Home Malware Programs Worms Blaxe

Blaxe

Posted: March 28, 2006

Blaxe is an Internet worm that spreads through file sharing networks using popular peer-to-peer softwares.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 directx.exe
    2 ftp.bat
    3 messenger plus! - setup.exe
    4 update.exe
    5 winbat.exe
    6 windll32.dll
    7 wzextract.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareGroksterLocalContentdir0=012345:%Windir%kernellHKEY_CURRENT_USERSoftwareGroksterLocalContentdir1=012345:%Windir%kernellHKEY_CURRENT_USERSoftwareGroksterLocalContentdir2=012345:%Windir%kernellHKEY_CURRENT_USERSoftwareKaZaALocalContentdir0=012345:%Windir%kernellHKEY_CURRENT_USERSoftwareKaZaALocalContentdir1=012345:%Windir%kernellHKEY_CURRENT_USERSoftwareKaZaALocalContentdir2=012345:%Windir%kernellHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunDirectX=%Windir%directx.exeHKEY_CURRENT_USERSoftwareiMeshClientLocalContentdir0=012345:%Windir%kernellHKEY_CURRENT_USERSoftwareiMeshClientLocalContentdir1=012345:%Windir%kernellHKEY_CURRENT_USERSoftwareiMeshClientLocalContentdir2=012345:%Windir%kernellHKEY_LOCAL_MACHINESOFTWAREClassesWinZipShellOpenCommand(Default)=[pathtowzextract.exe]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesDirectX=%Windir%directx.exe
Loading...