Home Malware Programs Worms Lerma

Lerma

Posted: March 28, 2006

Lerma is a destructive Internet worm that spreads by e-mail and through unprotected network shares. The spyware is designed to overwrite all archives, images, screensavers, web pages, documents, multimedia and computer files it finds on a compromised PC with executable copies of itself. As a result the user can lose valuable personal information. Lerma automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 csrss.exe
    2 ermasys32.exe
    3 kernel32.exe
    4 lasiaf.exe
    5 mode.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunLasErmaHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesLasErma
Loading...