Home Malware Programs Trojans Hotword

Hotword

Posted: March 28, 2006

Hotword is a dangerous trojan that logs user keystrokes, steals computer information and gives the attacker unauthorized remote access to a compromised PC. It sends gathered data by e-mail or uploads it to predetermined FTP servers. The intruder can use Hotword to terminate running processes, download and run arbitrary files, capture screenshots of user activity, send e-mail messages or update the trojan. Hotword is able to bypass Windows Firewall. The trojan automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 [X]svchost.exe
    2 explore.exe
    3 login.lnk
    4 mmsystem.dlx
    5 vzzpkghva.crb
    6 windll-objectswin*.dlx

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsWUHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunloginegedit

Related Posts

Loading...