Home Malware Programs Trojans Totmau

Totmau

Posted: March 28, 2006

Totmau is a trojan that runs a hidden proxy server on a compromised PC and uses it to distribute e-mail spam. The spyware silently downloads from the Internet and runs arbitrary files. These files are used by a proxy. Totmau also collects computer and network information and transfers it to a predetermined web site. The trojan uses a rootkit to hide its presence in the computer. Totmau automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 sysctl32.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoadsysctl32
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}D5FB5E20-DE80-12CF-9C87-C0AB005187DF
Loading...