Worm:Win32/Krepper.B (Microsoft); W32/Sndc.worm!p2p (McAfee); W32.IRCBot (Symantec); P2P-Worm.Win32.Krepper.c (Kaspersky); W32/Ircbot-X (Sophos); Trojan.Win32.Ircbot!cobra (v) (Sunbelt)
Windows
This Worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Arrival Details
This Worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Worm adds the following processes:
(Note: %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)
It creates the following folders:
(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.. %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.. %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)
Other System Modifications
This Worm modifies the following file(s):
(Note: %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)
It deletes the following files:
(Note: %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)
It adds the following registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\RunServices
It adds the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Run
WinProfile = "sndcfg16.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
RunServices
WinProfile = "sndcfg16.exe"
Dropping Routine
This Worm drops the following files: