Home Malware Programs Backdoors Backdoor.LolBot

Backdoor.LolBot

Posted: September 15, 2010

Backdoor.LolBot is malicious backdoor malware that spreads through instant messenger (IM) programs such as AOL, Yahoo! Messenger or Skype. Backdoor.LolBot sends a malicious message to the user's contacts. Backdoor.LolBot will attempt to spread by sending a link that contains a malicious download. Backdoor.LolBot also downloads other malware onto the infected system which spreads through removable drives such as USB flash devices. Remove Backdoor.LolBot immediately using a reliable malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\jusched.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...