WORM.HAMWEQ.A
Name:
Worm.Hamweq.a
Descr. Added:
January 15, 2013
Type:
Worm
Risk:
Low
Payload:
N/A
At risk systems:
Windows 95/98/ME/XP/NT/2003
Malware problems? We can help. Free Removal Tools.
Description:
When Worm.Hamweq.a is executed, it performs the following activities:It drops files on to the system at the following locations:%SystemDrive%\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\hostsv.exe%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-106669\w68v12.exe%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-917678\nepro0xz.exe%AppData%\1.exe%AppData%\2.exe%AppData%\3.exe%AppData%\4.exeIt creates/modifies the following registry entries:Taskman = "%SystemDrive%\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\hostsv.exe"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogonwi68 = "%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-106669\w68v12.exe"HKU\Software\Microsoft\Windows\CurrentVersion\Runt4q = "%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe"HKU\Software\Microsoft\Windows\CurrentVersion\Runnepro0xz = "%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-917678\nepro0xz.exe"HKU\Software\Microsoft\Windows\CurrentVersion\RunShell = "%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-917678\nepro0xz.exe, %SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-106669\w68v12.exe,explorer.exe, %SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe"HKU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4