Home Malware Programs Backdoors Foobot

Foobot

Posted: March 28, 2006

Foobot is an IRC-controlled backdoor, which gives the attacker unauthorized remote access to a compromised PC. The intruder can download and execute arbitrary files and perform Denial of Service attacks against specified hosts. Foobot also contacts predetermined web sites to receive additional instructions. The backdoor automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 services.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunkernel
Loading...