Home Malware Programs Malware RussKill

RussKill

Posted: February 26, 2010

RussKill is a malicious program which can be used by attackers to install malware or popups on your computer, spread machine lists and organize Delivery of Service (DoS) attacks. RussKill is controlled by a web panel of hackers who send commands to the infected machine to start attacks on specified websites using DoS attacks. Use a reliable anti-malware program to remove RussKill before it creates chaos on your system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %User%\Local Settings\Application Data\microsoft\windows\95548.exe
    2 %User%\Local Settings\Application Data\microsoft\windows\winfdd.exe
    3 %User%\Local Settings\Application Data\microsoft\windows\wtnmm.exe
    4 %User%\Start Menu\Programs\Startup\wtnmm.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: explorer.exeHKEY..\..\..\..{RegistryKeys}"%User%\Local Settings\Application Data\microsoft\windows\wtnmm.exe".db
Loading...