Home Malware Programs Backdoors BKDR_HELOAG.SM

BKDR_HELOAG.SM

Posted: April 21, 2010

BKDR_HELOAG.SM is a malicious Backdoor parasite which has the potential to damage the system and propogate. BKDR_HELOAG.SM is a part of a Command-and-Control (C&C) Botnet that continuously creates threads to connect to multiple IP address and receive commands from hackers. This routine causes the sytem slow down and hogs network resources. Remove BKDR_HELOAG.SM with an updated security program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windows%\ThunderUpdate.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HKEY..\..\..\..{RegistryKeys}Shell = "Explorer.exeWindows NT\CurrentVersion\Winlogon
Loading...