Padonok (k)
(Backdoor.Win32.Padodor.k)

by HangUp Team


Made in Russia

more versions



dropped files: c:\WINDOWS\system32\Aklbaknd.dll size: 6.145 bytes c:\WINDOWS\system32\Pghfibjp.exe size: 65.536 bytes port: 73, 16454, 32121, 23232 TCP added to registry: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess HKEY_CLASSES_ROOT\CLSID\{79FB9088-19CE-715E-D900-216290C5B738} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\. tested on Windows XP December 31, 2004
MegaSecurity