Threat Database Worms Worm:Win32/Vobfus.AD

Worm:Win32/Vobfus.AD

By SpideyMan in Worms

Worm:Win32/Vobfus.AD is a malicious computer worm which is a self-replicating program. Worm:Win32/Vobfus.AD can propagate from one computer system to another. Worm:Win32/Vobfus.AD will make effort to propagate by sending a link that includes a malicious download to all user's email contacts. Once Worm:Win32/Vobfus.AD is detected, it will make changes to system settings that lead to further injuries for the targeted computer. Worm:Win32/Vobfus.AD will attempt to connect with remote hosts and enable the attacker to get remote access to the affected computer.

File System Details

Worm:Win32/Vobfus.AD may create the following file(s):
# File Name Detections
1. c:\tymrtg.exe
2. %UserProfile%\buoufo.exe
3. %Temp%\winfkjk.exe
4. c:\autorun.inf

Registry Details

Worm:Win32/Vobfus.AD may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AMSINT32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32
HKEY_CURRENT_USER\Software\Apcrmkeh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000
HKEY_CURRENT_USER\Software\Apcrmkeh\-72398023
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amsint32\Security
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]UacDisableNotify = 0x00000001

Trending

Most Viewed

Loading...