W32.Leebad
Aliases: W32/Leebad-A
Variants: Worm.Win32.Leebad.C, W32/Leebad-B
Classification: Malware
Category: Computer Worm
Status: Active & Spreading
Spreading: Slow
Geographical info: North America
Removal: Easy
Platform: W32
Discovered: 05 Aug 2004
Damage: Low
Characteristics: W32.Leebad is a worm. It logs keystrokes and spreads by copying itself to the root of mapped drives. It was spotted August 5, 2004 and infects Windows systems.
W32.Leebad Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Leebad from your computer.
More details about W32.Leebad
W32.Leebad is a worm that logs keystrokes. It spreads by copying itself to the root of mapped drives. When the worm is executed, it copies itself to the root of each mapped drive as the following files: system32.exe and system32dll.dll. The worm requires both of these files to be able to run. After copying itself, it drops the files admin.bat and autorun.inf. The file admin.bat is a batch file that adds an administrator named "lee" to the infected computer. It has the password "abcd1234!@#". The file autorun.inf is a file that starts the worm whenever the root of the drive is viewed in Windows Explorer. Then, the worm logs keystrokes and monitors the system for windows with certain Chinese names.The W32.Leebad program may enter the system through network shares. An infected file may be placed in shared folders or resources. It may be saved with a file name similar to that of legitimate processes. Once the W32.Leebad application has been installed, it will create a backdoor. It searches for unused ports and randomly opens one. This will be used to connect to the Internet. The software will then notify the remote server that the installation has been completed.
Browse for more malware information
- W32.Leebad
- W32.Lemoor.A
- W32.Liac.A@mm
- W32.Likasimal
- W32.Lile.A
- W32.Lindo
- W32.Linkbot.A
- W32.Linkfars
- W32.Litar.Worm
- W32.Lofni.Worm
- W32.Logitall.A@mm
- W32.Lohack.C.Worm
- W32.Longbe@mm
- W32.Looked
- W32.Looksky.A@mm
- W32.Lorac
- W32.Losabel
- W32.Lovena.A@mm
- W32.Lovgate.AB@mm
- W32.Loxbot.A
- W32.Lunalight@mm
- W32.Mabezat.A
- W32.Madag.A
- W32.Madangel
- W32.Maddis.B
- W32.Mafeg
- W32.Magflag.A@mm
- W32.Mailbancos@mm
- W32.Maldal.C@mm
- W32.Mancsyn