Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

BACKDOOR.CYCBOT.G

 

 

Name:

Backdoor.Cycbot.g

Descr. Added:

September 1, 2012

Type:

Backdoor

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When Backdoor.Cycbot.g is executed, it performs the following activities:

It copies itself to the following locations on the system:

%Appdata%\3CC7C\2527E.exe
%Appdata%\3CC7C\CDD4.CC7
%Program Files%\LP\7E93\1.tmp
%Program Files%\LP\7E93\F7B.exe

It creates/modifies the following registry entries:

F7B.exe = "%Program Files%\LP\7E93\F7B.exe"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Shell = "explorer.exe,%Appdata%\3CC7C\2527E.exe"
HKU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4