Home Malware Programs Backdoors Rado

Rado

Posted: March 28, 2006

Rado is a backdoor that gives the attacker unauthorized remote access to a compromised PC.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 winupdate.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunwinupdate.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftKernelHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServiceswinupdate.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinupdate.exe

Related Posts

Loading...