Home Malware Programs Backdoors Prysat

Prysat

Posted: March 28, 2006

Prysat is a dangerous backdoor with rich malicious functionality. It gives the attacker full remote unauthorized access to the infected PC. Prysat runs on every Windows startup and secretly works in background awaiting commands from remote host. Such commands allow the attacker to get detailed computer information, upload and install additional software, including other harmful spywares, perform any action with files and running softwares.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 server.exe
    2 winhost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunWindowsHost=C:WINDOWSsystem32winhost.exe
Loading...