Threat Database Worms W32.Seswol.B

W32.Seswol.B

By JubileeX in Worms

Threat Scorecard

Ranking: 13,057
Threat Level: 10 % (Normal)
Infected Computers: 63
First Seen: March 21, 2013
Last Seen: August 2, 2023
OS(es) Affected: Windows

W32.Seswol.B is a worm that is circulates through removable drives and encrypts certain files on the corrupted PC. W32.Seswol.B encrypts all files whose extension is not '.sys' on all drives, except for files located on C: drive. When run, W32.Seswol.B creates malevolent files on all connected removable drives. W32.Seswol.B creates the registry entry. W32.Seswol.B also creates the registry entry so that it can load automatically whenever you start Windows.

File System Details

W32.Seswol.B may create the following file(s):
# File Name Detections
1. %System%\SVCHOST32.EXE
2. [DRIVE LETTER]:\Setup.EXE
3. [DRIVE LETTER]:\autorun.INF

Registry Details

W32.Seswol.B may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\"MyDate" = "[DATE]"

URLs

W32.Seswol.B may call the following URLs:

searcheira.com

Trending

Most Viewed

Loading...