This worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 184,320 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 25 Nov 2012
Arrival Details
This worm arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Autostart Technique
This worm adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /m"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /y"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /r"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /c"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /p"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /o"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /e"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /q"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /w"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /s"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /i"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /a"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /u"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /v"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /z"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /x"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /f"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /t"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /g"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /b"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /j"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /n"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /h"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /d"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /k"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
zuexio = "%User Profile%\zuexio.exe /l"
Other System Modifications
This worm adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
Advanced
ShowSuperHidden = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\
Microsoft\Windows\WindowsUpdate\
AU
NoAutoUpdate = "1"
This report is generated via an automated analysis system.
Connect with us on
| | | |