Home Malware Programs Backdoors Revrs

Revrs

Posted: March 28, 2006

Revrs is a dangerous backdoor that gives the attacker full remote unauthorized access to a compromised PC. The hacker can execute different commands, run applications, record user keystrokes, manage files, modify computer settings, download and install additional software, steal user sensitive information, control a PC and its devices. Revrs stores its files in C:WindowsSystem or C:WinntSystem directory. It runs on every Windows startup. The backdoor has the ability to update itself via the Internet.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 directx3d.exe
    2 msgsrv16.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunDirectX3DService=%Windir%Systemdirectx3d.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunService386Shell=%Windir%Systemmsgsrv16.exe
Loading...