Threat Database Trojans Backdoor.Lokidok

Backdoor.Lokidok

By GoldSparrow in Trojans

Threat Scorecard

Ranking: 10,243
Threat Level: 10 % (Normal)
Infected Computers: 579
First Seen: April 3, 2014
Last Seen: September 10, 2023
OS(es) Affected: Windows

Backdoor.Lokidok is a Trojan that may open a back door on the corrupted PC. Once executed, Backdoor.Lokidok creates the potentially infected files. Backdoor.Lokidok modifies the Windows Registry. Backdoor.Lokidok may then execute the potentially harmful activities such as control the network for specially crafted ICMP packets, decrypt data from ICMP packets and use it as a parameter to run %System%\cmd.exe and encrypt data and transmit it to the IP address that sent the ICMP packets.

File System Details

Backdoor.Lokidok may create the following file(s):
# File Name Detections
1. %System%\scardsrv.exe
2. %System%\cvpnd.exe

Registry Details

Backdoor.Lokidok may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc\Parameters\"ServiceDll" = "[THREAT FILE PATH]"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\irmon\Parameters\"ServiceDll" = "[THREAT FILE PATH]"

URLs

Backdoor.Lokidok may call the following URLs:

quickusermanuals.com

Trending

Most Viewed

Loading...