Home Malware Programs Trojans Looksky.b

Looksky.b

Posted: March 28, 2006

Looksky.b is a backdoor that gives the attacker unauthorized remote access to a compromised PC. It allows the intruder to download and run arbitrary files, retrieve computer information and update the spyware. Looksky.b is controlled through the IRC network. It is able to bypass Windows Firewall. The backdoor automatically runs on every computer startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 csmsv.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunManageProtocolCtrl
Loading...