Threat Database Backdoors Backdoor.CyberSpy.C

Backdoor.CyberSpy.C

By GoldSparrow in Backdoors

Backdoor.CyberSpy.C is a backdoor Trojan that runs in the background and allows attacker to gain remote access and control over a targeted computer. Backdoor.CyberSpy.C may access a compromised machine without a PC user's permission and knowledge. Backdoor.CyberSpy.C can steal passwords, log keystrokes, create screenshots, and control an affected computer system. Backdoor.CyberSpy.C can compromise a computer system's integrity by making changes to a system, allowing attackers to use it for malicious actions unknown to the victim.

File System Details

Backdoor.CyberSpy.C may create the following file(s):
# File Name Detections
1. %System%\cbutton.ocx
2. r3god.dll

Registry Details

Backdoor.CyberSpy.C may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\Implemented Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\ToolboxBitmap32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{99A011A2-D25B-4491-AD5A-C4DAC32EE504}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{99A011A2-D25B-4491-AD5A-C4DAC32EE504}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{E971125F-F7B0-4245-B481-EB662223AAD3}
HKEY_LOCAL_MACHINE\Software\Classes\CButton.Button\Clsid
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\ToolboxBitmap32] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\VERSION] (Default) = "5.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}] (Default) = "CButton.Button"
(Default) = "%System%\CButton.ocx" ThreadingModel = "Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{99A011A2-D25B-4491-AD5A-C4DAC32EE504}\ProxyStubClsid32] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{99A011A2-D25B-4491-AD5A-C4DAC32EE504}] (Default) = "Button"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E971125F-F7B0-4245-B481-EB662223AAD3}\ProxyStubClsid32] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0\HELPDIR] (Default) = "%Windir%\system32"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0] (Default) = "CButton Control"
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\Implemented Categories
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\Control
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\Implemented
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\MiscStatus\1
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\MiscStatus
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{99A011A2-D25B-4491-AD5A-C4DAC32EE504}
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{E971125F-F7B0-4245-B481-EB662223AAD3}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\CButton.Button
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0\HELPDIR
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}
"{A7C75093-2765-11D3-A0E4-FAFD20CEB591}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\MiscStatus\1] (Default) = "135569"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\MiscStatus] (Default) = "0"
"{A7C75093-2765-11D3-A0E4-FAFD20CEB591}" Version = "5.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E971125F-F7B0-4245-B481-EB662223AAD3}\TypeLib] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{99A011A2-D25B-4491-AD5A-C4DAC32EE504}\ProxyStubClsid] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0\0\win32] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E971125F-F7B0-4245-B481-EB662223AAD3}\ProxyStubClsid] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CButton.Button] (Default) = "CButton.Button"
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Windows\AppIinit_DLLs\ AppInit_DLLs
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\Implemented Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\VERSION
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{99A011A2-D25B-4491-AD5A-C4DAC32EE504}\TypeLib
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{E971125F-F7B0-4245-B481-EB662223AAD3}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\Software\Classes\Interface\{E971125F-F7B0-4245-B481-EB662223AAD3}\ProxyStubClsid
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0\FLAGS
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0\0\win32
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\TypeLib] (Default) =
"%System%\CButton.ocx, 30000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\ProgID] (Default) = "CButton.Button"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{99A011A2-D25B-4491-AD5A-C4DAC32EE504}\TypeLib] (Default) =
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}\Control] (Default) = ""
"{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E971125F-F7B0-4245-B481-EB662223AAD3}] (Default) = "Button"
"{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A7C75093-2765-11D3-A0E4-FAFD20CEB591}\5.0\FLAGS] (Default) = "2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CButton.Button\Clsid] (Default) = "{A7C7509F-2765-11D3-A0E4-FAFD20CEB591}"

Trending

Most Viewed

Loading...