Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

WORM_RONTOKBRO.R

BugsAlert Home > WORM_RONTOKBRO.R
 
 

This worm spreads as an attachment to email messages. The email message it sends out has the following details:

Subject: (blank)

Attachment: (any of the following)

• CINTA.EXE
• DATA-TEMEN.EXE
• HATI.EXE
• JANGKARU.EXE
• KANGEN.EXE
• PATAH.EXE
• RIYANI.EXE
• UNTUKMU.EXE

It gathers target email addresses by searching for files with certain extensions.

Upon execution, this memory-resident worm drops copies of itself in different folders using different file names. It uses a Windows folder icon to trick users into thinking that it is a valid folder.

It modifies the affected system's registry to disable services such as command prompt, Registry Editor, and removal of the Folder Options from the drop-down menu of Windows Explorer. It also hides files and extension names.

On Windows ME systems, this worm causes the affected system to pause during startup.

It also restarts the affected system upon detection of an active window containing certain strings on the title bar.




Original Source: http://feeds.trendmicro.com/~r/MalwareTop10/~3/196873350/default5.asp

Learn more about WORM_RONTOKBRO.R
 
Tags: worm rontokbro.r

Related Items

      my wsdl is not loaded correctly

      Vuln: OpenSSL SSLv3 Session ID Buffer Overflow Vulnerability

      CVE-2008-3923 (cmme)

      Avaya CMS Solaris Print Service Unspecified Vulnerabilities

      Mandriva Security Update Fixes MadWifi Remote Denial of Service Issue

      TalkBack 2.3.5 (language) Local File Inclusion Vulnerability

      FrSIRT - Move Media Player "UploadLogs()" Remote Buffer Overflow Vulnerability

 

Pixel