WORM.KOLAB.BDE
Name:
Worm.Kolab.bde
Added:
November 25, 2011
Type:
Worm
Risk:
Low
Payload:
N/A
At risk systems:
Windows 95/98/ME/XP/NT/2003
Malware problems? We can help. Free Removal Tools.
Description:
When Worm.Kolab.bde is executed, it performs the following activities:After execution, it drops the following files:%System%\ap%System%\Install.exe%System%\sms.exe%System%\sv.exe%System%\vbzip10.dll%Rootdrive%\tinkoIt modifies/creates the following registry entries:winupdate = "%System%\sv.exe"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Runsms: "%System%\sms.exe"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Runwinupdate: "%System%\sv.exe"HKU\Software\Microsoft\Windows\CurrentVersion\Runsms: "%System%\sms.exe"HKU\Software\Microsoft\Windows\CurrentVersion\RunThe Worm.Kolab.bde spreads Via Removable Drives and shared drives by dropping the files:%RemovableDrive%Autorun.inf%RemovableDrive%install.exeIt may connect to the domain using 8080 portns2.tXXXuisness.co
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4