|
Friday, 03 June 2005 |
Backdoor.Ranky.O is a back door Trojan horse program that allows a compromised computer to be used as a covert proxy.
When Backdoor.Ranky.O is executed, it performs the following actions:
Adds the value:
"Band-Aid" = "[file path to back door]"
to the registry key:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
so that the back door is executed every time Windows starts.
so that the back door is executed every time Windows starts.
Contacts one of the following servers, on UDP port 10100, with notification of infection:
168.251.73.0
83.79.8.182
37.123.146.2
165.148.65.20
81.218.164.202
65.193.140.0
198.171.88.7
69.28.235.18
Opens a covert proxy on the infected computer. |