Home Malware Programs Worms Worm.Slimbraju.A

Worm.Slimbraju.A

Posted: June 23, 2011

Worm.Slimbraju.A is a worm that runs without your permission, uses removable devices to infect new computers, ignores your firewall and can alter your file-viewing settings to conceal files. These features cause no direct harm to your PC but can be used by Worm.Slimbraju.A. Worm.Slimbraju.A can cause serious harm by disabling your security measures. Around removable devices, you should exercise caution to avoid being infected by Worm.Slimbraju.A. Since Worm.Slimbraju.A, like all worms, can create multiple copies of itself, you should delete Worm.Slimbraju.A by using an anti-malware program that can detect and remove Worm.Slimbraju.A, regardless of how many copies are spawned.

Where Worm.Slimbraju.A Comes from and How It Infects Your PC

Worm.Slimbraju.A is a recent worm that was confirmed to be a threat in 2011, and updates to threat definition files for your anti-virus software may be required to detect a Worm.Slimbraju.A infection. You may also see Worm.Slimbraju.A identified by the alternate name of TROJ_MEREDROP.PG. Although Worm.Slimbraju.A has limited functions that don't cause serious harm to your PC in their initial attacks, Worm.Slimbraju.A is classified as a severe threat because of how effectively Worm.Slimbraju.A's functions disarm your PC security.

The easiest place to get a Worm.Slimbraju.A infection from is a removable storage device such as a CD, flash drive or USB thumb drive. Worm.Slimbraju.A will copy Worm.Slimbraju.A's 'start.exe' file to all removable drives like the devices noted above, in addition to copying an Autorun.inf file. Autorun.inf files are text configuration files that can be benevolent, but Worm.Slimbraju.A abuses them to install itself automatically on any computer that opens an infected device.

Worm.Slimbraju.A, like many other PC threats, also corrupts the Windows Registry to guarantee that Worm.Slimbraju.A will run when Windows starts. You should assume that Worm.Slimbraju.A is active if your computer is infected, even if you don't see any signs of Worm.Slimbraju.A being open.

The Extra Stealth Tricks in the Worm.Slimbraju.A Repertoire

Worm.Slimbraju.A has shown two primary attacks, but remote hosts may configure Worm.Slimbraju.A for other ones to take advantage of initial vulnerabilities in your PC:

  • A Worm.Slimbraju.A infection can create an exception for itself in your firewall, once again, by abusing the Registry. This lets Worm.Slimbraju.A send information to or accept information from remote criminals without disabling your firewall. This behavior is often used to conduct remote attacks that can harm your PC in many ways. Common remote attacks include the installation of keyloggers or rogue security software and forcing your computer to participate in DDoS crimes.
  • Another and more unusual attack that Worm.Slimbraju.A has up Worm.Slimbraju's sleeve is the ability to prevent you from seeing files that have the Hidden or System attributes. This goes deeper than changing your file-viewing settings and will prevent you from using file-viewing options to see such files. Since most worms like Worm.Slimbraju.A will use these attributes for their own files this attack lets Worm.Slimbraju.A conceal itself flawlessly. As with Worm.Slimbraju.A's other attacks, this function uses the Windows Registry.

Malicious Registry entries like the ones that are used by Worm.Slimbraju.A should be attended to by an anti-virus or security program whenever possible. If you attempt to delete Worm.Slimbraju.A manually you may cause other undesirable problems for your PC.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 078.dll
    2 39837432.exe
    3 5tw_KTDN4-HL.dll
    4 EBSetup.exe
    5 GbPBye.sys
    6 GVR.exe
    7 Heart Bubbles.scr
    8 lokdefiancesetup-dm.exe
    9 mkvxl.dll
    10 MWSBAR.DLL
    11 peload3E.dll
    12 performsizm.exe
    13 PERVACNT.EXE
    14 queryscan117.exe
    15 ra71789.dll
    16 Recycle.Bin.exe
    17 resulttool137.exe
    18 scanquery.dll
    19 SeaPort.exe
    20 setup.exe
    21 SRO_Client.exe
    22 Srv.exe
    23 SteelID.exe
    24 SubsHelperBHO.dll
    25 svc2dll.exe
    26 winlogin.exe
    27 winntse.bin.exe
    28 YahooAUService.exe
Loading...