Home Malware Programs Worms Alasrou

Alasrou

Posted: March 28, 2006

Alasrou is a worm that spreads by infecting PCs running Windows operating computer with unpatched security vulnerabilities. The spyware searches the compromised computer for e-mail addresses, collects them and uploads to a predetermined FTP server. It silently downloads from the Internet and runs arbitrary potentially harfum files. Alasrou also changes Internet Explorer default home and search pages. The worm automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 file1.exe
    2 searchpage.htm

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchPage=[siteaddressorpathtothesearchpage.htmfile]HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddressorpathtothesearchpage.htmfile]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRuninstance001
Loading...