Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

WORM.HAMWEQ.A

 

 

Name:

Worm.Hamweq.a

Descr. Added:

January 15, 2013

Type:

Worm

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When Worm.Hamweq.a is executed, it performs the following activities:

It drops files on to the system at the following locations:

%SystemDrive%\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\hostsv.exe
%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-106669\w68v12.exe
%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe
%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-917678\nepro0xz.exe
%AppData%\1.exe
%AppData%\2.exe
%AppData%\3.exe
%AppData%\4.exe

It creates/modifies the following registry entries:

Taskman =  "%SystemDrive%\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\hostsv.exe"
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

wi68 = "%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-106669\w68v12.exe"
HKU\Software\Microsoft\Windows\CurrentVersion\Run

t4q = "%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe"
HKU\Software\Microsoft\Windows\CurrentVersion\Run

nepro0xz = "%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-917678\nepro0xz.exe"
HKU\Software\Microsoft\Windows\CurrentVersion\Run

Shell = "%SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-917678\nepro0xz.exe, %SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-106669\w68v12.exe,explorer.exe, %SystemDrive%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe"
HKU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
 

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4