Home Malware Programs Backdoors EasyServ

EasyServ

Posted: March 28, 2006

EasyServ is a backdoor that gives the attacker unauthorized remote access to a compromised PC. The threat runs a web server that shows the directory structure of any specified local hard disk. The intruder can steal any file using a web-based interface. EasyServ automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRuneasyserv
Loading...