Home Malware Programs Worms Kiman

Kiman

Posted: March 28, 2006

Kiman is a dangerous and complex Internet worm, which spreads via network shares protected by weak passwords or by exploiting known computer security vulnerabilities. The computer can be infected without any user interaction.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 1.reg
    2 a.bat
    3 dnsresolver.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftOLEDomainNameResolveServiceHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsMaxConnectionsPer1_0Server=50HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternetSettingsMaxConnectionsPerServer=50HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunDomainNameResolveServiceHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunServicesDomainNameResolveServiceHKEY_LOCAL_MACHINESOFTWAREMicrosoftOLEDomainNameResolveServiceHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunDomainNameResolveServiceHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesDomainNameResolveServiceHKEY_LOCAL_MACHINESYSTEMControlSet001ServiceswscsvcStart=4HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceswuauservStart=4HKEY_LOCAL_MACHINESoftwareMicrosoftOLEEnableDCOM=n

Related Posts

Loading...