Sophos

Troj/Bckdr-CIC

Aliases
  • BackDoor-CIC
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 30 September 2004 11:15:00 (GMT)
Last updated 12 October 2004 19:42:14 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bckdr-CIC is a backdoor Trojan for the Windows platform.

When first run, Troj/Bckdr-CIC will copy itself to the Windows System folder as KERNEL32S.EXE. In order to run automatically each time Windows is started, Troj/Bckdr-CIC sets the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Kernel32 = <SYSTEM>\kernel32s.exe

Troj/Bckdr-CIC will listen on a default port of 5050 for remote access.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer