Home Malware Programs Backdoors Nodelm

Nodelm

Posted: March 28, 2006

Nodelm is a backdoor that provides the attacker with unauthorized remote access to the compromised PC. It allows the intruder to take screenshots of user activity, download and upload arbitrary files, run applications, browse the file computer and start a hidden web server. Nodelm terminates running antiviruses, firewalls, many security-related applications and some other software. The backdoor may collect computer data and steal user sensitive information and transfer it to a predefined remote host. Nodelm runs on every Windows startup.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun[filename]
Loading...