Threat Database Backdoors Win32/Cycbot.G

Win32/Cycbot.G

By ESGI Advisor in Backdoors

Win32/Cycbot.G is a computer virus that installs a fake anti-spyware programs such as ThinkPoint and Windows Simple Protector on the compromised computer system. Win32/Cycbot.G can also deliver fake Microsoft Security Essentials alerts. Win32/Cycbot.G can disable genuine security applications on the corrupted PC. Payload of Win32/Cycbot.G is not restricted to the fake anti-spyware promotion only. Uninstall Win32/Cycbot.G as soon as possible.

File System Details

Win32/Cycbot.G may create the following file(s):
# File Name Detections
1. %AllUsersProfile%\Application Data\.dll
2. %AllUsersProfile%\Application Data\.exe
3. %AllUsersProfile%\Application Data\~r
4. %AllUsersProfile%\Application Data\

Registry Details

Win32/Cycbot.G may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""

Trending

Most Viewed

Loading...