Backdoor.Rumsoot.A
Backdoor.Rumsoot.A Description
Backdoor.Rumsoot.A is a Trojan virus capable of infiltrating a computer without user awareness or consent, and once active, Backdoor.Rumsoot.A downloads additional forms of malware onto the already infected machine. Backdoor.Rumsoot.A may also create backdoor ports, allowing an unauthorized user to gain remote access to the system, leading to theft of personal and financial information.
Type: Trojans
How Can You Detect Backdoor.Rumsoot.A?
Backdoor.Rumsoot.A Technical Report
As new Backdoor.Rumsoot.A details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following Backdoor.Rumsoot.A files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| winself.exe | 28672 | e60f0c0fb04488e98744bbc95970fdcb |
| winself.exe | 29696 | 955215b1005935dd1e74f3f6044777e5 |
| gavurjjf.exe | 25088 | 0e54a5b9a3d6a994ee7b23904e062f26 |
| thnd.exe | 29696 | bd37ea46affed137e3c1e7b7df9d6bc6 |
Backdoor.Rumsoot.A has typically the following processes in memory:
- winself.exe
- gavurjjf.exe
- thnd.exe
Backdoor.Rumsoot.A creates the following registry entries:
- HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMsSecurity Updated
- HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMSSysInterv
- HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMsSecurity
Important Article Disclaimer
This entry was posted on 09/14/09 and is filed under Trojans.
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

English 
Deutsch
Español
Français
Portuguese
Backdoor.Rumsoot.A 











