Threat Database Backdoors Backdoor.Salgorea

Backdoor.Salgorea

By ZulaZuza in Backdoors

Backdoor.Salgorea is a backdoor Trojan that opens a back door on the corrupted PC. Backdoor.Salgorea may propagate through spam emails carrying a harmful .hta file. When run, Backdoor.Salgorea replicates itself as the malevolent files on the infected computer system. Backdoor.Salgorea creates a partially modified copy of itself to the temporary folder and runs this copy with parameter '--help'. Backdoor.Salgorea also creates the clean file and executes it. Backdoor.Salgorea then creates the schedule task files in order to run the file 'sidebar.exe' daily. Backdoor.Salgorea creates the registry entry so that it can load automatically whenever you boot up Windows. Backdoor.Salgorea also creates other registry entries.

SpyHunter Detects & Remove Backdoor.Salgorea

File System Details

Backdoor.Salgorea may create the following file(s):
# File Name MD5 Detections
1. %Temp%\KeePass.exe
2. %Temp%\[RANDOM FILE NAME].exe
3. %UserProfile%\Application Data\Microsoft\Windows Sidebar\sidebar.exe
4. %Windir%\Tasks\Sidebar_[CURRENT USER].job
5. %Windir%\Tasks\Sidebar.job
6. %UserProfile%\Application Data\Microsoft\Windows\AeroGlass.theme
7. file.exe d33a9365a7e71f728b993a4a3ae58335 0
8. file.exe a4ae6e1cca7e1411b2dc9bf680e2b1b1 0

Registry Details

Backdoor.Salgorea may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Keyboard\"es-ec" = "[ENCODED DATA]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBar\OemCustomTheme\"(Default)" = "%UserProfile%\Application Data\Microsoft\Windows\AeroGlass.theme"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Keyboard\"es-ec" = "[ENCODED DATA]"
HKEY_CURRENT_USER\Software\Microsoft\SideShow\Gadgets\"Language" = "[TIME OF INFECTION]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Sidebar" = "%Temp%\[RANDOM FILE NAME].exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\UC\"SP" = "[TIME OF INFECTION]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\SideBar\OemCustomTheme\"(Default)" = "%UserProfile%\Application Data\Microsoft\Windows\AeroGlass.theme"

Trending

Most Viewed

Loading...