The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security > Malware Advisories (RSS)
Google UNIX.COM


Malware Advisories (RSS) Malware Security Advisories Via RSS

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Worm_yahlover.al iBot Malware Advisories (RSS) 0 01-14-2008 03:30 AM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 07-17-2008
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,296
Worm_yahlover.az

This worm may be downloaded unknowingly by a user when visiting malicious Web sites.

This worm drops copies of itself. It also drops component files which Trend Micro detects as MAL_OTORUN2.

This worm creates registry entries to enable its automatic execution at every system startup. It also uses Windows Task Scheduler to create a scheduled task that it uses to executes a dropped copy.

This worm sends messages to target recipients using instant messaging applications. This worm drops copies of itself in all removable drives. It drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.

This worm accesses Web sites to download files which Trend Micro detects as the following malware:

  • WORM_YAHLOVER.BH
  • TROJ_AGENT.ADZE
  • BKDR_POISON.DS
This worm terminates a certain process, if found running in memory.



More...
Reply With Quote
Google The UNIX and Linux Forums
Forum Sponsor
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 12:13 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0