|
|
|
|
|
|
malware Type: virus
Discovered: 2006-08-21
Added: 2006-08-25
Threat ID: 147482 |
Win32.HLLW.Nert is a virus that changes internet security settings and transmits personal information to remote computers. The Nert virus attempts to disable Windows Security Center notification options and firewall.
|
Risk Description:
Ease of Removing Win32.HLLW.Nert
Creates new unique registry entries
File contents uniquely generated
Runs as a service
Consistently named
Consistent file contents
Creates new registry entries with consistent data
Privacy Risks/Security Changes of Win32.HLLW.Nert
Changes internet security settings
Transmits personal data to remote computers
Damage/Intrusion/Annoyance of Win32.HLLW.Nert
Autoruns at startup without an option to be disabled
Modifies noncritical registry entries
Propagation/Saturation of Win32.HLLW.Nert
Spreads by exploiting vulnerabilities [VIRUS ONLY]
Mimics legitimate file names
Creates new files
Infects through a blind IP address attack [VIRUS ONLY]
Infects through Internet Relay Chat (IRC) [VIRUS ONLY]
Infects through Peer-2-Peer Software
Displays fake error messages |
alias(s) of Win32.HLLW.Nert
worm/IRCBot.9609
W32/Ircbot.TU
Win32:Ircbot-ABC
backdoor.Generic3.GBC
Backdoor.IRCBot.st
trojan.IRCBot-689
Win32/Cuebot.J!Worm
Win32/Cuebot.J
W32/Graweg.B!tr.bdr
Backdoor.Win32.IRCBot.st
Backdoor.Win32.IRCBot.uv
IRC-Mocbot!MS06-040
Backdoor:Win32/Graweg.A!CME-482
Win32/IRCBot.OO
W32/Ircbot.BVM
W32/Oscarbot.KD.worm!CME-482
W32/Cuebot-L
Trojan/Exploit.MS06-040.b
Backdoor.IRCBot.F121
Backdoor.IRCBot.AAH |
Further details about Win32.HLLW.Nert may be available at our Malware Research Center
|
|
|
|
|
|