Edge Rewrite
// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a2389063d9c11de6

Jump to content

AFX Windows Rootkit 2003

From Wikipedia, the free encyclopedia

AFX Windows Rootkit 2003 is a user mode rootkit that hides files, processes and registry.

Installation

[edit]

When the installer of the rootkit is executed, the installer creates the files iexplore.dll and explorer.dll in the system directory. The iexplore.dll is injected into explorer.exe, and the explorer.dll is injected into all running processes.[1]

Payload

[edit]

The injected DLLs hooks the Windows API functions to hide files, processes and registry.[1]

References

[edit]
  1. 1 2 "Trojan:Win32/Delf.M". Microsoft. January 16, 2007.