Home Malware Programs Backdoors Asb

Asb

Posted: March 28, 2006

Asb is a backdoor that provides the attacker with unauthorized remote access to the compromised PC. It allows the intruder to download arbitrary files, send messages to specified hosts, control CD and DVD drives. Asb can also log user keystrokes and transfer gathered data to a predefined remote location. The backdoor runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 of.sys
    2 pic04.exe
    3 win.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinload

Related Posts

Loading...