W32.Redlofs
Aliases: N/A
Variants: N/A
Classification: Malware
Category: Computer Worm
Status: Active & Spreading
Spreading: Slow
Geographical info: North America
Removal: Easy
Platform: W32
Discovered: 18 Nov 2008
Damage: Low
Characteristics: W32.Redlofs is a low risk worm. It infects Windows systems. It spreads by copying itself to hard drives and removable drives. When these drives are connected to another computer, the worm copies itself to those drives to propagate itself.
W32.Redlofs Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Redlofs from your computer.
More details about W32.Redlofs
The worm W32.Redlofs propagates on fixed, network and removable drives by creating a copy of itself using the autorun.inf file. It also modifies various system files to prevent users from cleaning the infection. It uses the standard windows folder icon as its own icon in an attempt to confuse users. It searches for folders and sets them to hidden. It hides files and file extensions by setting the attributes to hidden by default. Afterwards, it copies itself to that location as the following file: [FOLDER NAME].exe. The threat adds the item “Scan for viruses by Bkav2006” to the right-click menu. If the registry editor is opened, the worm may log out of the administrator account. It also adds a flashing pixel rotating around the mouse pointer when the computer is restarted.The W32.Redlofs application makes some changes on the user’s web browser. This includes changes on the error page, home page and search page. Users may also be redirected to unsolicited websites when a URL (Uniform Resource Locator) is mistyped. The W32.Redlofs software also executes a proxy server on a TCP (Transfer Control Protocol) port. The Trojan program may be controlled by a remote intruder through the open port. Some commands that may be carried out on the affected computer are starting DoS (Denial of Service) attacks, uploading and downloading of unwanted content and removing important files from the user’s computer.
Browse for more malware information
- W32.Redlofs
- W32.Redlofwen
- W32.Redplut
- W32.Redzed@mm
- W32.Refaz
- W32.Refoav@mm
- W32.Reidana.A
- W32.Relfeer
- W32.Relnek.A
- W32.Remabl.Worm
- W32.Remadmin
- W32.Remadworm
- W32.Renama.A@mm
- W32.Renco@mm
- W32.Repad.Worm
- W32.Reploret
- W32.Resdoc
- W32.Resik.A
- W32.Rexli.A@mm
- W32.Reztrict@mm
- W32.Ridnu.B
- W32.Rinbot!gen
- W32.Rispif.A
- W32.Rokid
- W32.Ronoper.B@mm
- W32.Rontokbro
- W32.Rontokbro.AN@mm
- W32.Row@mm
- W32.Ruland.A@mm
- W32.Rungbu