Home Malware Programs Worms Worm.Ludbaruma

Worm.Ludbaruma

Posted: August 7, 2016

Threat Metric

Threat Level: 5/10
Infected PCs: 84
First Seen: August 7, 2016
Last Seen: June 10, 2021
OS(es) Affected: Windows

Technical Details

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%HOMEDRIVE%\Data user.exe%HOMEDRIVE%\xk.exe%LOCALAPPDATA%\WINDOWS\csrss.exe%LOCALAPPDATA%\WINDOWS\lsass.exe%LOCALAPPDATA%\WINDOWS\SERVICES.EXE%LOCALAPPDATA%\WINDOWS\smss.exe%LOCALAPPDATA%\WINDOWS\winlogon.exe%USERPROFILE%\Local Settings\Application Data\WINDOWS\csrss.exe%USERPROFILE%\Local Settings\Application Data\WINDOWS\lsass.exe%USERPROFILE%\Local Settings\Application Data\WINDOWS\SERVICES.EXE%USERPROFILE%\Local Settings\Application Data\WINDOWS\winlogon.exe%WINDIR%\xk.exe

Additional Information

The following directories were created:
%HOMEDRIVE%\XK
Loading...