Home Malware Programs Viruses Nethood.htm

Nethood.htm

Posted: July 23, 2009

Nethood.htm is a file used by the virus Feldor. Feldor attempts to provide an attacker with unauthorized remote access to the compromised PC by changing the computer settings.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 folder.htt
    2 ghost.bat
    3 nethood.htm
    4 nethood.htmwindows.exe
    5 windows.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunempcomHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunempcom
Loading...