Infection Channel: Downloaded from the Internet, Dropped by other malware, Propagates via removable drives
This worm arrives by connecting affected removable drives to a system. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 102,400 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 03 Oct 2012
Arrival Details
This worm arrives by connecting affected removable drives to a system.
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This worm drops the following copies of itself into the affected system:
- %User Startup%\svchost..exe
(Note: %User Startup% is the current user's Startup folder, which is usually C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup on Windows NT, and C:\Documents and Settings\{User name}\Start Menu\Programs\Startup.)
Propagation
This worm drops the following copy(ies) of itself in all removable drives:
NOTES:
Upon execution, the malware checks the OS version of the affected machine. If it is Windows Vista or Windows 7, it drops the following copies of itself on the affected system:
(Note: %Desktop% is the current user's desktop, which is usually C:\Users\{user name}\Desktop on Windows Vista or Windows 7.)
If the OS version is not Windows Vista or Windows 7, it drops the following copies of itself on the affected system:
- %Windows%\system\svchost..exe
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT).
For Windows Vista or Windows 7, %User Startup% is the current user's Startup folder, which is usually C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup on Windows Vista or Windows 7.
It searches for folders in all removable drives then drops copies of itself inside the folder as {folder name}.EXE.
Connect with us on
| | | |