BACKDOOR.GBOT.HPL
Name:
Backdoor.Gbot.hpl
Added:
August 2, 2011
Type:
Backdoor
Risk:
Low
Payload:
N/A
At risk systems:
Windows 95/98/ME/XP/NT/2003
Description:
When Backdoor.Gbot.hpl is executed, it performs the following activities:After execution, it drops the following files:%Temp%\csrss.exe%Temp%\{Random name}.tmp%AppData%\{Random name}.%AppData%\dwm.exe%AppData%\Microsoft\conhost.exeIt creates/modifies the following registry entries:conhost = "%AppData%\Microsoft\conhost.exe"HKLM\Software\Microsoft\Windows\CurrentVersion\RunShell = "explorer.exe,%AppData%\dwm.exe"HKU\Software\Microsoft\Windows NT\CurrentVersion\WinlogonLoad = "%Temp%\csrss.exe"HKU\Software\Microsoft\Windows NT\CurrentVersion\WindowsProxyEnable = "1"HKU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Malware problems?We can help.
Evaluate Thirtyseven4 Antivirus Now
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4