BackDoor-DNW trojan provides remote access capabilities to an attacker by opening a backdoor on the compromised machine. The trojan is dropped by Exploit-TaroDrop.g, which exploits a vulnerability in JustSystem Ichitaro.
|
Minimum DAT
5256 (2008-03-20) Updated DAT6152 (2010-10-30) |
Minimum Engine
5.2.00 File LengthVaries |
Description Added
2008-03-20 Description Modified2009-03-15 |
Upon execution, the trojan drops following files:
The following registry key is modified:
It connects the following site and sends system information including computer name and OS version.
Then the trojan opens a backdoor. Backdoor has the following functions:
Backdoor-DNW is dropped by Expolit-TaroDrop.g trojan.
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
But in some particular cases, the following steps need to be taken.
Please go to the Microsoft Recovery Console and restore a clean MBR.
On Windows XP:
On Windows Vista and 7: