Home Malware Programs Backdoors BKDR_POISON.BLW

BKDR_POISON.BLW

Posted: August 29, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 67
First Seen: August 29, 2012
OS(es) Affected: Windows

BKDR_POISON.BLW is a backdoor Trojan that exploits a Java Runtime Environments (JRE) vulnerability. BKDR_POISON.BLW may be dropped by other PC threats from remote websites. BKDR_POISON.BLW connects to certain websites for sending and receiving information. BKDR_POISON.BLW performs malicious actions on the compromised PC. BKDR_POISON.BLW allows attackers to gain remote access and control over the vulnerable computer system. BKDR_POISON.BLW downloads and executes malicious files. BKDR_POISON.BLW adds the certain registry entries so that it can run automatically every time you start Windows. BKDR_POISON.BLW can also manage devices, processes, services, and installed programs.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



hi.exe File name: hi.exe
Size: 17.08 KB (17086 bytes)
MD5: c85c0441042b8195eff435453188a04b
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 30, 2012
%System%\mspmsnsv.dll File name: %System%\mspmsnsv.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager PendingFileRenameOperations = "%User Temp%\{random file name}.dat"
Loading...