Sophos

W32/LimpNet-A

Aliases
  • Worm.Win32.VB.br
  • Win32/VB.BR
  • worm
  • W32.SillyFDC
  • WORM_SILLYFDC.O
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2007 (4.18)
Protection available since 12 July 2006 08:56:47 (GMT)
Last updated 13 April 2007 01:42:27 (GMT)
Detected by All Sophos products

Action

More Information

W32/LimpNet-A is a worm for the Windows platform.

When first run W32/LimpNet-A copies itself to:

<Startup>\plus.exe
<Windows>\orawin.exe W32/LimpNet-A is a worm for the Windows platform.

When first run W32/LimpNet-A copies itself to:

<Startup>\plus.exe
<Windows>\orawin.exe

The following registry entry is created to run orawin.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HP_spooler
<Windows>\orawin.exe

W32/LimpNet-A will attempt to copy itself to floppy disk as save documents_zip.exe and will also create the file log.tmp. W32/LimpNet-A

will also attempt to copy itself to the following drives:

D:\Morales_vs_PAcquiao.txt<lots of spaces>.exe
E:\Pacquiao_history.txt<lots of spaces>.exe
F:\Morales.txt<lots of spaces>.exe
G:\Pacquiao_history.txt<lots of spaces>.exe
H:\Pacquiao_history.txt<lots of spaces>.exe
I:\Pacquiao_history.txt<lots of spaces>.exe
J:\Pacquiao_history.txt<lots of spaces>.exe
K:\Pacquiao_history.txt<lots of spaces>.exe
L:\Pacquiao_history.txt<lots of spaces>.exe
M:\Pacquiao_history.txt<lots of spaces>.exe
N:\Pacquiao_history.txt<lots of spaces>.exe
O:\Pacquiao_history.txt<lots of spaces>.exe
P:\Pacquiao_history.txt<lots of spaces>.exe
Q:\Pacquiao_history.txt<lots of spaces>.exe
R:\Pacquiao_history.txt<lots of spaces>.exe
S:\Pacquiao_history.txt<lots of spaces>.exe

W32/LimpNet-A will also attempt to copy itself to network shares by scanning a network in the IP range of 192.168.xxx.xxx (where x represents a number from 0 to 255). W32/LimpNet-A creates the file C:\<Windows>\ora1.tmp which contains the output from the windows ping utility.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer