Home / malwarePDF  

Lager.DP


First posted on 01 March 2007.
Source: SecurityHome

Aliases :

Lager.DP is also known as Email-Worm.Win32.Zhelatin.a, Trojan-Proxy.Win32.Lager.dp, W32/Stormy, Email-Worm.Win32.Banwarum.l, Trojan-Downloader.Win32.Small.ciw.

Explanation :

Lager.DP is a mass mailing worm that drops a copy of Small.DAM.

Lager.DP arrives on the system as an attachment to spam e-mails.

When executed, Lager.DP drops a copy of itself named "alsys.exe" in the Windows system directory.

It also drops several files in various locations on the system using a random eight character filename.


In addition to this, it drops and executes a randomly named copy of Small.DAM in the current directory.

It also adds the following registry entries to enable its automatic execution upon system Startup:



Propagation

Lager.DP propagates by mailing itself to several e-mail addresses gathered from the affected system.

It may use any of the following string as its Subject:


Attachments may be any of the following filenames:

Last update 01 March 2007

 

TOP

Malware :

Family: