![]() |
|
|
|
|
|||||||
| Forums | Portal | Register | Forum Rules | FAQ | Contribute | Members List | Arcade | Search | Today's Posts | Mark Forums Read |
| Malware Advisories (RSS) Malware Security Advisories Via RSS |
|
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Worm_onlineg.ugx | iBot | Malware Advisories (RSS) | 0 | 07-08-2008 04:40 AM |
| Worm_onlineg.ugt | iBot | Malware Advisories (RSS) | 0 | 06-24-2008 08:10 AM |
| Worm_onlineg.gte | iBot | Malware Advisories (RSS) | 0 | 05-22-2008 06:50 AM |
| Worm_onlineg.gak | iBot | Malware Advisories (RSS) | 0 | 04-18-2008 05:50 AM |
| Worm_onlineg.djo | iBot | Malware Advisories (RSS) | 0 | 01-30-2008 04:00 PM |
|
|
Submit Tools | LinkBack | Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||
|
||||
|
Worm_onlineg.xdz
This worm may be downloaded unknowingly by a user when visiting malicious Web site(s).
It creates registry entry(ies) to enable its automatic execution at every system startup. It modified registry entry(ies) to hide files with both System and Read-only attributes. It drops copies of itself in all physical and removable drives. It also drops an AUTORUN.INF file to enable the automatic execution of its dropped copies every time the said drives are accessed. This worm accesses Web sites to download file(s), including WORM_ONLINE.CS. The downloaded .RAR file contains an encrypted URL code which can download a copy of WORM_ONLINE.CS. As a result, routines of the downloaded files are also exhibited on the affected system. It also drops component file(s). One of the .DLL files, which contains all malicious routines of its main malware component, is injected into the legitimate process EXPLORER.EXE. It terminates process(es), if found running in memory. This worm steals information by collecting user inputs (specifically user names and passwords) from certain URLs. It also monitors certain online game processes. It then sends the gathered information to several IP addresses. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data. More... |
||||
| Google The UNIX and Linux Forums |
| Forum Sponsor | ||
|
|
| Thread Tools | Search this Thread |
| Display Modes | |
|
|