Home Malware Programs Worms Net-Worm.Randex.B!rem

Net-Worm.Randex.B!rem

Posted: June 9, 2010

Net-Worm.Randex.B!rem is a network-aware computer worm that uses system exploits to replicate across vulnerable networks. Net-Worm.Randex.B!rem opens a conduit to welcome a host of malware onto the infected system. Net-Worm.Randex.B!rem poses a serious threat to PC security and can cause loss of sensitive data or other faults such as slow system performance. Victims are advised to use a reliable security application to terminate Net-Worm.Randex.B!rem immediately.

Aliases

Net-Worm.Win32.Kolab.gqr [Kaspersky Lab]
W32/Sdbot.worm!ht [McAfee]
Mal/Behav-104
Mal/Behav-004
Mal/Behav-024
Mal/Emogen-R
Mal/TinyDL-T (Sophos)
Win32/IRCBot.worm.Gen (AhnLab)
Packed with PE_Patch.PECompact (Kaspersky Lab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %FontsDir%\unwise_.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...