Zone Labs LLC
ZoneAlarm Spyware Alert
  
  How useful was this article?
 Very  Somewhat  Not at all      
Provide more feedback  
 
Virus Information Center
The Virus Information Center serves as a rich, up-to-the-minute resource, containing detailed information on viruses, worms, Trojans, and hoaxes, as well as valuable documentation on the implementation of comprehensive antivirus protection and internet security.
Virus Information Search Results
 
Virus Name: Lioten.LE
Pervasiveness:  
3 of 5
Destructiveness:  
3 of 5
Wildness:  
2 of 5
Type: Worm
Aliases: [Win32/]SdBot.37888!Worm (InoculateIT); [Win32/]Sdbot.113940!Dropper (InoculateIT); [W32/]Sdbot.HAS (F-Secure); [Win32/]Lioten.LE; [TROJ_]MULTDROP.AL (Trend); [Troj/]Mu ltidr-DA (Sophos); [W32.]Randex (Symantec); [Backdoor.]Win32.IRCBot.bl (Kaspersky); [Win32/]Lioten.LE; [Win32/]Lioten.LE; [WORM_]SDBOT.ASP (Trend);
 
Date Modified: 30-May-2006
Date Published: 30-May-2006
 
Description:

Win32/Lioten is a family of worms that spread via network shares. Early variants spread via network shares only, and had no payload, but modern variants can also spread by exploiting Windows vulnerabilities and act as IRC controlled backdoors. Lioten worms are often found packaged with variants of Win32.Ranck trojan .

This particular variant of Lioten is distributed as a 37,888 byte Win32 executable, that exhibits the following specific characteristics:

When executed this variant copies itself to the %System% directory as YIKYLOHI.EXE and makes the following modifications to the registry to ensure that this file is executed at each Windows system start:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\azixegoira = "yikylohi.exe"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\azixegoira = "yikylohi.exe"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\azixegoira = "yikylohi.exe"

Note: '%Syste m%' is a variable location. The malware determines the location of the current system directory by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32.

For more detailed information regarding the functionality of the Win32.Lioten family, please visit the Win32.Lioten description elsewhere in our encyclopedia .



 

Copyright ©1999-2006 Zone Labs LLC, 475 Brannan Street, San Francisco, CA 94107, USA.
All rights reserved. All other trademarks are the property of their respective owners.

Privacy Policy