WORM.WBNA.AOT
Name:
Worm.WBNA.aot
Added:
July 29, 2011
Type:
Worm
Risk:
Low
Payload:
N/A
At risk systems:
Windows 95/98/ME/XP/NT/2003
Description:
When Worm.WBNA.aot is executed, it performs the following activities:After execution, it drops the following files:%Appdata%\LocalAccountAuthority.bat%Appdata%\lssas.exeIt creates/modifies the following registry entries:Use FormSuggest = "yes"HKLM\SOFTWARE\Microsoft\Internet Explorer\MainLocal Account Service = "%Appdata%\lssas.exe"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Runf6h45yhjqapath = "%Appdata%\"HKLM\SOFTWARE\f6h45yhjqaImagePath = "%Appdata%\LocalAccountAuthority.bat"HKLM\SYSTEM\ControlSet001\Services\Local Account Authority ServiceList\%Appdata%\lssas.exe = "%Appdata%\lssas.exe :* :Enabled =lssas.exe"HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicyStandardProfile\AuthorizedApplicationsImagePath = "%Appdata%\LocalAccountAuthority.bat"HKLM\SYSTEM\CurrentControlSet\Services\Local Account Authority Servicewin = "%Appdata%\lssas.exe"HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Windowsinit = "%Appdata%\lssas.exe"HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Windowswin = "%Appdata%\lssas.exe"HKU\Software\Microsoft\Windows NT\CurrentVersion\Windowsinit = "%Appdata%\lssas.exe"HKU\Software\Microsoft\Windows NT\CurrentVersion\Windowswin = "%Appdata%\lssas.exe"HKU\Software\Microsoft\Windows NT\CurrentVersion\Windowsinit = "%Appdata%\lssas.exe"HKU\Software\Microsoft\Windows NT\CurrentVersion\Windowslssas.exe runs every time Windows starts
Malware problems?We can help.
Evaluate Thirtyseven4 Antivirus Now
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4