Search:       

Saturday, 11 October 2008       

Worm.Win32.Slute Spyware/Adware Definition


Name: Worm.Win32.Slute
Category: Viruses
Description: Details
Worm.Win32.Sluter
Sluter is a worm virus that spreads over Win32 networks through shared resources.
The worm is a Windows PE EXE file about 18KB in length (when compressed by UPX, the decompressed size is about 45KB). It is written in Microsoft Visual C++.
When the infected file is run the worm registers itself in the system registry auto-run key:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
superslut = { worm file name }

Next, Sluter runs its spreading routines.
The spreading routine runs up to 60 "threads" which scan port 445 at random IP addresses. When successfully connecting to a victim machine it tries to locate open resources on the remote computer and connects to them using several passwords such as:
"","admin", "root", "123", e.t.c.

If a successful connection is made the worm copies itself to the victim machine under the following names:
c$winntsystem32msslut32.exe
Admin$system32msslut32.exe

The worm then uses the WinNT remote management API to run an infected file on the remote machine.
The worm doesn't have any payload and does not manifest itself in any other way.


Top Viruses Visited Pages:
Parity.44
Pathhunt.123
Perfume Famil
Permutan.54
Phantasmagori
Pieck.201
Ply.422
PME.Burglar.326
Polifemo Famil
Populizer Famil
Potpis.69
Predator.115
PrintDevil.71
Priv.193
Quake.960.

 


Main Menu
Home
Top Downloads
New Programs
Awards
Submit
Link to us
Spyware Definitions
Viruses Info
Recipes
Jokes
Contact us




 

 

- Privacy Policy -