Home Malware Programs Worms Bibot

Bibot

Posted: March 28, 2006

Bibot is an Internet worm that spreads by exploiting unpatched security vulnerabilities found on network PCs running Microsoft Windows operating computer. The spyware contains an integrated IRC-controlled backdoor that gives the attacker unauthorized remote access to a compromised PC. The intruder can use it to steal user confidential information, install and run a hidden FTP server, access specified Internet resources and network shares, participate in Distributed Denial of Service attacks against particular remote hosts. Bibot automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 winmgr.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwindowspc=winmgr.exe
Loading...