Threat Database Trojans Backdoor.Pestic

Backdoor.Pestic

By GoldSparrow in Trojans

Backdoor.Pestic is a backdoor trojan infection that obtains access to a computer via security programs or network vulnerability in the background. Backdoor.Pestic opens up a backdoor and connects to a distant host. Then Backdoor.Pestic downloads malicious files to mess up your system files. Backdoor.Pestic gathers and sends personal data to a predetermined computer.

File System Details

Backdoor.Pestic may create the following file(s):
# File Name Detections
1. C:\Documents and Settings\\Application Data\Macromedia\swfupdate\swfupdate.dll
2. C:\Documents and Settings\\Application Data\Macromedia\swfupdate\Ui.dtd
3. C:\Documents and Settings\\Application Data\Macromedia\swfupdate\USTemp.dtd
4. C:\Documents and Settings\\Application Data\Macromedia\swfupdate\UTemp.dtd
5. C:\Documents and Settings\\Application Data\Macromedia\swfupdate\S32DATA.dtd
6. C:\Documents and Settings\\Application Data\Macromedia\swfupdate\Local.dtd
7. C:\Documents and Settings\\Application Data\Macromedia\swfupdate\H64DATA.dtd

Registry Details

Backdoor.Pestic may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Shared Access\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\C:\WINDOWS\explorer.exe: "explorer.exe:*:Enabled:Microsoft Windows Explorer"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Shared Access\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\explorer.exe: "explorer.exe:*:Enabled:Microsoft Windows Explorer"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\ShellServiceObjectDelayLoad\"SwUpdate" = "7B 00 30 00 30 00 33 00 35 00 34 00 31 00 41 00 31 00 2D 00 33 00 42 00 43 00 30 00 2D 00 31 00 42 00 31 00 43 00 2D 00 41 00 41 00 46 00 33 00 2D 00 3
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Shared Access\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\C:\WINDOWS\system32\lsass.exe: "C:\WINDOWS\system32\lsass.exe:*:Enabled:LSA Shell"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Shared Access\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\system32\lsass.exe: "C:\WINDOWS\system32\lsass.exe:*:Enabled:LSA Shell"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Shared Access\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\[ORIGINAL FILE NAME].exe: "[ORIGINAL FILE NAME].exe:*:Enabled:Application Layer Gateway Service"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Shared Access\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\[ORIGINAL FILE NAME].exe: "[ORIGINAL FILE NAME].exe:*:Enabled:Application Layer Gateway Service"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{003541A1- 3BC0-1B1C-AAF3-040114001C01}

Trending

Most Viewed

Loading...