BACKDOOR.CYCBOT.G
Name:
Backdoor.Cycbot.g
Descr. Added:
September 1, 2012
Type:
Backdoor
Risk:
Low
Payload:
N/A
At risk systems:
Windows 95/98/ME/XP/NT/2003
Malware problems? We can help. Free Removal Tools.
Description:
When Backdoor.Cycbot.g is executed, it performs the following activities:It copies itself to the following locations on the system:%Appdata%\3CC7C\2527E.exe%Appdata%\3CC7C\CDD4.CC7%Program Files%\LP\7E93\1.tmp%Program Files%\LP\7E93\F7B.exeIt creates/modifies the following registry entries:F7B.exe = "%Program Files%\LP\7E93\F7B.exe"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunShell = "explorer.exe,%Appdata%\3CC7C\2527E.exe"HKU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4