Home Malware Programs Backdoors Clunky

Clunky

Posted: March 28, 2006

Clunky is a backdoor that provides the attacker with unauthorized remote access to the compromised PC. The intruder can download, upload and run arbitrary files, manage the computer and retrieve user sensitive information. Clunky can download and install other spywares. The backdoor automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 adslcom.exe
    2 adslcom.sys
    3 adslcomdos.exe
    4 fixcomdos.exe
    5 iexplore.exe
    6 iexplorer.exe
    7 msfport.dll
    8 wincontxt.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRunsyncmon
Loading...