Home Malware Programs Worms Ritdoor

Ritdoor

Posted: March 28, 2006

Ritdoor is a dangerous Internet worm that spreads through file sharing networks, via unprotected network shares and by exploiting vulnerable PCs running Microsoft Windows operating computer with unpatched security flaws.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 msdefr.exe
    2 nb32ext4.exe
    3 services.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}%Windows%services.exeHKEY_CURRENT_USERSoftwareMicrosoftInternetExploreriepsdgxc=1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesDisableRegistryTools=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesDisableRegistryTools=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServiceshelloworld3HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonUserinit%System%userinit.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4pcserv32g

Related Posts

Loading...