Winmap32

Solo disponible en BuenasTareas
  • Páginas : 2 (469 palabras )
  • Descarga(s) : 0
  • Publicado : 3 de julio de 2009
Leer documento completo
Vista previa del texto
Virus Characteristics
This detection is for a worm. It attempts to spread to accessible drives by creating an autorun.inf file, which will run the worm automatically. Additional files may then beobtained to install additional malware.
Upon execution, the following registry keys are created: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B45FF030-4447-11D2-85DE-00C04FA35C89}
 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{8ECC055D-047F-11D1-A537-0000F8753ED1}\0026
 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BNDMSS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BNDMSS
 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E97E-E325-11CE-BFC1-08002BE10318}\v HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{8ECC055D-047F-11D1-A537-0000F8753ED1}\0026
 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BNDMSS
The following files are written to the root of writeable volumes:
%Root%\Autorun.inf%Root%\dmgr.exe
 
The following files may also be added to an infected host:
%Root%\RECYCLER\[Recylcer ID]\winmap32.exe
%WinDir%\system32\bndmss.exe
%WinDir%\system32\winmap32.exe

Contact maybe initiated with the following Domains:
mix.na[Removed].info
mix.c[Removed].biz
mix.cha[Removed].com
zon[Removed].info
bnew.h[Removed].com
newss.al[Removed].info

All Users:
Use current engine and DAT filesfor detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engineand DAT combination (or higher).
Additional Windows ME/XP removal considerations
Disabling System Restore
Windows ME and XP utilize a restore utility that backs up selected files automatically tothe C:\_Restore folder. This means that an infected file could be stored there as a backup file, and VirusScan will be unable to delete these files. You must disable the System Restore Utility...
tracking img