Home Malware Programs Backdoors Sokacaps

Sokacaps

Posted: March 28, 2006

Sokacaps is a dangerous backdoor that gives the attacker unauthorized remote access to a compromised PC. The threat uses a chat client and is controlled through the IRC network. It allows the intruder to manage files, collect computer information, run and terminate softwares, download and execute arbitrary files. Sokacaps includes an integrated keylogger module that records all user keystrokes. The backdoor can also be used to perform a DoS attack against a defined remote host. Sokacaps automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 csrss.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunRegWrite=%Windir%Mediacsrss.exe
Loading...