WORM.COLOWNED.A
Name:
Worm.Colowned.a
Added:
February 19, 2012
Type:
Worm
Risk:
Low
Payload:
N/A
At risk systems:
Windows 95/98/ME/XP/NT/2003
Malware problems? We can help. Free Removal Tools.
Description:
When Worm.Colowned.a is executed, it performs the following activities:After execution it drops the following files:%Appdata%\taskhost.exe%systemdrive%\viewDrive.exe%systemdrive%\autorun.infThe autorun.inf files contains-[autorun]open=viewdrive.exedefault=1action=Open folder to view driveshell\open\command=viewDrive.exeshell\explore\command=viewDrive.exeuseautoplay= 1It modifies/creates the following registry entries:Windows Task Host = "%Appdata%\taskhost.exe"HKCU\Software\Microsoft\Windows\CurrentVersion\RunWindows Task Host = "%Appdata%\taskhost.exe"HKLM\Software\Microsoft\Windows\CurrentVersion\RunThe keys allow "taskhost.exe" to run every time Windows starts.
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4