Threat Database Worms Email-Worm.Ackantta

Email-Worm.Ackantta

Email-Worm.Ackantta is a mass-mailing worm. Email-Worm.Ackantta is able to propagate from one system to another by harvesting the e-mail addresses in a compromised PC and sending infected e-mails to all the harvested addresses. Email-Worm.Ackantta may also download harmful malware onto a computer system therefore the immediate removal of Email-Worm.Ackantta from an infected machine is strongly advised.

Aliases

5 security vendors flagged this file as malicious.

Anti-Virus Software Detection
- Win-Trojan/Dracur.439808
- Trojan-Dropper
- Worm:Win32/Prolaco
- Mal/CryptBox-A
- Trojan-Dropper.Win32.Typic.bev

File System Details

Email-Worm.Ackantta may create the following file(s):
# File Name Detections
1. %AppData%\SystemProc\lsass.exe
2. %System%\AdobeARMI.exe
3. %ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
4. %ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
5. %ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf

Registry Details

Email-Worm.Ackantta may create the following registry entry or registry entries:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
[HKEY_CURRENT_USER\Identities]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]

Related Posts

Trending

Most Viewed

Loading...