Threat Database Backdoors Backdoor.Moudoor

Backdoor.Moudoor

By Domesticus in Backdoors

Threat Scorecard

Ranking: 2,236
Threat Level: 20 % (Normal)
Infected Computers: 20,956
First Seen: October 9, 2012
Last Seen: September 20, 2023
OS(es) Affected: Windows

Backdoor.Moudoor is a Trojan that opens a back door on the compromised PC. Once executed, Backdoor.Moudoor may create several potentially malicious files. Backdoor.Moudoor may also create several registry entries so that it can run automatically every time you start Windows. Backdoor.Moudoor connects to one of the several locations. Backdoor.Moudoor allows attackers to gain remote access and control over the

affected computer system. Backdoor.Moudoor may collect the victim's personal information and send it to a remote server.

File System Details

Backdoor.Moudoor may create the following file(s):
# File Name Detections
1. %ProgramFiles%\Symantec\LiveUpdate\VPTray.exe
2. %Temp%\svohost.exe
3. %Temp%\VPTray.exe
4. %Windir%\up.bak
5. %System%\KB1035627.dat

Registry Details

Backdoor.Moudoor may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\"SymantecLiveUpdate" = "%PROGRAMFILES%\Symantec\LiveUpdate\VPTray.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\"SymantecLiveUpdate" = "%PROGRAMFILES%\Symantec\LiveUpdate\VPTray.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Microsoft Update" = "%TEMP%\svohost.exe"

URLs

Backdoor.Moudoor may call the following URLs:

allactualstories.com

Trending

Most Viewed

Loading...