Home Malware Programs Backdoors Backdoor.Sheedash!gen1

Backdoor.Sheedash!gen1

Posted: August 5, 2011

Backdoor.Sheedash!gen1 is a behavior-based and PC security brand-specific label that's used to detect infections from the Sheedash family of backdoor Trojans. SpywareRemove.com PC threat analysts have linked Backdoor.Sheedash!gen1 infections to spyware and security vulnerabilities that could be used to control your PC; however, Backdoor.Sheedash!gen1 Trojans are unlikely to show any visible symptoms and may be undetectable without appropriate security program. It's strongly suggested that you react to any possible Backdoor.Sheedash!gen1 infection with the use of fully-updated anti-malware programs, since Backdoor.Sheedash!gen1 infections are recently-emerged PC threats.

How to Tell if Backdoor.Sheedash!gen1 is Lurking Behind the Scenes?

Although variants of backdoor Trojans from the Sheedash family have been reported for quite some time, Backdoor.Sheedash!gen1 is a new variation that wasn't seen until late July of 2011. Backdoor.Sheedash!gen1 infections are detected heuristically, or by behaviors that they show that are identical to characteristics of other Sheedash Trojan attacks. Backdoor.Sheedash!gen1 infections may be able to avoid detection by out-of-date anti-malware products, and you should always keep your anti-malware scanners updated for recent threats before scanning your PC for Backdoor.Sheedash!gen1 or other infections.
 
SpywareRemove.com threat research team has seen some Backdoor.Sheedash!gen1 variants creating separate memory processes which may be visible in Task Manager, a default Windows program that can be accessed with Ctrl+Alt+Del. However, some variations of Backdoor.Sheedash!gen1 may use rootkit-based techniques to infect native memory processes, so you shouldn't rely on this detection method as a foolproof strategy.
 
Serious Backdoor.Sheedash!gen1-related problems can be detected by looking for open ports, altered network or security settings, program exceptions added to your firewall or other changes to your computer's settings that you didn't authorize. These changes are a primary symptom of backdoor activity that allows remote attackers to control your PC with the assistance of Backdoor.Sheedash!gen1. Remote attacks are responsible for DDoS attacks, identity theft and other serious crimes and may even destroy your computer.
 
You may also see unfamiliar programs, files or memory processes that are installed by Backdoor.Sheedash!gen1 and remain active without your permission. SpywareRemove.com malware analysts have seen Backdoor.Sheedash!gen1 and other members of the Sheedash family installing keyloggers that record keyboard input to steal private information and Backdoor.Sheedash!gen1 may be capable of installing other types of spyware.

Saving Your Computer's Security from Backdoor.Sheedash!gen1

Since the signs of a Backdoor.Sheedash!gen1 attack are minimal, using up-to-date security application is the easiest way to detect a possible Backdoor.Sheedash!gen1 infection. Because Backdoor.Sheedash!gen1 is a brand-specific detection label, you may also see Backdoor.Sheedash!gen1 infections identified by other names, such as Backdoor.Sheedash, Backdoor.Sheedash!inf, Trojan.Win32.Parchood, Patched-SFCFile or Trojan.Obfuscated.
 
Disabling Backdoor.Sheedash!gen1 before you use any threat-removal strategies may be the only way to get Backdoor.Sheedash!gen1 off of your PC for good. Fortunately, some Backdoor.Sheedash!gen1 infections have shown an inability to cope with Safe Mode, which can disable the startup routines of less-advanced malicious programs. In cases where a Backdoor.Sheedash!gen1 variant poses more trouble, you may need to repair the Windows Registry or reboot from an external device. Unless you have no access whatsoever to anti-malware programs, deleting Backdoor.Sheedash!gen1 manually is not recommended.

Aliases

BackdoorSheedashgen1

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Start Menu\Backdoor.Sheedash!gen1\Backdoor.Sheedash!gen1.lnk File name: %UserProfile%\Start Menu\Backdoor.Sheedash!gen1\Backdoor.Sheedash!gen1.lnk
Mime Type: unknown/lnk
%UserProfile%\Desktop\Backdoor.Sheedash!gen1.lnk File name: %UserProfile%\Desktop\Backdoor.Sheedash!gen1.lnk
File type: Shortcut
Mime Type: unknown/lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Backdoor.Sheedash!gen1.lnk File name: %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Backdoor.Sheedash!gen1.lnk
File type: Shortcut
Mime Type: unknown/lnk
%UserProfile%\Start Menu\Backdoor.Sheedash!gen1\Registration.lnk File name: %UserProfile%\Start Menu\Backdoor.Sheedash!gen1\Registration.lnk
File type: Shortcut
Mime Type: unknown/lnk
%UserProfile%\Start Menu\Backdoor.Sheedash!gen1\Help.lnk File name: %UserProfile%\Start Menu\Backdoor.Sheedash!gen1\Help.lnk
File type: Shortcut
Mime Type: unknown/lnk
%Program Files%\Backdoor.Sheedash!gen1\Backdoor.Sheedash!gen1.exe File name: %Program Files%\Backdoor.Sheedash!gen1\Backdoor.Sheedash!gen1.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USER\Software\13376694984709702142491016734454 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "13376694984709702142491016734454"
Loading...