Home Malware Programs Worms W32.Jonbarr.D

W32.Jonbarr.D

Posted: March 28, 2006

W32.Jonbarr.D@mm, which is a variant of the W32.Jonbarr@mm worm, is a worm that uses its own SMTP engine to send itself to all the email addresses it finds in the .htm files and in temporary Internet files. Besides, the worm attempts to kill the processes of many antivirus applications.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:DeletethevalueNero.ma=%SystemRoot%system[twoorthreerandomdigits].exeHKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun
Loading...