Home Malware Programs Worms Worm.Nayrabot.gen!A

Worm.Nayrabot.gen!A

Posted: May 24, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 37
First Seen: December 5, 2011
OS(es) Affected: Windows

Worm.Nayrabot.gen!A is a worm that affects Windows PCs and can invade the targeted system secretly. Worm.Nayrabot.gen!A can steal personal information without having administrative authorizations. Worm.Nayrabot.gen!A is distributed via encrypted downloads or setups in malicious spam email attachments. Worm.Nayrabot.gen!A might be very difficult to detect and remove from the corrupted PC system, because the Trojan does not have an interface, and is composed of such files, which help disguise its malicious components from extermination. Worm.Nayrabot.gen!A can be covered with the rootkit technique; its files are know to change their structures, and various other Trojan's attributes help it remain protected from deletion. Worm.Nayrabot.gen!A can cause serious Windows breakdows, as well as such illegitimate interruptions as IRC connections, downloads or modification of Windows Registry entries. Worm.Nayrabot.gen!A can monitor browsing activities, copy inputs, add/delete and even corrupt processes. Worm.Nayrabot.gen!A can easily establish a connection to a remote server, copy information on keyboard inputs and virus scanners, and send spam emails, using your email and contact book details.

Aliases

BackDoor.IRC.Aryan.1 [DrWeb]UnclassifiedMalware [Comodo]Worm.Win32.Ngrbot.lof [Kaspersky]Trojan [K7AntiVirus]Worm.Nayrabot.A4 [CAT-QuickHeal]Suspicious.Cloud.5 [Symantec]FakeAlert-Rena.am [McAfee]BackDoor.Gbot.1851 [DrWeb]Gen:Variant.Kazy.46520 [BitDefender]Win32:Gbot-T [GData]Mal/FakeAV-IS [Sophos]TR/Crypt.EPACK.Gen2 [AntiVir]Win32:Gbot-T [Trj] [Avast]Suspicious file [Panda]Generic26.OVW [AVG]
More aliases (62)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\E86D4\lvvm.exe File name: lvvm.exe
Size: 189.44 KB (189440 bytes)
MD5: a6eecf497f629b0671dd4ac8d4f70b6b
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\E86D4
Group: Malware file
Last Updated: December 6, 2011
%USERPROFILE%\Local Settings\Application Data\bne.exe File name: bne.exe
Size: 259.58 KB (259584 bytes)
MD5: 8705ff620aaab0a2352eac9bc4081e60
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 8, 2011
%APPDATA%\7E079\lvvm.exe File name: lvvm.exe
Size: 189.44 KB (189440 bytes)
MD5: f587c577bc8b0f1bf21c96b5847d4c58
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\7E079
Group: Malware file
Last Updated: December 7, 2011
%APPDATA%\4423.exe File name: 4423.exe
Size: 39.42 KB (39424 bytes)
MD5: 188ad70b8d3a2b47e88ab22859978877
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: October 15, 2012
Loading...