Welcome to the Virus Encyclopedia of Panda Security.
It carries out several modifications in the Windows Registry, which prevent the computer from working properly. It disables the function Search of the Start menu and System Restore. It spreads through removable, shared and mapped drives.
|First detected on:||April 19, 2008|
|Detection updated on:||Nov. 4, 2008|
|Yes, using TruPrevent Technologies
Radulambu.A is a worm that reaches the computer passing itself off as an image. When it is run, the Windows image viewer is opened, so that the user is not aware that the executed file was malicious.
Additionally, it carries out several modifications in the Windows Registry, which prevent the user from carrying out the following actions, among others:
- Doing searches in a fast and straight way, as it disables the option Search from the Start menu.
- Restoring system, which is used to undo changes in the system and recover previously created restore points.
Radulambu.A reaches the computer passing itself off as an image. It spreads through removable, mapped and shared drives.
Radulambu.A is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.
However, it could be easily recognized if the user is browsing through the Internet, as it modifies the title of the Internet Explorer windows, changing it to the following text:
++++ Hey, Hokage/babon (Anbu*TeamSampit), Is this My places, Wanna start a War ++++