Home Malware Programs Trojans Gamqowi

Gamqowi

Posted: March 28, 2006

Gamqowi is a trojan that gives the attacker unauthorized remote access to a compromised PC. It allows the intruder to download files, send e-mail messages and retrieve computer information. Gamqowi terminates running processes of antiviruses, firewalls and security-related applications and blocks access to popular security-related web sites and online services. The spyware also disables Windows File Protection and prevents the user from launching Registry Editor. Gamqowi secretly runs on every computer startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ajlkqjlk.exe
    2 dodrrr.exe
    3 mscore32.dll
    4 mwfirewall.exe
    5 svch0st.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSOFTWAREMicrosoftInternetExplorerlmnlaHKEY_CURRENT_USERSOFTWAREMicrosoftInternetExplorermtxnmHKEY_CURRENT_USERSOFTWAREMicrosoftInternetExplorerveerHKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionPoliciesDisableRegistryTools=0HKEY_CURRENT_USERSoftwareMicrosoftOLEwinrun=svch0st.exeHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunOncems_anti_spywareHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunms_anti_spywareHKEY_CURRENT_USERSystemCurrentControlSetControlLsawinrun=svch0st.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftOLEwinrun=svch0st.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesDisableRegistryTools=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOncems_anti_spywareHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRundevsecHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunms_anti_spywareHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSFCDisable=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonSFCScan=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsawinrun=svch0st.exe
Loading...