Home Malware Programs Worms Lehs

Lehs

Posted: March 28, 2006

Lehs is a dangerous Internet worm with a devastating payload. It spreads by e-mail in messages with infected executable attachments. These messages look like Microsoft support letters providing a patch for certain Windows vulnerabilities.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 backup.exe
    2 bin.exe
    3 dage.exe
    4 gadeth.exe
    5 kern16.exe
    6 kernel32.exe
    7 microcorp.exe
    8 micropackage.exe
    9 msdos_3.bat
    10 msiinstall.exe
    11 msishell.exe
    12 mtk.exe
    13 ndad.exe
    14 notepad.exe
    15 patch.exe
    16 patch[X].exe
    17 reinstall.exe
    18 restoreshell.exe
    19 shell.exe
    20 splinter.exe
    21 win-16_bit.exe
    22 wincom.exe
    23 windows.exe
Loading...