Home Malware Programs Remote Administration Tools Destruktor

Destruktor

Posted: March 28, 2006

This small RAT application was created by a Polish hacker called Destructor. The applicationming language is Delphi. Several variants of this pest appeared in the internet from December 2002 to February 2004. The virus creates a "backdoor" in the infected security computer, allowing the intruder to control the PC and stay unnoticed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 [system
    2 backdoor.destrukor.14.exe
    3 czytaj.txt
    4 dest_1_1.exe
    5 dest_1_3.exe
    6 dest_1_4.exe
    7 game.exe
    8 opis.txt
    9 rotkurtsed.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionotkurtsedun
Loading...