Threat Database Worms Win32.Brontok.AP@mm

Win32.Brontok.AP@mm

By Sumo3000 in Worms

Threat Scorecard

Ranking: 10,679
Threat Level: 10 % (Normal)
Infected Computers: 154
First Seen: March 8, 2012
Last Seen: August 9, 2023
OS(es) Affected: Windows

Win32.Brontok.AP@mm belongs to the Brontok family of worms, one of the preferred malware-delivery methods for criminals since their first appearance in 2006. Win32.Brontok.AP@mm in particular has been linked to a Trojan infection that hides the victim's files in an attempt to convince the computer user to purchase a useless bogus hard disk repair utility. ESG security researchers consider that any infection involving the Win32.Brontok.AP@mm or other members of the Brontok family as severe in nature and should be removed immediately with the aid of a reliable anti-malware program.

Symptoms of a Win32.Brontok.AP@mm-Related Malware Infection

There are many variants of the Win32.Brontok.AP@mm worm, and the symptoms necessarily change from one case to the next. Some symptoms that have been linked to this malware infection include the following:

  • Having an application closing immediately after starting up or having Windows rebooting when trying to launch an application, particularly security-related programs.
  • Having certain websites becoming inaccessible or being unable to update security software.
  • Not being able to modify folder options through Windows Explorer. This is particularly nasty when it comes to Win32.Brontok.AP@mm's associated with a hidden files fraud Trojan, since the victim is not able to set the hidden files' attribute back from hidden.
  • Having essential Windows components related to malware removal become disabled, such as the command shell, System restore, Task manager and the Windows Registry editor.

As you can see, the Win32.Brontok.AP@mm worm is not only designed to deliver malware, but also has been engineered to make malware infections more likely to take hold and much more difficult than normal to remove from the infected computer system.

Understanding the Win32.Brontok.AP@mm Family of Worms

Win32.Brontok.AP@mm is a worm that tends to spread from removable memory drives. Win32.Brontok.AP@mm is able to send out mass emails from the infected computer's email address to all of that email account's contacts. These email messages help spread Win32.Brontok.AP@mm from one computer to another. Win32.Brontok.AP@mm creates a folder and, in order to download a text file into that folder, connects to the Internet. It copies itself several times, using several different extensions (including EXE, PIC, SCR, and COM. The file names that the Win32.Brontok.AP@mm worm uses tend to be the same for common Windows system files, such as lsass, csrss, smss, services and winlogon. One of the ways in which the Win32.Brontok.AP@mm worm makes it more likely that the computer user will open it is by using the Windows 'New Folder' icon, making it seem as if it is a directory rather than an executable file.

Trending

Most Viewed

Loading...