Home Malware Programs Worms Net-Worm.Win32.Kolab.hit

Net-Worm.Win32.Kolab.hit

Posted: August 20, 2010

Net-Worm.Win32.Kolab.hit is a worm that attempts to propagate by exploiting local network shares. Net-Worm.Win32.Kolab.hit will also attempt to join a predefined IRC server and channel in order to allow hackers to participate in dangerous distributed denial-of-service attacks (DDoS). DDoS attaks are an attempt by hackers to make a computer resource unavailable to its intended users. Net-Worm.Win32.Kolab.hit poses a severe security threat to any PC and should be removed upon detection.

Aliases

VirTool:Win32/VBInject.gen!DU (Microsoft)
Trojan-Dropper.Win32.VB (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\Bifrost\logg.dat
    2 %System%\Bifrost\Server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}]
Loading...