Home Malware Programs Trojans Corem

Corem

Posted: March 28, 2006

Corem, also known as Xmaib, is a trojan that searches the infected computer for e-mail addresses, collects them and sends out to a predefined web server.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 windowssvc.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunWindows=windowssvc.exe

Related Posts

Loading...