Home Malware Programs Worms Secefa.b

Secefa.b

Posted: March 28, 2006

Secefa.b is a dangerous and complex Internet worm, which spreads to vulnerable PCs running Microsoft Windows operating computer with unpatched security flaws. It automatically exploits certain vulnerabilities and does not require any user interaction.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ft54.scr
    2 msdef.exe
    3 mstempf.exe
    4 qwe.bat
    5 services.exe
    6 upx.exe
    7 ws1lib.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExploreriepgfsgdcHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerjkdfeflkHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorermsrewfdarhHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyDomainProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyDomainProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4pcser32g
Loading...