Threat Database Backdoors Backdoor.Odivy

Backdoor.Odivy

By SpideyMan in Backdoors

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 11
First Seen: August 26, 2011
Last Seen: October 9, 2022
OS(es) Affected: Windows

Backdoor.Odivy is a backdoor Trojan that will open a back door on the corrupted PC system. Backdoor.Odivy usually propagates via an email attached compressed 7z or RAR SFX executable file. Backdoor.Odivy will inject a malicious code into a user's default Internet browser that makes it vulnerable to remote administration tool. Backdoor.Odivy helps attackers to access the targeted computer system and trace and gather your browsing habits and confidential information. Backdoor.Odivy is able to modify Windows registry and change default web browser settings that will lead to annoying browser redirections. You need to delete Backdoor.Odivy from the affected PC system as soon as possible.

File System Details

Backdoor.Odivy may create the following file(s):
# File Name Detections
1. %System%\winsys.exe
2. %System%\jql.sys
3. %Temp%\xxxx.exe
4. %CommonProgramFiles%\ODBC\ODUBC.DLL
5. %Temp%\happiness.txt

Registry Details

Backdoor.Odivy may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{34DED0E2-8B26-67FC-4718-B8C8A145ADB6}\"StubPath" = "%System%\winsys.exe"

Trending

Most Viewed

Loading...