Home Malware Programs Backdoors Piebot

Piebot

Posted: March 28, 2006

Piebot is an IRC-controlled backdoor that provides the attacker with unauthorized remote access to a compromised PC. The intruder can manage the file computer, alter computer configuration, terminate running antivirus and security-related software, steal user sensitive information, launch a Denial of Service attack or perform other harmful actions. Piebot blocks access to numerous antivirus and security-related web sites. It also disables the Windows Firewall and the Shared Access service. Piebot automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 mididef32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunFirewallPolicy=mididef32.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesFirewallPolicy=mididef32.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4
Loading...