WORM_RONTOKBRO.K |
|
| BugsAlert Home > WORM_RONTOKBRO.K | |
|
Similar to other variants of WORM_RONTOKBRO, this worm propagates as an attachment to email messages. It sends to itself to email addresses it harvests from local drives of an affected system. The email message it sends out has the following details:
Subject: (blank) Upon execution, it drops a copy of itself using different file names in different locations. The file name it uses and the folder where it drops a copy of itself varies depending on the operating system of the affected machine. It removes the Folder Options, and disables the Registry Editor and command prompt. It also hides files and file extension names. It does the said actions by modifying the affected system's registry. It uses the Windows folder icon to trick users into thinking that this is a valid folder. It also opens the Windows Explorer folder upon execution to hide its malicious routines. In addition, this worm restarts the system when it detects certain strings in an active window's title bar. Furthermore, it launches PING attacks against certain Web sites. Original Source: http://feeds.trendmicro.com/~r/MalwareTop10/~3/376279618/default5.asp Learn more about WORM_RONTOKBRO.K |
|
| Tags: worm rontokbro.k | |
Related Items |
|
|
CVE-2008-3472 (internet_explorer)
|
|
|
CVE-2008-2686 (flux_cms)
|
|
|
CVE-2007-6295 (Lotus Sametime)
|
|
|
Fedora update for postfix
|
|
|
FrSIRT - Apple iPhone Code Execution and Security Bypass Vulnerabilities
|
|
|
PHP-NUKE SQL Modules Name 4ndvddb
|
|
|
Ubuntu: Firefox vulnerabilities
|
|