Threat Database Backdoors BKDR_INJECT.EVL

BKDR_INJECT.EVL

By LoneStar in Backdoors

BKDR_INJECT.EVL is a backdoor Trojan that propagates via spam email attachments sent by cybercriminals or other malware infections. The fraudulent email message attempts to fool victims into opening and running a malevolent attachment file. BKDR_INJECT.EVL connects to a specific URL to send and obtain information. BKDR_INJECT.EVL injects its DLL component to the process named svchost.exe. BKDR_INJECT.EVL adds the 'allthesam' mutex to make sure that only one of its copies is launched at any time. BKDR_INJECT.EVL registers itself as a system service by creating the specific registry entries so that it can start automatically whenever you boot up your computer. Eliminate BKDR_INJECT.EVL to keep your PC safe.

File System Details

BKDR_INJECT.EVL may create the following file(s):
# File Name Detections
1. %System%\svc32ex.dll - also detected as BKDR_INJECT.EVL

Registry Details

BKDR_INJECT.EVL may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\6to4
Services\6to4\Parameters ServiceDll = %System%\svc32ex.dll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

Trending

Most Viewed

Loading...