Threat Database Worms W32.Pholdicon

W32.Pholdicon

By ZulaZuza in Worms

W32.Pholdicon is a worm that drops potentially harmful files and proliferates through network shares and removable media.

W32.Pholdicon looks as a Windows folder icon and propagates through removable media and network shares. Once run, W32.Pholdicon creates the potentially infected files. W32.Pholdicon creates the registry entry so that it can load automatically every time the computer user starts Windows. W32.Pholdicon drops and executes potentially infected files from the certain distant location.

File System Details

W32.Pholdicon may create the following file(s):
# File Name Detections
1. [MAPPED NETWORK DRIVE]\Photo.exe
2. [DRIVE LETTER]\Photo.exe
3. [DRIVE LETTER]\Photo\Photo.exe
4. [REMOVABLE DRIVE]\Photo.exe

Registry Details

W32.Pholdicon may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Photo" = "[DRIVE LETTER]\Photo\Photo.exe"

URLs

W32.Pholdicon may call the following URLs:

http://www.managtest.ru

Trending

Most Viewed

Loading...