Home Malware Programs Worms Mogi

Mogi

Posted: March 28, 2006

Mogi is an Internet worm, which spreads through file sharing networks using popular peer-to-peer softwares including eDonkey2000, Kazaa, eMule, Limewire, Morpheus, BearShare and Gnucleus. It may also propagate via the ICQ network.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ath.exe
    2 bayloz.exe
    3 bomba.exe
    4 bonk.exe
    5 covert.dll
    6 dragon_naturallyspeaking_xp.exe
    7 iexplore.exe
    8 jolt2.exe
    9 kod.exe
    10 layer.exe
    11 multi_password_cracker.exe
    12 norton_2004_setup.exe
    13 sin.exe
    14 smurf.exe
    15 suf.exe
    16 syn.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunservices=iexplore.exe
Loading...