Home Malware Programs Worms Loxbot

Loxbot

Posted: March 28, 2006

Loxbot, also known as Maibot, is a dangerous Internet worm that uses AOL Instant Messenger to propagate through messages containing malicious links, which silently download and install the spyware.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 lockx.exe
    2 msdirectx.sys
    3 svkp.sys
    4 xz.bat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunfreestyle=lockx.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesfreestyle=lockx.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunfreestyle=lockx.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRootLEGACY_MSDIRECTXHKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRootLEGACY_SVKPHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSVKPHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesmsdirectx

Related Posts

Loading...