Threat Database Worms Win32/Lefgroo

Win32/Lefgroo

By LoneStar in Worms

Win32/Lefgroo is a worm that replicates itself to any removable drives or mapped network shares, and shows messages. While being installed on the targeted computer system, Win32/Lefgroo makes system changes by downloading harmful files and making changes to the Windows Registry. Win32/Lefgroo also creates a registry entry to make sure that it launches automatically every time you boot up Windows. Win32/Lefgroo may also open websites in a full-screen browser window. Win32/Lefgroo may also make modifications to the registry entries attempting to stay on the PC, and help in delivery of its payload. Win32/Lefgroo removes the Folder Options item from all Explorer menus and the Control Panel by making modifications the Windows Registry. Win32/Lefgroo modifies Internet Explorer settings and disables the system tool Task Manager by modifying the Windows Registry. Win32/Lefgroo uses the folder icon, which may fool the PC user into clicking on it. If the folder icon is clicked, Win32/Lefgroo will be executed.

File System Details

Win32/Lefgroo may create the following file(s):
# File Name Detections
1. %windir%\profile\susoft.exe
2. %windir%\profile\services.exe
3. [Drive]:\musica.exe

Registry Details

Win32/Lefgroo may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoFolderOptions" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "HTML" = "%windir%\profile\services.exe"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "FullScreen" = "yes"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = "1"

Trending

Most Viewed

Loading...