Home Malware Programs Backdoors Telemot

Telemot

Posted: March 28, 2006

Telemot is a backdoor that gives the attacker unauthorized remote access to a compromised PC. It allows the intruder to terminate running processes, download and upload arbitrary files, take screenshots of user activity, retrieve computer information, update the backdoor and reboot the infected PC. Telemot is able to bypass Windows Firewall. It automatically runs as a service on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 chkdsk32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLogicalDiskManagerUsersService

Related Posts

Loading...