Sophos

W32/Pykse-C

Aliases
  • Win32/Persky.I
  • worm
  • Worm.Win32.Skipi.b
  • W32/Pykse.worm.b
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2007 (4.23)
Protection available since 12 September 2007 00:50:25 (GMT)
Detected by All Sophos products

Action

More Information

W32/Pykse-C is a worm for the Windows platform.

W32/Pykse-C includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/Pykse-C copies itself to:

<System>\mshtmldat32.exe
<System>\sdrivew32.exe
<System>\winlgcvers.exe
<System>\wndrivs32.exe

As well as to any removable drives as:

<Removable Drive>:\game.exe
<Removable Drive>:\zjbs.exe

It will also create an AUTORUN.INF file whihc is detected as W32/Pykse-C.

The following registry entry is created to run mshtmldat32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Services Start
mshtmldat32.exe

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Policies Options
m

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Windows Sys
explorer.exe mshtmldat32.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Logon Settings
mshtmldat32.exe

Registry entries are created under:

HKCU\Software\RMX\cfg
HKLM\SOFTWARE\RMX\cfg

Sophos's anti-virus products include Behavioral Genotype® Protection, which can proactively guard against new threats without requiring an update. Sophos customers have been protected against W32/Pykse-C (detected as Mal/Behav-043) since version 4.18.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer