| |
Added by WORM_SDBOT.Q (PE-PACK,VC++). Delete it ASAP.
This virus adds a few items in the startup registry : HKLM\Software\Microsoft\Windows\CurrentVersion\Run "MS Configuration"="%SYSDIR%\MSFramer.exe" HKCU\Software\Microsoft\Windows\CurrentVersion\Run "MS Configuration"="%SYSDIR%\MSFramer.exe" HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "MS Configuration"="%SYSDIR%\MSFramer.exe"
It will try to login intranet with follow passwords: "passWord" "passwd" "pass" "pwd" "password1" "pass1234" "administrator" "admin" "adm" "1" "12" "123" "1234" "12346" "123467" "1234678" "12346789" "123467890" "121" "007" "test" "guest" "none" "changeme" "default" "system" "server" "null" "qwerty" "teacher" "staff" "oeminstall"
Default path: C:\WINNT\system32\MSFramer.exe (%SYSDIR%\MSFramer.exe) |
|