Home Malware Programs Backdoors Dckane

Dckane

Posted: March 28, 2006

Dckane is a backdoor that provides the attacker with unauthorized remote access to a compromised PC. The intruder can issue specific commands, which will allow him to control the computer and steal user sensitive information. Dckane is able to hide itself by injecting malicious code into active computer processes. The backdoor automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 kane.dll
    2 kane.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonShell=explorer.exekane.exe
Loading...