Home Malware Programs Backdoors Cosdoor

Cosdoor

Posted: March 28, 2006

Cosdoor is a backdoor that gives the attacker unauthorized remote access to a compromised PC. The intruder can use the spyware to steal victim's confidential information. Cosdoor also records all user keystrokes. The backdoor automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iexplore.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}%System%iexplore.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunInternetExplorer=%System%iexplore.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonUserinit%System%userinit.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftsconf
Loading...