%SysDir%\Jdbgmgr.exe |
| Name |
%SysDir%\Jdbgmgr.exe |
Description
|
%Startup%\ShockWave.exe (or FlasMovie) is W32.HLLW.Dormin.A@mm mass mailing worm. When ShockWave.exe worm runs, it displays the fake error message, "MacroMedia Shockwave Flash is not installed!" Copies itself as the following files: * %Startup%\ShockWave.exe * %System%\FlashMovie.exe * %System%\Jdbgmgr.exe * %mIRC%\FlashMovie.ex_ * %Pirch32%\FlashMovie.ex_ * %KaZaA%\Virtual Sex Simulator.exe * %KaZaA%\Shockwave Flash.exe * %KaZaA%\SWF_Movie.exe * %KaZaA%\FlashMovie.exe * %KaZaA%\XXX video.exe * %KaZaA%\Cat attacks child.exe * %KaZaA%\SWF.exe * %KaZaA%\Comedy video.exe * %KaZaA%\Simpsons Episode (#[Number calculated from current time]).exe * %KaZaA%\Tutorial Video on Hacking.exe * %KaZaA%\MacroMedia Flash 6.0.exe * %KaZaA%\[SWF] - The Fast and the Furious.exe * %KaZaA%\[SWF] - Swordfish.exe * %KaZaA%\[SWF] - Harry Potter and the philosophers stone.exe * %KaZaA%\[SWF] - Jurassic Park 3.exe Adds the registry values: Nimrod_Keyboard Rundll32.exe Keyboard,Disable Nimrod_Mouse Rundll32.exe Mouse,Disable to teh key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ RunServices to disable the mouse and keyboard when you start Windows. It works with Windows 9X/Me only. ShockWave sends e-mails with attachment FlashMovie.exe. |
|
|
|
|