Home Malware Programs Backdoors Elburro

Elburro

Posted: March 28, 2006

Elburro is a backdoor that provides the attacker with unauthorized remote access to a compromised PC. The intruder can download and execute arbitrary files, alter computer configuration, retrieve computer information, collect e-mail addresses and send letters to specified recipients. Elburro can close some opened folders, terminate running security-related tools and computer utilities like the Registry Editor. It also is able to bypass Windows Firewall. Elburro afects mostly PCs running Spanish version of Microsoft Windows. The trojan automatically runs on every OS startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 msappts32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunmsappts32=%Windows%msappsmsinfomsappts32.exe
Loading...