This backdoor may be dropped by other malware.
File size: 148,480 bytes
File type: EXE
Memory resident: No
Initial samples received date: 06 Apr 2011
Payload: Drops files
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor drops the following files:
- %system root%\Documents and Settings\All Users\bootstat.dat
- %WINDOWS%\mjRemote.dll.bak
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
explorer\run
mj = Rundll32.EXE %WINDOWS%\mjRemote.dll,GetClassObject
Connect with us on
| | | |