Home Malware Programs Worms Crutle.b

Crutle.b

Posted: March 28, 2006

Crutle.b is a worm that spreads via IRC chats and through file sharing networks using popular Kazaa software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 lsass.exe
    2 macbet.mrc
    3 msfck.exe
    4 mswin32.exe
    5 porn_in_msn.txt.pif
    6 sysoff.pif
    7 sysreset.scr
    8 taskbar.exe
    9 tasker.pif
    10 thefuck.scr
    11 win.exe
    12 winini.scr
    13 winlog.pif

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareKazaaLocalContentDisableSharing=0HKEY_CURRENT_USERSoftwareKazaaResultsFilterfirewall_filter=0HKEY_CURRENT_USERSoftwareKazaaResultsFiltervirus_filter=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinexec
Loading...