Home Malware Programs Backdoors Gravebot

Gravebot

Posted: March 28, 2006

Gravebot is an IRC-controlled backdoor that provides the remote attacker with full unauthorized access to a compromised PC. The threat also contacts a predetermined web server, silently downloads from there and runs arbitrary files, some of them can be malicious. Gravebot automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 codll.exe
    2 sum.tgz

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRundivx=codll.exe
Loading...