Home Malware Programs Remote Administration Tools Remote Boot Tool

Remote Boot Tool

Posted: March 28, 2006

Remote Boot Tool is a malicious RAT application that consists of server and client. The server runs on the compromised computer and can be used by the attacker to log off current user, reboot or shutdown a PC.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 msgsrv32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunmsgsrv32
Loading...