Home Malware Programs Backdoors Mepcod

Mepcod

Posted: March 28, 2006

Mepcod is a backdoor that gives the attacker remote unauthorized access to a compromised PC. It also contacts a predetermined web server and downloads arbitrary files and additional instructions. Mepcod automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 mcafeescanplus.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMcAfeeScanPlus=%Windir%mcafeescanplus.exeHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%McAfeeScanPlus
Loading...