Backdoor.Orcus is a Remote Access Trojan (RAT) that is being sold on underground forums.
Backdoor.Orcus often creates Scheduled Tasks to gain persistence. The Scheduled Tasks have names like Orcus Respawner.jobor Orcus.job.
Backdoor.Orcus offers a lot of configurability options. Installing a keyloggeris one of these options.
Malwarebytes can removes Backdoor.Orcus without further user interaction.
Scheduled Tasks:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Orcus%SYSDIR%\Tasks\Orcus%WINDIR%\Tasks\Orcus.jobHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Orcus Respawner%SYSDIR%\Tasks\Orcus Respawner%WINDIR%\Tasks\Orcus Respawner.job
Select your language