Home Malware Programs Backdoors SikBot

SikBot

Posted: March 28, 2006

SikBot is an IRC-controlled backdoor, which gives the attacker unauthorized remote access to the compromised PC. The intruder can control the infected computer, retrieve computer information, steal user sensitive data and launch Distributed Denial of Service attacks against specified hosts. SikBot secretly runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 slay7383.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunslayhacker734
Loading...