Sophos

W32/LCJump-B

Aliases
  • Win32/RJump.F
  • WORM_AGENT.AAIN
  • W32/DKR.worm
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from December 2007 (4.24)
Protection available since 12 October 2007 01:33:07 (GMT)
Detected by All Sophos products

Action

More Information

W32/LCJump-B is a worm for the Windows platform.

W32/LCJump-B attempts to copy itself to mapped drives with the filename RavMon.exe and create a file autorun.inf which will attempt to load the worm automatically when the infected drive is accessed.

W32/LCJump-B is a worm for the Windows platform.

W32/LCJump-B attempts to copy itself to mapped drives with the filename RavMon.exe and create a file autorun.inf which will attempt to load the worm automatically when the infected drive is accessed.

W32/LCJump-B also creates a backdoor, enabling a remote user control over the infected computer.

When run, W32/LCJump-B copies itself to <Windows>\SVCHOST.EXE and creates the file <Windows>\MDM.exe. The file MDM.exe is detected as Troj/Bckdr-PXR.

The following registry entries are set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SVCHOST
<Windows>\MDM.EXE

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
0

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer