Threat Database Worms Worm:Win32/Vobfus.SO

Worm:Win32/Vobfus.SO

By LoneStar in Worms

Worm:Win32/Vobfus.SO is a worm that proliferates via removable drives and network drives. Worm:Win32/Vobfus.SO may also drop and execute arbitrary files. Once run, Worm:Win32/Vobfus.SO creates a copy of itself to the specific locations. Worm:Win32/Vobfus.SO creates the malevolent files on a corrupted PC. Worm:Win32/Vobfus.SO may also set an 'autorun.inf' file in the root directory of the targeted drive. Such 'autorun.inf files' carry execution commands for the OS, so that when the removable drive is accessed from another PC, which supports the Autorun feature, Worm:Win32/Vobfus.SO is launched automatically. Worm:Win32/Vobfus.SO may contact a remote host at Ns1.boxonline1.com using port 7001. Typically, Worm:Win32/Vobfus.SO may contact a remote host to download and execute arbitrary files (incorporating updates or other malware infections), to report a new infection to its creator, to upload data taken from the attacked PC, to receive configuration or other data and to receive commands from a remote attacker.

File System Details

Worm:Win32/Vobfus.SO may create the following file(s):
# File Name Detections
1. [targeted drive]:\subst.exe
2. [targeted drive]:\qlmew.exe
3. [targeted drive]:\passwords.exe
4. [targeted drive]:\secret.exe
5. [targeted drive]:\porn.exe
6. [targeted drive]:\sexy.exe
7. Ns1.boxonline1.com
8. C:\Documents and Settings\\rcx1c.tmp
9. C:\Documents and Settings\\rcx1f.tmp
10. C:\Documents and Settings\\rcx12.tmp
11. C:\Documents and Settings\\rcx15.tmp
12. C:\Documents and Settings\\rcx18.tmp
13. C:\Documents and Settings\\rcx21.tmp
14. C:\Documents and Settings\\rcx1b.tmp
15. C:\Documents and Settings\\rcx1e.tmp
16. C:\Documents and Settings\\rcx11.tmp
17. C:\Documents and Settings\\rcx14.tmp
18. C:\Documents and Settings\\rcx17.tmp
19. C:\Documents and Settings\\rcx20.tmp
20. C:\Documents and Settings\\rcx23.tmp
21. C:\Documents and Settings\\rcx1a.tmp
22. C:\Documents and Settings\\rcx1d.tmp
23. C:\Documents and Settings\\rcx10.tmp
24. C:\Documents and Settings\\rcx13.tmp
25. C:\Documents and Settings\\rcx16.tmp
26. C:\Documents and Settings\\rcx19.tmp
27. C:\Documents and Settings\\rcx22.tmp

Trending

Most Viewed

Loading...