WORM_VOBFUS.RU

By Domesticus in Worms | 21 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

WORM_VOBFUS.RU Description

WORM_VOBFUS.RU is a worm that propagates via removable drives, can be downloaded from the web or delivered by other computer infections. WORM_VOBFUS.RU comes by connecting corrupted removable drives to a machine. WORM_VOBFUS.RU proliferates as a malicious file downloaded by other computer infections or is dropped unknowingly by computer users when visiting dangerous websites. WORM_VOBFUS.RU downloads an autorun.inf file to automatically load the copies it donwloads when a PC user accesses the drives of a vulnerable machine. While being installed, WORM_VOBFUS.RU downloads the copies of itself in the form of the malicious files in all removable drives of the compromised computer system. WORM_VOBFUS.RU adds several registry entries so that it can start automatically whenever you boot up Windows and access the drives. WORM_VOBFUS.RU also adds the particular registry entries as part of its installation routine. WORM_VOBFUS.RU modifies the particular registry entries to disguise files with Hidden attributes. WORM_VOBFUS.SMAC connects to the particular web addresses to send and get commands from remote cybercriminals.

Type: Worms

How Can You Detect WORM_VOBFUS.RU?

WORM_VOBFUS.RU Removal Details

WORM_VOBFUS.RU has typically the following processes in memory:

  • %User Profile%\{RANDOM CHARACTERS}.exe

WORM_VOBFUS.RU creates the following files in the system:

  • autorun.inf

WORM_VOBFUS.RU creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run {RANDOM CHARACTERS} = “%User Profile%\{RANDOM CHARACTERS}.exe /{RANDOM CHARACTERS}”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUNoAutoUpdate = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedShowSuperHidden = “0″

Important Article Disclaimer

ESG Support Center

This entry was last updated on 10/11/12 and posted on 10/11/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.