Main Menu
Home
Bookmark
Contact Us



 
Worm.Win32.Lemoor. Viruses Information

Name: Worm.Win32.Lemoor.
Category: Viruses
Description: Details
Worm.Win32.Lemoor.a

This worm spreads via the Internet, propagating via a vulnerability in the FTP server of Worm.Win32.Sasser.
Only computers which have already been infected by Sasser are vulnerable to Lemoor.
Lemoor is written in Assembler, and is packed using FSG. The packed file is 1985 bytes in size, and the unpacked file is approximately 20992 bytes in size.
Installation
When lanuching, the worm registers itself in the sytem registry, to ensure that it is run each time the system is launched:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
[Ephemeral 2.4] by TreeHugger, =
Propagation
The worm sends a broadcast quest and waits for responses from machines infected by Sasser.
When it receives an answer from a victim machine, it utilizes a vulnerability in the FTP server installed by Sasser to launch its command shell on a randomly chosen port. It then sends its body to the victim machine and launches it.
Other
The worm is only programmed to propagate: it does not have any other payload.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
I-Worm.NetSky.
RMNS.MW.Man.29
Win32.Cham
Win95_Sot
Goblin.175
PZ Famil
Zoom.26
Quox.
Nr.30
Brackets.136


 


© 2006-2008 spyware32.com - Privacy Policy