BKDR_CN.A
Trojan:Win32/Crazynet.378 (Microsoft), Backdoor.CrazyNet.3.7.5 (FSecure), Backdoor.Win32.VB.HMR!cobra (v) (Sunbelt), BDS/CrazyNet.521 (Antivir), Trojan horse BackDoor.CrazyNet (AVG), Backdoor.CrazyNet.3.7.5 (Bitdefender), W32/CrazyN.378!tr.bdr (Fortinet), Backdoor.Win32.CrazyNet.375 (Ikarus), Win32/CrazyNet.375 trojan (ESET), Trojan W32/Crazzy.3_78 (Norman), Bck/CrazzyNet.3.7.8 (Panda)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
![](/vinfo/imgFiles/legend.jpg)
Threat Type: Backdoor
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This backdoor drops the following copies of itself into the affected system and executes them:
- %Windows%\Registry32.exe
(Note: %Windows% is the Windows folder, which is usually C:\Windows.)
It drops the following files:
- %System Root%\mykeys.sys
- %System Root%\winstart.bat
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.)
It terminates the execution of the copy it initially executed and executes the copy it drops instead.
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Reg32 = "Registry32.exe"
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\Windows
run = "Registry32.exe"
It modifies the following registry entries to ensure it automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Winlogon
Shell = "Explorer.exe Registry32.exe"
(Note: The default value data of the said registry entry is Explorer.exe.)