Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:Worm/VB.45056
Date discovered:18/06/2010
Type:Worm
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Low
Damage Potential:Low to medium
Static file:Yes
File size:45.056 Bytes
MD5 checksum:4bbf6141370db3ff468404f48f943b00
IVDF version:7.10.08.127 - Friday, June 18, 2010

 General Aliases:
   •  Sophos: Mal/VB-M
   •  Bitdefender: Trojan.Generic.3596858
   •  Panda: Trj/Scar.P
   •  Eset: Win32/VB.NXC


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Downloads a malicious file
   • Drops malicious files
   • Registry modification

 Files It copies itself to the following location:
   • %drive%\lsasss.exe




It tries to download a file:

The locations are the following:
   • http://59c268b3.lin**********.com
   • http://2085c5cc.lin**********.com
   • http://ba40ed9e.lin**********.com
   • http://5b51ba7f.lin**********.com
   • http://abd6ec9d.lin**********.com
   • http://e6230199.lin**********.com
   • http://d16fd297.lin**********.com
   • http://3cbc32f4.lin**********.com
   • http://08b18380.lin**********.com
   • http://532dfab3.lin**********.com




It tries to execute the following file:

Filename:
   • c:\lsasss.exe

 Registry The following registry key is added in order to run the process after reboot:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "lsasss"="c:\lsasss.exe"

 File details Programming language:
The malware program was written in Visual Basic.

Description inserted by Petre Galan on Thursday, September 23, 2010
Description updated by Petre Galan on Thursday, September 23, 2010

Back . . . .