Shoutbox

Backdoor.ducy - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Tech Talk (/forumdisplay.php?fid=17)
+----- Thread: Backdoor.ducy (/showthread.php?tid=27166)

Backdoor.ducy by Vantage on 06-13-2004 at 10:43 PM

Mess.be says:
Backdoor.Ducy is a backdoor Trojan horse that uses MSN Messenger to give an attacker access to your computer.

The latest instant-messaging virus was detected last week and can infect an individual's computer from a Website or an e-mail attachment.

"Backdoor.Ducy is being used . . . for command and control," said Vincent Weafer, senior director of development for Symantec Security Response. "Once it's there, [users are] basically using instant messaging as a means to send command-and-control capabilities to an attacker." [Source: New York Post]

What does Ducy do?

1) It creates the file, %Windir%\Msn.exe.

2) Adds the value:

"control"="%Windir%\msn.exe " to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the Trojan runs when you start Windows.

3) Opens a backdoor on the infected system, allowing an attacker to connect to the system using MSN Messenger.


Watch out for this Virus
read more about it Here