|
Thursday, 24 March 2005 |
Trojan.Mochi is a Trojan horse program that relays spam.
Type: Trojan Horse
Infection Length: 2,511,292 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
When Trojan.Mochi is executed, it performs the following actions:
Copies itself as %System%mocih.exe.
Note: %System% is a variable that refers to the System folder. By default this is C:WindowsSystem (Windows 95/98/Me), C:WinntSystem32 (Windows NT/2000), or C:WindowsSystem32 (Windows XP).
Creates the following service:
Service Name: ACCRA
Display Name: Trace network connections
Description: Managing network connections
Connects to the following servers:
195.225.177.37
pigmailer.scarryserv.biz
Sends SPAM when it receives a command from the above servers.
|