|
Illusion Mailer This trojan is basically an anonymous emailer using the victims computer to send the emails from . This effectively spoofs the real senders ip ( like hackers telneting from shells etc ) I cant see why anyone would want to use this as there are much simpler ways of spoofing your ip with email . It opens ports 2155 TCP, 5512 TCP on the infected machine
Removal : Open regedit and follow the following path : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Look for the key that says sysmem and delete it .
Reboot and then go to start and find and do a search for memory.exe when its found delete this file .
|
|