Home Malware Programs Backdoors Radium

Radium

Posted: March 28, 2006

Radium is a backdoor that gives the attacker unauthorized remote access to a compromised PC. The intruder can manage the file computer, terminate running applications, execute computer commands, take screenshots, download and upload arbitrary files, open and close the CD-ROM tray, hide the taskbar and desktop icons, restart or turn off a PC. Radium is able to bypass Windows firewall. The backdoor automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 helpsvc.exe
    2 ldr.dll
    3 msp.dll
    4 ntr.sys

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTCLSID(FF00E8A3-2BE6-11D2-8003-92E340524100)HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoadWebCheck=(FF00E8A3-2BE6-11D2-8003-92E340524100)
Loading...