Threat Database Backdoors Backdoor.Korplug

Backdoor.Korplug

By ZulaZuza in Backdoors

Backdoor.Korplug is a backdoor Trojan that opens a back door and may steal information from the compromised PC. When run, Backdoor.Korplug may create several potentially infectious files. Backdoor.Korplug may also create several registry subkeys. Backdoor.Korplug can execute many damaging actions that involve recording keystrokes, opening a remote command shell, taking screenshots and stealing information about the affected PC and its network. Backdoor.Korplug then transfers the stolen information to remote attackers.

SpyHunter Detects & Remove Backdoor.Korplug

File System Details

Backdoor.Korplug may create the following file(s):
# File Name MD5 Detections
1. %UserProfile%\SxS\rc.exe
2. %UserProfile%\SxS\rcdll.dll
3. %UserProfile%\SxS\rc.hlp
4. %UserProfile%\SxS\bug.log
5. 1889.exe 2263ad19cd270571617b5677d3e5652a 0
6. file.exe 9641752497aa67d3912a5928ccf051df 0
7. file.dll 60da52a3709057b677d02cbe80cb0c87 0
8. file.dll 2fbb87311dbc96508b1c471d9abab041 0

Registry Details

Backdoor.Korplug may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SXS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FAST
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SxS

Related Posts

Trending

Most Viewed

Loading...