WORM_GRIDER.B |
|
| BugsAlert Home > WORM_GRIDER.B | |
|
This worm may be dropped by other malware. It may arrive via network shares. It may be installed manually by a user. It may be downloaded unknowingly by a user when visiting malicious Web sites. It floods the current folder using copies of a certain non-malicious file. It creates registry entries to enable its automatic execution at every system startup. This worm propagates by dropping a copy of itself into all folders, as well shared folders, and mapped drives. It uses the name of the current folder name as the file name of its dropped copies. As a result, it may replace normal files with a copy of itself if these normal files also use the folder name in their file names. It then searches for certain files in the current folder, which it uses in order to run properly. These files are non-malicious and are used in MS Visual Basic applications to add the functionality of socket programming. It opens a random port to allow a remote user to connect to the affected system. Once a successful connection is established, the remote user executes commands on the affected system. The said routine effectively compromises the affected system's security. It connects to Web sites. Original Source: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_GRIDER.B Learn more about WORM_GRIDER.B |
|
| Tags: worm grider.b | |
Related Items |
|
|
Trojan Downloader.Agent.UZM
|
|
|
Website Directory - XSS Exploit
|
|
|
CVE-2008-2872 (shibby_shop)
|
|
|
CVE-2008-4740 (tinycms)
|
|
|
Vuln: Mozilla Firefox CSSValue Array Data Structure Remote Code Execution Vulnerability
|
|
|
VU#888209:Liferay Portal Forgot Password User-Agent HTTP header XSS
|
|
|
CVE-2008-0701 (CE)
|
|