Sophos

W32/Pahati-A

Aliases
  • W32/Pahati.worm
  • Virus.Win32.VB.ef
  • Win32/VB.NKT
  • worm
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 1 November 2007 15:30:09 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Pahati-A is a worm for the Windows platform.

When first run W32/Pahati-A copies itself to:

<Root>\<original file name>.doc .exe
<Program Files>\Microsoft Office\winword.exe
<Root>\System Volume Information\word32.exe

and creates the file <Temp>\~dfaf02.tmp.

The following registry entry is created to run word32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
(Default)
<Root>\System Volume Information\WORD32.EXE

The following registry entry is changed to run winword.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
explorer.exe, <Program Files>\Microsoft Office\WINWORD.EXE

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ClassicViewState
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer