Threat Database Worms Worm.Kolabc.A

Worm.Kolabc.A

By Sumo3000 in Worms

Threat Scorecard

Ranking: 14,392
Threat Level: 50 % (Medium)
Infected Computers: 94
First Seen: May 24, 2011
Last Seen: July 11, 2023
OS(es) Affected: Windows

Worm.Kolabc.A is a malicious worm which spreads through removable drives and other computers connected to the network. Worm.Kolabc.A opens a back door to help remote attackers get full access to the compromised machine and makes changes to the Windows Firewall and other security reports by modifying the system registry. When Worm.Kolabc.A is installed onto the targeted PC, it drops a copy of itself in the Windows fonts folder. Worm.Kolabc.A makes effort to corrupt other PCs which are connected to the infected computer via a mapped network share. Worm.Kolabc.A also attempts to use certain ports to connect to some remote servers to get further instructions from its makers. Worm.Kolabc.A creates a unique 'Desktop.ini' file which changes the icon of its executable so that it will occur as a 'recycle bin' file, which then executes from the original Worm.Kolabc.A's executable. Delete Worm.Kolabc.A before it harms your PC.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Suspicious file
BitDefender Gen:Trojan.Heur.VP.fm0@am8ECzob
BitDefender Gen:Trojan.Heur.VP.fm0@aaM@Nlcb
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Trojan.Heur.VP.fm0@amouf3eb
Kaspersky Trojan.Win32.VBKrypt.darp
Fortinet MSIL/Agent.SH!tr.pws
Antiy-AVL Trojan/win32.agent.gen
Sophos Mal/MSIL-A
eSafe Win32.MSILAgent.SH.P
McAfee Artemis!63CBB1DAD54E
AhnLab-V3 Trojan/Win32.VBKrypt
BitDefender Gen:Trojan.Heur.VP.fm0@a4pElSeb
Kaspersky Trojan.Win32.VBKrypt.daqk
NOD32 probably a variant of Win32/VB.PTG

SpyHunter Detects & Remove Worm.Kolabc.A

File System Details

Worm.Kolabc.A may create the following file(s):
# File Name MD5 Detections
1. 8pyt.exe 38d42ab8f27c9a10d0a2678173a9abd2 14
2. Kobalc.exe 15717cd327a723820d71900611545917 11
3. e8wb.exe b7d92b68457272ddde8d2ce057dcf53d 11
4. 8l964.exe ba78d8e48a99127b52806d424d57989b 5
5. urlmon32.exe 7c11cd111476ccdf5bf395bf69756ba2 4
6. snvztea.exe 243e58918479b990209a3de43cafac9b 1
7. sv.exe
8. iexplorer.exe
9. umdmgr.exe
10. waw32.exe
11. avdrive32.exe
12. scvchost.exe
13. audiodh.exe
14. winupd01.exe
15. csrss.exe
16. jjdrive32.exe
17. winupd.exe
18. 715.exe
19. file.exe
20. 8pyt.exe
21. msvmcls64.exe
22. services.exe
23. lsass.exe
24. xfgn.exe
25. sysmngsr322.exe
26. wind7upd.exe
27. sysdiag64.exe
28. ihost.exe
29. wndrive32.exe
30. cidrive32.exe
31. taskmrg32.exe

Registry Details

Worm.Kolabc.A may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Management Service
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ file
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Advanced DHTML Enable
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft Update Setup
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft Driver Setup
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 788
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ winupdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MS Virtual CLS
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MicrosoftNAPC
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows automatic updates

Trending

Most Viewed

Loading...