Home Malware Programs Backdoors Dragodor

Dragodor

Posted: March 28, 2006

Dragodor is a backdoor that provides the attacker with unauthorized remote access to the compromised PC. The intruder can change the Internet Explorer default home page, download and execute arbitrary files. Dragodor can also terminate some running antiviruses and security-related applications. The backdoor runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 services.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunServicesservicesHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunservicesHKEY_CURRENT_USERSoftwareMicrosoftWindowsNTCurrentVersionRunservicesHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesservicesHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunservices
Loading...