W32.Addnu

By JubileeX in Worms

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 19
First Seen: November 13, 2012
Last Seen: November 17, 2022
OS(es) Affected: Windows

W32.Addnu is a worm that proliferates by creating copies of itself on removable drives. W32.Addnu also opens a back door on the corrupted PC. While being activated, W32.Addnu creates copies of itself to one of the particular locations on the targeted computer system. W32.Addnu then creates one of the particular registry entries so that it can start automatically every time you boot up Windows. W32.Addnu then connects to the specific remote location and opens a back door on the vulnerable PC. W32.Addnu may then get instructions from the command-and-control (C&C) server. W32.Addnu then creates copies of itself on removable drives.

File System Details

W32.Addnu may create the following file(s):
# File Name Detections
1. %UserProfile%\Local Settings\Application Data\Microsoft\svchost.exe
2. %UserProfile%\Local Settings\Application Data\Microsoft\rundll32.exe

Registry Details

W32.Addnu may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Windows Update" = "%UserProfile%\Local Settings\Application Data\Microsoft\svchost.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Windows Update" = "%UserProfile%\Local Settings\Application Data\Microsoft\rundll32.exe"

Trending

Most Viewed

Loading...