Backdoor.ducy - Printable Version
-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Tech Talk (/forumdisplay.php?fid=17)
+----- Thread: Backdoor.ducy (/showthread.php?tid=27166)
Backdoor.ducy by Vantage on 06-13-2004 at 10:43 PM
Mess.be says:
Backdoor.Ducy is a backdoor Trojan horse that uses MSN Messenger to give an attacker access to your computer.
The latest instant-messaging virus was detected last week and can infect an individual's computer from a Website or an e-mail attachment.
"Backdoor.Ducy is being used . . . for command and control," said Vincent Weafer, senior director of development for Symantec Security Response. "Once it's there, [users are] basically using instant messaging as a means to send command-and-control capabilities to an attacker." [Source: New York Post]
What does Ducy do?
1) It creates the file, %Windir%\Msn.exe.
2) Adds the value:
"control"="%Windir%\msn.exe " to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
3) Opens a backdoor on the infected system, allowing an attacker to connect to the system using MSN Messenger.
Watch out for this Virus
read more about it Here
|