Home Malware Programs Worms Secefa.c

Secefa.c

Posted: March 28, 2006

Secefa.c is a dangerous and complex Internet worm, which spreads to vulnerable PCs running Microsoft Windows operating computer with unpatched security flaws. It automatically exploits certain vulnerabilities and does not require any user interaction.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ft3.scr
    2 ft4.scr
    3 ft54.scr
    4 msdef.exe
    5 mstempf.exe
    6 qwe1.bat
    7 qwe2.bat
    8 qwe3.bat
    9 qwe4.bat
    10 services.exe
    11 up2.exe
    12 ws1lib.exe
    13 ws2lib.exe
    14 ws3lib.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}AuthorizedApplicationsList\%Windir%services.exeHKEY_CURRENT_USERSoftwareMicrosoftInternetExploreriepgfsgdcHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerjkdfeflkHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorermsrewfdarhHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyDomainProfileHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyDomainProfileHKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMControlSet002ServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList\%Windir%services.exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4pcser32g
Loading...