W32/VBWormMem-A

Category: Viruses and Spyware Protection available since:13 Dec 2012 20:02:25 (GMT)
Type: Win32 worm Last Updated:13 Dec 2012 20:02:25 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of W32/VBWormMem-A include:

Example 1

File Information

Size
2.0M
SHA-1
86f60337788c2bc26c1e059bd7fa29936a5b054f
MD5
d35d3194b87c16f4bd18233a0805c414
CRC-32
ab992bfb
File type
Windows executable
First seen
2007-07-03

Runtime Analysis

Copies Itself To
  • C:\WINDOWS\system32\system.exe
  • C:\WINDOWS\userinit.exe
  • F:/forever.exe
Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\~DF5C6A.tmp
  • F:/AutoRun.inf
  • c:\Documents and Settings\test user\Local Settings\Temp\~DF8B77.tmp
  • C:\WINDOWS\kdcoms.dll
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
    ShowSuperHidden
    0x00000000
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Userinit
    C:\WINDOWS\userinit.exe
Processes Created
  • c:\windows\explorer.exe
  • c:\windows\system32\system.exe
  • c:\windows\userinit.exe

Example 2

File Information

File type
application/x-ms-dos-executable

download Try Sophos products for free
Download now