Home Malware Programs Backdoors Backdoor.Misdat

Backdoor.Misdat

Posted: October 26, 2011

Threat Metric

Threat Level: 6/10
Infected PCs: 82
First Seen: October 26, 2011
OS(es) Affected: Windows

Backdoor.Misdat is a backdoor Trojan that opens a backdoor on infected computers. When Backdoor.Misdat is executed, it starts the Windows Help application. Backdoor.Misdat displays a breaking news report. Then, Backdoor.Misdat attempts to connect to a certain website. Backdoor.Misdat collects personal information on the victim's computer and transmits it to remote attackers. Backdoor.Misdat sends unique ID to the remote host and receives a list of commands to further harm the computer. Backdoor.Misdat adds system files and modifies the registry.

Aliases

BKDR_EXDEPH.A

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Gadhafi info.zip File name: Gadhafi info.zip
Size: 43 KB (43008 bytes)
MD5: 70af59ca74693efcdba8f9b845c5bfbf
Detection count: 66
Mime Type: unknown/zip
Group: Malware file
Last Updated: October 27, 2011
Gadhafi info.zip File name: Gadhafi info.zip
Size: 43 KB (43008 bytes)
MD5: cb7b5173126112efead2700e2bac41d4
Detection count: 65
Mime Type: unknown/zip
Group: Malware file
Last Updated: October 27, 2011
Gadhafi info.zip File name: Gadhafi info.zip
Size: 24.12 KB (24120 bytes)
MD5: 1957fb657ff396029b326d788a3411bb
Detection count: 64
Mime Type: unknown/zip
Group: Malware file
Last Updated: October 27, 2011
C:\A.VBS File name: C:\A.VBS
Mime Type: unknown/VBS
Group: Malware file
C:\xml.exe.exe File name: C:\xml.exe.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Common Files\e6d13d3a8d\msdtc.exe File name: C:\Program Files\Common Files\e6d13d3a8d\msdtc.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Backtsaleht\"StubPath" = "C:\Program Files\Common Files\e6d13d3a8d\msdtc.exe"

Additional Information

The following URL's were detected:
msevpn.3322.org
Loading...