Threat Database Worms W32.Wapomi.D

W32.Wapomi.D

By JubileeX in Worms

Threat Scorecard

Threat Level: 10 % (Normal)
Infected Computers: 1
First Seen: March 1, 2013
Last Seen: February 7, 2023
OS(es) Affected: Windows

W32.Wapomi.D is a worm that circulates by replicating itself to network and removable drives. W32.Wapomi.D corrupts .exe, .html, .asp, .htm, and .aspx files, and aims at disabling anti-virus applications. W32.Wapomi.D also corrupts .exe files within .rar files stored on shared network resources. Once executed, W32.Wapomi.D adds the potentially harmful file, which is used to conceal the appearance of the worm. W32.Wapomi.D registers the file as a service. W32.Wapomi.D creates the registry subkey in an effort to applications. W32.Wapomi.D aims at restricting a lot of files related to anti-virus software from running. W32.Wapomi.D deletes registry entries under the subkey in order to block the PC from rebooting in Safe Mode. W32.Wapomi.D also modifies the Windows registry.

File System Details

W32.Wapomi.D may create the following file(s):
# File Name Detections
1. %DriveLetter%\recycle.{645FF040-5081-101B-9F08-00AA002F954E}\setup.exe
2. %SystemDrive%\[RANDOM CHARACTERS].sys
3. %DriveLetter%\autorun.inf

Registry Details

W32.Wapomi.D may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\SW\{eec12db6-ad9c-4168-8658-b03daef417fe}\{ABD61E00-9350-47e2-A632-4438B90C6641}\"Service" = "drmkaud"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[RANDOM CHARACTERS]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\"Start" = "3"

URLs

W32.Wapomi.D may call the following URLs:

searchstreamz.com

Trending

Most Viewed

Loading...