Home Malware Programs Trojans Mailbot

Mailbot

Posted: March 28, 2006

Mailbot is a trojan that sends out large amount of spam e-mail messages from a compromised PC. It harvests e-mail addresses from local web pages, text and spreadsheet documents, mail clients configuration files. Mailbot also regularly contacts predetermined web sites in order to transfer operation statistcs and receive additional instructions. The trojan is able to bypass certain firewalls and hide its presence in the computer by injecting malicious code into legitimate running processes . Mailbot automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 msctl32.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonNotifymsctl32.dll

Related Posts

Loading...