry so that it can execute whenever Windows is started. Backdoor.Nineblog contacts the certain remote location. Backdoor.Nineblog sends the certain information including the Host name and the list of running processes to the remote location. Backdoor.Nineblog then opens a back door and may download and run additional Visual Basic scripts on the affected computer.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\RECYCLER\desktop.ini File name: %UserProfile%\Application Data\RECYCLER\desktop.ini
Mime Type: unknown/ini
Group: Malware file
%UserProfile%\Application Data\Microsoft\Windows\Microsoft-Experance-Improve.vbe File name: %UserProfile%\Application Data\Microsoft\Windows\Microsoft-Experance-Improve.vbe
Mime Type: unknown/vbe
Group: Malware file
%UserProfile%\Application Data\RECYCLER\Microsoft-Windows-DiskCleaner.vbe File name: %UserProfile%\Application Data\RECYCLER\Microsoft-Windows-DiskCleaner.vbe
Mime Type: unknown/vbe
Group: Malware file
%Windir%\Tasks\Microsoft-Experance-Improve.job File name: %Windir%\Tasks\Microsoft-Experance-Improve.job
Mime Type: unknown/job
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft-Windows-DiskCleaner\"wscript.exe" = "%DriveLetter%\Documents and Settings\Administrator\Application Data\RECYCLER\Microsoft-Windows-DiskCleaner.vbe"

Additional Information

The following URL's were detected:
fbmedia-lys.com
Loading...