Threat Database Worms Worm.Abfewsm.A

Worm.Abfewsm.A

By SpideyMan in Worms

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 123
First Seen: December 8, 2010
Last Seen: March 24, 2024
OS(es) Affected: Windows

Worm.Abfewsm.A is a self-replicating and malicious worm. Worm.Abfewsm.A spreads by replicating itself in the folder used for copying files onto CDs. Worm.Abfewsm.A is able to modify a variety of system settings and services. Worm.Abfewsm.A blocks the affected PC user's access to the Control Panel and other registry editors. Worm.Abfewsm.A also changes the settings or even completely disables the computer's firewall. Worm.Abfewsm.A is generated to allow remote attackers gain access to the corrupted machine. When installed, Worm.Abfewsm.A makes changes to some processes automatically without a user's intervention. Uninstall Worm.Abfewsm.A as quickly as possible.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Worm/Generic.BBIE
eTrust-Vet Win32/Khatraxe.A
Sophos Mal/HckPk-E
AntiVir TR/Autoit.tkw
Comodo Worm.Win32.Autoit.FQ0
AVG Worm/Autoit.YKR
AhnLab-V3 Dropper/Win32.Autoit
CAT-QuickHeal Worm.AutoIt.k
AVG Worm/Autoit.AECA
AhnLab-V3 Win-Trojan/Autorun.506687
AntiVir TR/Crypt.CFI.Gen
Comodo Worm.Win32.Autorun.Autoit_AH0
BitDefender Trojan.Generic.2323748
Kaspersky Trojan-Dropper.Win32.Autoit.y
K7AntiVirus Trojan

SpyHunter Detects & Remove Worm.Abfewsm.A

File System Details

Worm.Abfewsm.A may create the following file(s):
# File Name MD5 Detections
1. okomoh.sys 2046d5dbd0bd74134083d1baecce81f5 36
2. mIRC.exe faa932b50030d848385f9ac6a215e5ba 25
3. pqremovezotob.com 825bd2da5eb9372a5bd61fb10e2e5c18 12
4. KHATRA.exe b58067d75a08193f86a9afa4d8d14404 12
5. Xplorer.exe cb69637f911341a170505743b64ab267 8
6. Xplorer.exe 6a5867abd4754ceac34e164ba608f37b 2
7. KHATRA.exe b4380864d64c91c7501aa7ff7118817a 2
8. KHATRA.exe 15dfa7c7c644a9a9e1d4834af9d5337c 2
9. okomoh.sys

Registry Details

Worm.Abfewsm.A may create the following registry entry or registry entries:
HKLM\SYSTEM\ControlSet001\Services\mnmsrvc

Trending

Most Viewed

Loading...