Posting Terbaru

Selasa, 01 Juli 2008

Bdoor-AMH Trojan Edits Registry Value, Connects to Remote Host

Tidak ada komentar :
Troj/Bdoor-AMH is a Trojan for the Windows platform.

Troj/Bdoor-AMH copies itself to either the (Windows\naver2.exe) folder or C:\naver2.exe.

Troj/Bdoor-AMH edits the registry value:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run naver2.exe

Troj/Bdoor-AMH connects to a remote host to receive information. After receiving instructions from the remote host, it will then send the data back to the remote host using SMTP.
More information can be found at this Sophos page.

Source : esecurityplanet.com

Tidak ada komentar :