Home Malware Programs Worms Secefa

Secefa

Posted: March 28, 2006

Secefa is a dangerous and complex Internet worm, which spreads to vulnerable PCs running Microsoft Windows operating computer with unpatched security flaws. It exploits certain vulnerabilities and does not require any user interaction.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 dodrrr.exe
    2 ftp.scr
    3 msdef.exe
    4 mstempf.exe
    5 qwe.bat
    6 services.exe
    7 ws3lib.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesDisableRegistryTools=0x0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesDisableRegistryTools=0x0HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyStandardProfile\EnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicy\EnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileAuthorizedApplicationsListservices.exe=services.exe:*:enabled:services.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicy\EnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4pcser32g

Related Posts

Loading...