Threat Database Worms W32.Greypac

W32.Greypac

By Domesticus in Worms

W32.Greypac is a worm that is able to copy itself to shared Internet folders. W32.Greypac may circulate to the corrupted PC as a malevolent email attachment. While being activated, W32.Greypac copies itself to the specific location of the targeted computer system. W32.Greypac creates the particular registry entry so that it can load automatically whenever you boot up Windows. W32.Greypac then downloads the particular image file and shows it. W32.Greypac may also create and illustrate a window with the title 'Main_Window'. W32.Greypac can enumerate all system drivers from C through Z. W32.Greypac searches fixed drives for files with the file extensions such as '.htm' and '.php'.

File System Details

W32.Greypac may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\rcs.jpg
2. C:\Settings\search.cmd

Registry Details

W32.Greypac may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Search" = "C:\Settings\search.cmd"

URLs

W32.Greypac may call the following URLs:

martixstar.net

Trending

Most Viewed

Loading...