Examples of W32/VBWormMem-A include:
Example 1
File Information
- Size
- 2.0M
- SHA-1
- 86f60337788c2bc26c1e059bd7fa29936a5b054f
- MD5
- d35d3194b87c16f4bd18233a0805c414
- CRC-32
- ab992bfb
- File type
- Windows executable
- First seen
- 2007-07-03
Runtime Analysis
Copies Itself To
- C:\WINDOWS\system32\system.exe
- C:\WINDOWS\userinit.exe
- F:/forever.exe
Dropped Files
- c:\Documents and Settings\test user\Local Settings\Temp\~DF5C6A.tmp
- F:/AutoRun.inf
- c:\Documents and Settings\test user\Local Settings\Temp\~DF8B77.tmp
- C:\WINDOWS\kdcoms.dll
Registry Keys Modified
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
- ShowSuperHidden
- 0x00000000
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- Userinit
- C:\WINDOWS\userinit.exe
Processes Created
- c:\windows\explorer.exe
- c:\windows\system32\system.exe
- c:\windows\userinit.exe
Example 2
File Information
- File type
- application/x-ms-dos-executable