Threat Database Backdoors BKDR_SIMBOT.EVL

BKDR_SIMBOT.EVL

By Sumo3000 in Backdoors

BKDR_SIMBOT.EVL is a backdoor Trojan that is spread via an infected MS PowerPoint document, which is delivered via an infected .PPT file, found as BKDR_SIMBOT.EVL, attached to particular email messages. The malicious .PPT file drops another malicious file named 'Winword.tmp'. 'Winword.tmp' encompasses an inserted Flash file, which exploits a Flash Player vulnerability known as CVE-2011-0611 to download BKDR_SIMBOT.EVL onto the victim's PC. BKDR_SIMBOT.EVL is spread by TROJ_PPDROP.EVL. BKDR_SIMBOT.EVL executes instructions from remote cybercriminals, taking over the corrupted machine. BKDR_SIMBOT.EVL connects to a particular URL to transmit and obtain information. BKDR_SIMBOT.EVL downloads the copies of itself by generating a specific file onto the affected computer. BKDR_SIMBOT.EVL inserts the codes into the processes such as svchost.exe and services.exe. BKDR_SIMBOT.EVL generates the certain registry key so that it can load automatically whenever you boot up Windows. BKDR_SIMBOT.EVL runs the certain instructions from remote cybercriminals.

SpyHunter Detects & Remove BKDR_SIMBOT.EVL

File System Details

BKDR_SIMBOT.EVL may create the following file(s):
# File Name MD5 Detections
1. %UserProfile%\Local Settings\{random filename}.exe
2. hkmsvc.exe 996376a04c664c6e762f78e98b505b92 0

Registry Details

BKDR_SIMBOT.EVL may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run {random filename} = "%User Profile%\local settings\{random file name}.exe"

Trending

Most Viewed

Loading...