Threat Database Worms W32.Extrat

W32.Extrat

By LoneStar in Worms

W32.Extrat is a worm that proliferates by creating copies of itself on removable drives and P2P file-sharing networks. W32.Extrat opens a back door on the infected computer system and steals information from the victim. W32.Extrat is connected with the remote access tools (RATs) called 'Spy-Net RAT' and 'Xtreme RAT'. When activated, W32.Extrat creates the particular file on the affected PC. W32.Extrat then creates the specific registry entry so that it can launch automatically whenever you boot up Windows. W32.Extrat enables cybercriminals to connect to a control server on TCP, create an HTTP proxy, log keystrokes, and make other harmful activities. W32.Extrat may embed itself into 'iexplore.exe', or any other process, which can be customized. W32.Extrat then proliferates further by creating copies of itself onto shared folders.

File System Details

W32.Extrat may create the following file(s):
# File Name Detections
1. %Windir%\installdir\server.exe

Registry Details

W32.Extrat may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\"Policies" = "%Windir%\installdir\server.exe"

Trending

Most Viewed

Loading...