Spam-Mailbot.c implements advanced rootkit techniques to hide its presence. It hides into Alternate Data Streams and have functionality to send spam e-mails. This trojan also displays backdoor capabilities by running its code within the context of services.exe.
|
Minimum DAT
4798 (2006-07-03) Updated DAT5855 (2010-01-08) |
Minimum Engine
5.1.00 File LengthN/A |
Description Added
2006-07-19 Description Modified2006-07-19 |
System Changes
Files Added
Registry
The following registry keys are created:
Other characterstics
It may open random TCP ports within the context of legitimate "Services.exe" process.
Attempts to contact following URLs
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc
All Users:
Manual Removal Instructions