Home Malware Programs Backdoors Backdoor.Shatekrat

Backdoor.Shatekrat

Posted: June 25, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 9
First Seen: June 25, 2013
OS(es) Affected: Windows

Backdoor.Shatekrat is a backdoor Trojan that opens a back door on the affected computer. When executed, Backdoor.Shatekrat replicates itself to the specific location on the corrupted PC. Backdoor.Shatekrat also creates the potentially malicious files. Backdoor.Shatekrat creates the registry entry so that it can run automatically whenever Windows is started. Backdoor.Shatekrat then opens a back door and allows a remote attacker to gain access and control to the infected computer system. Backdoor.Shatekrat may then download more malicious files on to the targeted computer system, update itself, and steal information from the victimized PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\Microsoft\svchost.exe File name: %UserProfile%\Application Data\Microsoft\svchost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\[THREAT FILE NAME].exe.log File name: %Temp%\[THREAT FILE NAME].exe.log
Mime Type: unknown/log
Group: Malware file
%Temp%\melt.txt File name: %Temp%\melt.txt
Mime Type: unknown/txt
Group: Malware file
%Temp%\svchost.exe.log File name: %Temp%\svchost.exe.log
Mime Type: unknown/log
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"(Default)" = "%UserProfile%\Application Data\Microsoft\svchost.exe"
Loading...