Home Malware Programs Worms WORM_VOBFUS.RU

WORM_VOBFUS.RU

Posted: October 11, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 84
First Seen: October 11, 2012
OS(es) Affected: Windows

WORM_VOBFUS.RU is a worm that circulates via removable drives. WORM_VOBFUS.RU can also be downloaded from the Internet or distributed by other malware infections. WORM_VOBFUS.RU comes by connecting affected removable drives to a computer system. WORM_VOBFUS.RU is distributed to a vulnerable computer system as a file downloaded by other security threats or dropped unknowingly by computer users when visiting malicious websites. WORM_VOBFUS.RU downloads an autorun.inf file to automatically run the copies it downloads when a PC user accesses the drives of a targeted machine. When installed, WORM_VOBFUS.RU downloads the copies of itself in the form of the malevolent files in all removable drives of the victimized PC. WORM_VOBFUS.RU adds several registry entries so that it can load automatically every time you start Windows and access the drives. WORM_VOBFUS.RU also adds the specific registry entries as part of its installation routine. WORM_VOBFUS.RU modifies the specific registry entries to conceal files with Hidden attributes. WORM_VOBFUS.SMAC connects to the certain URLs to transfer and get commands from remote attackers.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%User Profile%\{RANDOM CHARACTERS}.exe File name: %User Profile%\{RANDOM CHARACTERS}.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
autorun.inf File name: autorun.inf
Mime Type: unknown/inf
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedShowSuperHidden = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUNoAutoUpdate = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run {RANDOM CHARACTERS} = "%User Profile%\{RANDOM CHARACTERS}.exe /{RANDOM CHARACTERS}"
Loading...