Home Malware Programs Worms Net-Worm.Win32.Kolabc.icb

Net-Worm.Win32.Kolabc.icb

Posted: August 18, 2010

Net-Worm.Win32.Kolabc.icb is a network-aware worm that uses known exploits to replicate across vulnerable networks. Net-Worm.Win32.Kolabc.icb may also open a conduit to welcome a host of malware onto the infected system. Net-Worm.Win32.Kolabc.icb poses a serious threat to PC security and can cause loss of sensitive data or other faults such as slow system performance. Victims are advised to use a reliable security application to terminate Net-Worm.Win32.Kolabc.icb immediately.

Aliases

Net-Worm.Win32.Kolabc (Ikarus)
Win32/Kolabc.worm.140430.D (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %FontsDir%\unwise_.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...