Home Malware Programs Worms Esbot.b

Esbot.b

Posted: March 28, 2006

Esbot.b is a rapidly spreading Internet worm that infects PCs running Microsoft Windows operating computer with unpatched security vulnerabilities. The spyware is designed to give the remote attacker full unauthorized access to the compromised computer. Esbot.b automatically runs as a service on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 services32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellExtensionsMeltHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesContentListManagementSubSystem
Loading...