Home Malware Programs Backdoors Telemot.b

Telemot.b

Posted: March 28, 2006

Telemot.b is a backdoor that gives the attacker unauthorized remote access to the compromised PC. It allows the intruder to terminate running processes, alter the Windows registry, take screenshots of user activity, download and upload arbitrary files, shutdown a PC and update the backdoor. Telemot.b injects malicious code into legitimate computer processes in order to hide itself from the user. It is able to bypass the Windows Firewall. The backdoor runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 chkdsk64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLogicalUsersDiskManagerService
Loading...