Ha bisogno di assistenza? Chieda alla community oppure consulti un esperto.
Vai ad Avira Answers
Date discovered:14/08/2013
In the wild:No
Reported Infections:Medium
Distribution Potential:Low
Damage Potential:Low
Static file:No
VDF version:
IVDF version:

 General Method of propagation:
   • No own spreading routine

   •  Eset: VBS/Agent.NDE.worm

Platforms / OS:
   • Windows XP
   • Windows 2003
   • Windows Vista
   • Windows Server 2008
   • Windows 7

Side effects:
   • Can be used to execute malicious code
   • Downloads a malicious file

 Registry One of the following values is added in order to run the process after reboot:

–  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "sample"=""wscript.exe //B "%appdata%\sample.vbs"""

 Miscellaneous Internet connection:
In order to check for its internet connection the following DNS server is contacted:
   • penter**********.no-ip.biz

 File details Programming language:
The malware program was written in Visual Basic.

Descrizione inserita da Soe-liang Tan su venerdì 16 agosto 2013
Descrizione aggiornata da Wensin Lee su venerdì 16 agosto 2013

Indietro . . . .