Threat Database Worms W32.Shadesrat.B

W32.Shadesrat.B

By Domesticus in Worms

Threat Scorecard

Ranking: 5,031
Threat Level: 20 % (Normal)
Infected Computers: 72,756
First Seen: March 30, 2012
Last Seen: September 18, 2023
OS(es) Affected: Windows

W32.Shadesrat.B is a PC worm that uses removable drives to spread itself. W32.Shadesrat.B also opens a back door on the hacked computer by connecting to the particular web pages. Once executed, W32.Shadesrat.B copies itself by creating the particular files on all removable drives and runs when the drives are accessed. W32.Shadesrat.B then creates the specific registry entries so that it can run automatically each time you start your PC. W32.Shadesrat.B then creates the specific registry entries to avoid the Windows firewall. W32.Shadesrat.B may steal passwords from the applications such as .NET Messenger, MSN Messenger and Mozilla FireFox. Remote attackers may also try to distribute W32.Shadesrat.B through the file-sharing applications such as uTorrent, BitTorrent, Vuze and LimeWire, if installed on the infected computer. You should remove W32.Shadesrat.B in order to secure your PC from damage.

File System Details

W32.Shadesrat.B may create the following file(s):
# File Name Detections
1. %DriveLetter%[ORIGINAL FILE NAME].exe
2. %System%winlogin.exe
3. %UserProfile%Application DataEZSpammer.exe
4. %DriveLetter%autorun.inf
5. %UserProfile%Application Datadata.dat

Registry Details

W32.Shadesrat.B may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun"winlogin" = "%UserProfile%Application DataEZSpammer.exe"
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList"%UserProfile%Application DataEZSpammer.exe" = "%UserProfile%Application DataEZSpammer.exe:*:Enabled:Windows Messanger"
HKEY_CURRENT_USERSoftwareVB and VBA Program SettingsSrvIDID"|Ae*}jFVWT" = "Blackshades"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftActive SetupInstalled Components{AB68ADAA-71EF-4CDD-BFFF-CEC31F5A92EB}"StubPath" = "%UserProfile%Application DataEZSpammer.exe"
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun"winlogin" = "%UserProfile%Application DataEZSpammer.exe"
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfile"DoNotAllowExceptions" = "0"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer un"winlogin" = "%UserProfile%Application DataEZSpammer.exe"
HKEY_CURRENT_USERSoftwareMicrosoftActive SetupInstalled Components{AB68ADAA-71EF-4CDD-BFFF-CEC31F5A92EB}"StubPath" = "%UserProfile%Application DataEZSpammer.exe"
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList"%CurrentFolder%[ORIGINAL FILE NAME].exe" = "%CurrentFolder%[ORIGINAL FILE NAME].exe:*:Enabled:Windows Messanger"

URLs

W32.Shadesrat.B may call the following URLs:

download-step1.com

Trending

Most Viewed

Loading...