Threat Database Worms WORM/Slenfbot.DP.5

WORM/Slenfbot.DP.5

By ZulaZuza in Worms

Worm/Slenfbot.DP.5.worm is a malicious computer worm that denies access for users to local networks and sometimes to the Internet as a side-effect. The aim of Worm/Slenfbot.DP.5.worm is to use computer systems targeted as bots monitored by remote criminals. The criminals monitoring bot computers enjoy both extended control of the infected computer system and exhausted information on actions taken by its victims. WORM/Slenfbot.DP.5.worm can replicate itself without any user's interruption. WORM/Slenfbot.DP.5.worm will send copies of itself to other computers through the network without any authorization. All the distributed copies of WORM/Slenfbot.DP.5.worm can reproduce themselves on the affected computers that have security problems. WORM/Slenfbot.DP.5.worm does not need to attach itself to an existing application, but it can, at least, result in some damage to the network.

File System Details

WORM/Slenfbot.DP.5 may create the following file(s):
# File Name Detections
1. %Temp%\wscsvc32.exe
2. %Documents and Settings%\[UserName]\Start Menu\ Settings.lnk

Registry Details

WORM/Slenfbot.DP.5 may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'Protection Center'v
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run '[random string]'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings 'ProxyServer' = 'http=127.0.0.1:5555'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System 'DisableTaskMgr' = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations 'LowRiskFileTypes' = '.exe'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce 'SelfdelNT'
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}

Trending

Most Viewed

Loading...