Home Malware Programs Backdoors Disgu

Disgu

Posted: March 28, 2006

Disgu is a backdoor that provides the attacker with unauthorized remote access to the compromised PC. The intruder can manage the entire file computer, download and upload arbitrary fils, run softwares, manipulate the mouse, record sounds and restart the PC. Disgu hides its presence in the computer by injecting malicious code into legitimate processes. The backdoor automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iexplorer.exe
    2 kernel.dll
    3 sendmsg.dll
    4 systemlr.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRuniexplorer.exe=%System%iexplorer.exe
Loading...