Home Malware Programs Worms IM-Worm.Win32.Sohanad.qr

IM-Worm.Win32.Sohanad.qr

Posted: February 25, 2011

As a worm and a Trojan, IM-Worm.Win32.Sohanad.qr is capable of spreading quickly through networks while dropping malicious files on infected systems. IM-Worm.Win32.Sohanad.qr is highly likely to alter security settings in a negative fashion and may allow remote attackers to have access. Its highly aggressive Trojan behavior, threat of high propagation and general security issues call for deleting IM-Worm.Win32.Sohanad.qr with expediency, or the infected machine may be permanently damaged.

Stomping IM-Worm.Win32.Sohanad.qr Before It Gets In

IM-Worm.Win32.Sohanad.qr is confirmed to spread through networks from one computer to the next. You're still required to interact with files on the network before your own system can be infected, so scanning any network-shared files before using them may help you avoid a IM-Worm.Win32.Sohanad.qr infection. Many worms like IM-Worm.Win32.Sohanad.qr will also copy themselves to removable drives and use Autorun functions to infect the next system the peripheral is plugged into, making caution with removable devices a helpful concern.

Some reports have shown IM-Worm.Win32.Sohanad.qr to be 1176 kb in size, but this number shouldn't be absolutely relied on for identification, given the possibility of new variations of the worm. Relying on recognizing file names is also unwise, since IM-Worm.Win32.Sohanad.qr has been indicated to start up .exe processes that are named after legitimate Windows files.

IM-Worm.Win32.Sohanad.qr was identified in late 2010, so don't rely on anti-malware scanners that have older malware definition databases than that to catch this attacker. In the case that you do get a IM-Worm.Win32.Sohanad.qr infection, it will probably add start-up entries to your registry, and may also make other registry modifications harm your computer's security.

The Gunk IM-Worm.Win32.Sohanad.qr Drops

Computers infected by IM-Worm.Win32.Sohanad.qr will have serious security risks, whether these issues are readily apparent or not. IM-Worm.Win32.Sohanad.qr is capable of directly altering some system settings to lower your security, which IM-Worm.Win32.Sohanad.qr will do as a matter of course in the process of dropping malware onto the machine.

IM-Worm.Win32.Sohanad.qr's Trojan functionality enables it to download and run many different kinds of threats without notifying the computer's user. The IM-Worm.Win32.Sohanad.qr worm has even been reported to pair these malware executions with matching marketing advertisement! Here are just a few of the possibilities:

  • Rogue products that fake the appearance of popular anti-virus scanners. Such rogue anti-virus products will distract users with persistent and false errors, alerts, and scanner outputs.
  • Browser hijackers. This form of malware will redirect your browser to a dangerous site. In addition to being able to embed links in otherwise harmless content, hijackers can use error messages and other blocking techniques to keep you from accessing safe sites.
  • Spyware. Keyloggers are some of the most well-known of spyware, with the ability to record keyboard input with each button pressed. However, spyware can also search for passwords and other private information in files, and even record input from other devices such as microphones.
  • Botnet-enablers. This malware will make it easier for remote attackers to control your computer and utilize it for illegal DDoS attacks and other crimes.

IM-Worm.Win32.Sohanad.qr's dropping capabilities aren't limited to these options, but these should be considered the most likely additional threats. The drastic nature of its aggression towards system hostility indicates that one should delete IM-Worm.Win32.Sohanad.qr very quickly, before other complicating factors arise.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %PROGRAM_FILES%\IM-Worm.Win32.Sohanad.qr.
    2 %System%\setup.ini
    3 %System%\ssdata\lgstat.ini
    4 %Windir%\regsvr.exe
    5 %Windir%\Tasks\At1.job
    6 c:\Documents and Settings\All Users\IM-Worm.Win32.Sohanad.qr\
    7 c:\Documents and Settings\All Users\Start Menu\IM-Worm.Win32.Sohanad.qr\

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\SystemHKEY_LOCAL_MACHINE\Software\IM-Worm.Win32.Sohanad.qr[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...