Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

WORM.HAMWEQ.A

 

 

Name:

TrojanSpy.Vwealer.NS5

Descr. Added:

January 13, 2013

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When TrojanSpy.Vwealer.NS5 is executed, it performs the following activities:

After execution, it drops the following files:

%Temp%\~DF9FA3.tmp
%WinDir%\system32\New Folder.exe
%SystemDrive%\AUTOEXEC.exe
%SystemDrive%\yahoopath.txt

It modifies/creates the following registry entries:

Userinit = "C:\WINDOWS\system32\userinit.exe,"
Userinit = "userinit.exe,New Folder.exe"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

New Folder = "New Folder.exe"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4