Home Malware Programs Backdoors Litebot

Litebot

Posted: March 28, 2006

Litebot is a dangerous backdoor that allows the remote attacker to download and execute arbitrary files from the Internet. The spyware also decreases overall computer security by changing default Windows firewall settings. Litebot main files have random names. The backdoor automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 photoandarticle.exe
    2 uninst.bat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsupport-reverse-smileys
Loading...