virus scan software   contact virus scan software
virus scan software   online software store
virus scan software anti virus software virus scan software mission   new anti virus scan software
User solutions
scan for viruses
virus removal
virus protection
secure browsing
block hackers
data protection
filter email
kill spam
Corporate solutions
virus protection
mailserver
Firewall software
Black ice
Zone alarm pro
Featured product
trend micro pc-cillin
 


VIRUS NAME: BackDoor-ABH



Trojan Characteristics

This Remote Access Trojan masquerades as a downloader for an email client application. When executed on the victim machine, the Trojan attempts to connect to an FTP server. The Trojan contains the string:

'Would you like to download Bmail.. Bmail is a talking Email software that works with POP and other email accounts. Its works with Yahoo also. More will be added soon..'

In addition to opening this FTP connection, the worm opens an additional port on the victim machine, enabling remote access to the machine.
The Trojan sets the following Registry key in an attempt to run itself at system startup:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\_
    Run "SetFTPBack" = C:\WINDOWS\SYSTEM\createsw.exe

However, in testing the Trojan did not successfully copy itself to CREATESW.EXE in the System directory.



Symptoms

Existence of the Registry hook detailed above
Port 5135 open on victim machine



Method Of Infection

The Trojan is designed to install itself on the victim machine upon execution.

 

 

 
Latest viruses
MyLife.e@MM
Goround.worm
Gluas.a
Linux/Alfa
QDel234
BackDoor-OG
Best sellers
Kaspersky PRO
Panda Platinum
Tiny firewall
Volume licensing

McAfee, Inc

Online services
Mcafee removal
 
   

[ virus-scan-software.com ] - [ products ] - [ security ] - [ services ] - [ support ] - [ what's new ] - [ contact ]

website design by Siteowners