Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

WORM.WBNA.AOT

 

 

 

Name:

Worm.WBNA.aot

Added:

July 29, 2011

Type:

Worm

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Description:

 

When Worm.WBNA.aot is executed, it performs the following activities:

After execution, it drops the following files:

%Appdata%\LocalAccountAuthority.bat
%Appdata%\lssas.exe

It creates/modifies the following registry entries:

Use FormSuggest = "yes"
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main

Local Account Service = "%Appdata%\lssas.exe"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

f6h45yhjqapath = "%Appdata%\"
HKLM\SOFTWARE\f6h45yhjqa

ImagePath = "%Appdata%\LocalAccountAuthority.bat"
HKLM\SYSTEM\ControlSet001\Services\Local Account Authority Service

List\%Appdata%\lssas.exe = "%Appdata%\lssas.exe :* :Enabled =lssas.exe"
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Firewal
lPolicy
StandardProfile\AuthorizedApplications

ImagePath = "%Appdata%\LocalAccountAuthority.bat"
HKLM\SYSTEM\CurrentControlSet\Services\Local Account Authority Service

win = "%Appdata%\lssas.exe"
HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Windows

init = "%Appdata%\lssas.exe"
HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Windows

win = "%Appdata%\lssas.exe"
HKU\Software\Microsoft\Windows NT\CurrentVersion\Windows

init = "%Appdata%\lssas.exe"
HKU\Software\Microsoft\Windows NT\CurrentVersion\Windows

win = "%Appdata%\lssas.exe"
HKU\Software\Microsoft\Windows NT\CurrentVersion\Windows

init = "%Appdata%\lssas.exe"
HKU\Software\Microsoft\Windows NT\CurrentVersion\Windows

lssas.exe runs every time Windows starts
 

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Malware problems?
We can help.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Evaluate Thirtyseven4 Antivirus Now

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4