Threat Database Worms W32.Scrshotvid

W32.Scrshotvid

W32.Scrshotvid is a Windows platform worm that spreads by replicating itself across mapped and removable drives. W32.Scrshotvid may enter a computer system bundled or hidden in a legitimate download. W32.Scrshotvid is also able to open a backdoor into a compromised PC, giving remote attackers unauthorized access to the system. W32.Scrshotvid allows remote attackers to conduct malicious activities such as log keystrokes, download harmful files and capture screen or web cam shots. W32.Scrshotvid is a privacy risk that should be removed once detected.

File System Details

W32.Scrshotvid may create the following file(s):
# File Name Detections
1. %DriveLetter%\imagem.exe
2. %System%\msnmsg.exe
3. %DriveLetter%\autorun.inf

Registry Details

W32.Scrshotvid may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\"Msnmsg" = "%System%\msnmsg.exe"

Trending

Most Viewed

Loading...