Recently, Kaspersky, a well-known information security vendor, published a virus broadcast, reminding users to pay attention to a Trojan program named backdoor. win32.backoff..
It is reported that this is a backdoor Trojan. After intruding into the computer, it first copies itself to the root directory, then adds it to the boot auto-start item through the registry, and creates a log file to save the user's key record, then, the logs are remotely uploaded to the specified location according to the instructions of the Trojan horse author. In addition, the trojan also creates a socket to connect to a remote address to receive commands and execute malicious code. At the same time, malicious code is injected into the system process, and then the program itself is deleted to increase its concealment.
Kaspersky reminds users to update the virus database of Anti-Virus products in a timely manner and patch the system regularly without opening suspicious emails or websites, do not randomly receive the files transmitted on the chat tool and link to the developed website. When using mobile media, it is best to right-click the file and use it. If necessary, scan the file first, downloading software from unreliable channels is likely to carry viruses.
Kaspersky: Watch out for "keyboard recorder Trojan"