Threat Database Backdoors Backdoor.win32.scrab.p

Backdoor.win32.scrab.p

By Domesticus in Backdoors

While the Backdoor.win32.scrab.p Trojan is generally considered a backdoor Trojan, this malware infection is closely associated with rogue security programs and similar scareware. Backdoor Trojans, such as the Backdoor.win32.scrab.p Trojan, are designed to create an opening in the computer user's security – a backdoor through which a hacker can enter an infected computer system. Hackers use these backdoors to install other malware on the infected computer. The malware associated with the Backdoor.win32.scrab.p Trojan can vary from case to case, but most Backdoor.win32.scrab.p Trojan infections will often result in variations of the rogue security program scam. ESG security researchers advise scanning your computer system regularly with a real anti-malware program. Most anti-malware applications updated up to 2011 should be able to detect and remove the Backdoor.win32.scrab.p Trojan. It may be necessary to restore your firewalls and router settings, to undo the security holes left behind by the Backdoor.win32.scrab.p Trojan.

Understanding Scareware Associated with the Backdoor.win32.scrab.p Trojan

Scareware is a term used to refer to a kind of malware that is designed to use threatening messages and tactics to scare its victims into paying a certain amount of money. The Backdoor.win32.scrab.p Trojan is closely associated with several scareware scams, especially ransomware and rogue security programs. Ransomware will usually take the form of a fake message from the police, the record companies, or from an authority figure in general. The malware displaying the fake message will also block access to the infected computer until the victim pays some kind of "fine."

Rogue security programs are a collection of malicious scripts and Trojans that hide under the disguise of a legitimate anti-virus or anti-malware program. A rogue security program will spam the PC user displaying fake security alerts, error messages, and fake computer scans to make its victim think that the computer is severely infected. These fake error messages will usually be accompanied by a large number of computer problems, caused by the rogue security program itself. The rogue security program is designed to try to scare its victim into paying for a "full version" of the fake anti-virus in order to remove the nonexistent infections.

While the Backdoor.win32.scrab.p Trojan may be used to spread other kinds of malware such as remote access tools or adware, the scams mentioned above make up the vast majority of the malware associated with Backdoor.win32.scrab.p Trojan infections. ESG team of PC security researchers recommends getting rid of the Backdoor.win32.scrab.p Trojan and its associated malware with a fully-updated anti-malware tool. Malware associated with the Backdoor.win32.scrab.p Trojan will often change your system settings to block legitimate security programs. To bypass Backdoor.win32.scrab.p, it will probably be necessary to start up Windows in Safe Mode.

File System Details

Backdoor.win32.scrab.p may create the following file(s):
# File Name Detections
1. %temp%\.dll
2. C:\Documents and Settings\\application data\.exe

Registry Details

Backdoor.win32.scrab.p may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run shell=
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_CURRENT_USER\Software\Microsoft \Windows\CurrentVersion Explorer/ShellFolders Startup="C:\windows/start menu/programs\startup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\

Trending

Most Viewed

Loading...