Home Malware Programs Worms Win32/Lefgroo

Win32/Lefgroo

Posted: January 9, 2013

Threat Metric

Threat Level: 5/10
Infected PCs: 91
First Seen: January 9, 2013
OS(es) Affected: Windows

Win32/Lefgroo is a worm that copies itself to removable and network drives, and displays messages. Once installed on the corrupted PC, Win32/Lefgroo makes system changes by dropping potentially malicious files and modifying the Windows Registry. Win32/Lefgroo also creates a registry entry to assure that it loads automatically each time you start Windows. Win32/Lefgroo may also open websites in a full-screen browser window. Win32/Lefgroo may modify the registry entries in an attempt to help remain on the computer system, and help to deliver its payload. Win32/Lefgroo removes the Folder Options item from all Explorer menus and the Control Panel and modifies Internet Explorer settings by modifying the Windows Registry. Win32/Lefgroo disables the system tool Task Manager by making modifications to the Windows Registry.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



[Drive]:\musica.exe File name: [Drive]:\musica.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%windir%\profile\services.exe File name: %windir%\profile\services.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%windir%\profile\susoft.exe File name: %windir%\profile\susoft.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "FullScreen" = "yes"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoFolderOptions" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "HTML" = "%windir%\profile\services.exe"
Loading...