Home Malware Programs Worms Worm:Win32/Neeris.AN

Worm:Win32/Neeris.AN

Posted: May 12, 2011

Worm.Win32.Neeris.AN is a malignant computerworm that replicates itself across local and network computers. Worm.Win32.Neeris.AN usually propagates via email attachments or instant messages. Worm:Win32/Neeris.AN installs itself secretly without any signs, such as setup window or dialog box. Worm.Win32.Neeris.AN makes changes to registry entries to conceal its existence from computer users. Worm.Win32.Neeris.AN adds a start-up entry to run automatically when you start up your computer. Remove Worm.Win32.Neeris.AN as soon as possible to protect your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Internet Explorer\iedw.exe
    2 %ProgramFiles%\MSN\MSNIA\msniasvc.exe
    3 %ProgramFiles%\MSN\MSNIA\prestp.exe
    4 %ProgramFiles%\MSN\MsnInstaller\msninst.exe
    5 %ProgramFiles%\Windows Media Player\wmplayer.exe
    6 %ProgramFiles%\Windows NT\Accessories\wordpad.exe
    7 %ProgramFiles%\Windows NT\dialer.exe
    8 %ProgramFiles%\Windows NT\hypertrm.exe
    9 %ProgramFiles%\Windows NT\Pinball\PINBALL.EXE
    10 %System%\csrsc.exe
    11 %Windir%\Temp\0001F008_Rar\csrsc.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SRServiceHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Streams DriversHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\System Bus ExtenderHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ ASC3360PRHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASC3360PR\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVERHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINSPOOLSVCHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINSPOOLSVC\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSpoolSvcHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSpoolSvc\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSpoolSvc\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3360pr\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3360pr\Security
Loading...