Home Malware Programs Backdoors Prosti

Prosti

Posted: March 28, 2006

Prosti is a backdoor that gives the attacker unauthorized remote access to the compromised PC. It allows the intruder to control the infected computer and steal user sensitive information. Prosti also logs user keystrokes and terminates running processes of popular antiviruses, firewalls and other security-related applications. The backdoor can also alter computer configuration. Prosti runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 lass..exe
    2 service.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonShell="explorer.exe%System%lass..exe"

Related Posts

Loading...