Crutle_b details

  • Description

    Crutle.b is a worm that spreads via IRC chats and through file sharing networks using popular Kazaa software. Once executed, the parasite silently installs itself to the system and creates a folder with numerous infected files inside it. These files have meaningful names. Then Crutle.b shares a new folder using the Kazaa program, making files inside this directory accessible to other peer-to-peer clients. The worm doesn't carry any destructive payload, as it is designed only to spread.

  • Exe

    lsass.exe, msfck.exe, mswin32.exe, taskbar.exe, win.exe

  • Registry

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinexecHKEY_CURRENT_USERSoftwareKazaaLocalContentDisableSharing=0HKEY_CURRENT_USERSoftwareKazaaResultsFilterfirewall_filter=0HKEY_CURRENT_USERSoftwareKazaaResultsFiltervirus_filter=0