This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
|
Minimum DAT
4397 (2004-10-06) Updated DAT4406 (2004-11-10) |
Minimum Engine
5.1.00 File LengthVaries |
Description Added
2004-10-06 Description Modified2004-11-12 |
There are several variants of this trojan. This text describes one recent variant, which was recently installed via an HTML page that contained the Exploit-IframBO trojan. Navigating to a malicious site hosting this webpage resulted in vulnerable Internet Explorer web browsers executing download code, which downloaded and executed BackDoor-CHN.gen. This variant is detected with the 4397 DAT files (and higher).
When run, the BackDoor trojan copies itself to the WINDOWS and WINDOWS SYSTEM directories and creates 2 registry run keys to load itself at system startup:
The trojan attempts to notify websites of the infected systems IP address:
The trojan also monitors Internet Explorer usage in an attempt to steal account information. It particularly looks for the following website Titles and URLs
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
But in some particular cases, the following steps need to be taken.
Please go to the Microsoft Recovery Console and restore a clean MBR.
On Windows XP:
On Windows Vista and 7: