Home Malware Programs Backdoors BanBot

BanBot

Posted: March 28, 2006

BanBot is a backdoor that provides the attacker with unauthorized remote access to a compromised PC. The intruder can download, upload and execute arbitrary files, run softwares, manage the file computer, control the mouse and keyboard and steal user sensitive information. BanBot includes the functionality to record user keystrokes. It is able to bypass some firewalls. The backdoor secretly runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ali.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun""=%System%ali.exe
Loading...