W32/Newurg-A is a worm for the Windows platform.
W32/Newurg-A includes functionality to access the internet and communicate with a remote server via HTTP.
W32/Newurg-A is a worm for the Windows platform.
W32/Newurg-A includes functionality to access the internet and communicate with a remote server via HTTP.
When first run W32/Newurg-A copies itself to <System>\<worm filename>.exe and creates the file <current folder>\<random characters>.exe.
The file <current folder>\<random characters>.exe is detected as Troj/Dloadr-AQQ.
The following registry entries are created to run nordsys.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Nord
<System>\<worm filename>.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Nord
<System>\<worm filename>.exe
W32/Newurg-A sets the following registry entries, disabling the automatic startup of other software:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4
Note: disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection Firewall (ICF).