|
|
|
VIRUS
NAME : BackDoor-AJZ
Trojan
Characteristics
This is a remote access
trojan. When run, it creates a registry run key to load itself at startup:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run\Explorer=%Trojan Path%
It opens TCP port 2090 to allow
a remote attacker to connect to the infected system and perform various tasks.
Symptoms
Port 2090 being left opened
Method
Of Infection
Remote access trojans
give an attacker a method for connecting to the compromised system and performing
various tasks. This remote access trojan is designed to have several capabilities,
such as:
- Copy, and delete files
and folders
- Create folders
- List running programs
and opened window titles
- Execute commands
- Download files
- Display messages on
the screen of the remote machine
|
|
|