Home Malware Programs Viruses Redplut

Redplut

Posted: March 28, 2006

Redplut is a worm, also known as W32.Redplut and Email-Worm.Win32.VB.bd, that tries to spread its infection through open file shares and in the process lowers the user's security settings. Redplut does not create any cookies or registry keys. Redplut installs itself in the registry and affects Windows.

Aliases

W32.Redplut
Email-Worm.Win32.VB.bd

File System Modifications

  • The following files were created in the system:
    # File Name
    1 about.htm
    2 gcc.exe
    3 lcc.exe
    4 msdef.exe
    5 notepad.exe
    6 pluto.bmp
    7 services.exe
    8 setup32i.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunPluto!pagerHKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunsystemhandlerHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunPluto!pagerHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsystemhandler
Loading...