Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2007 (4.23) |
| Protection available since | 12 September 2007 00:50:25 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Pykse-C is a worm for the Windows platform.
W32/Pykse-C includes functionality to access the internet and communicate with a remote server via HTTP.
When first run W32/Pykse-C copies itself to:
<System>\mshtmldat32.exe
<System>\sdrivew32.exe
<System>\winlgcvers.exe
<System>\wndrivs32.exe
As well as to any removable drives as:
<Removable Drive>:\game.exe
<Removable Drive>:\zjbs.exe
It will also create an AUTORUN.INF file whihc is detected as W32/Pykse-C.
The following registry entry is created to run mshtmldat32.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Services Start
mshtmldat32.exe
Registry entries are set as follows:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Policies Options
m
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Windows Sys
explorer.exe mshtmldat32.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Logon Settings
mshtmldat32.exe
Registry entries are created under:
HKCU\Software\RMX\cfg
HKLM\SOFTWARE\RMX\cfg
Sophos's anti-virus products include Behavioral Genotype® Protection, which can proactively guard against new threats without requiring an update. Sophos customers have been protected against W32/Pykse-C (detected as Mal/Behav-043) since version 4.18.
