Threat Database Rootkits Win32: Tiny-AMB

Win32: Tiny-AMB

By JubileeX in Rootkits

Threat Scorecard

Ranking: 12,984
Threat Level: 10 % (Normal)
Infected Computers: 598
First Seen: October 31, 2011
Last Seen: July 14, 2023
OS(es) Affected: Windows

Win32: Tiny-AMB is a computer infection known as a rootkit. Win32: Tiny-AMB is commonly known to perform malicious actions without any indication to the computer users. Win32: Tiny-AMB will execute upon startup of Windows. Once loaded, Win32: Tiny-AMB may prevent trusted anti-malware and anti-virus programs from being successfully detected and deleted. Additionally, Win32: Tiny-AMB may prevent other security features from running on a PC such as a firewall or spam blocker applications. It is very important that an updated spyware removal program capable of removing rootkits be used to completely delete Win32: Tiny-AMB.

File System Details

Win32: Tiny-AMB may create the following file(s):
# File Name Detections
1. C:\WINDOWS\System32\aswBoot.exe
2. C:\WINDOWS\system32\spoolsv.exe
3. C:\windows\system\hpsysdrv.exe
4. C:\WINDOWS\system32\wscntfy.exe
5. C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
6. %APPDATA%\win32:Tiny-AMB

Registry Details

Win32: Tiny-AMB may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer
HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon: 'Userinit' = '\userinit.exe, %Documents and Settings%\[UserName]\Application Data\win32:Tiny-AMB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Win32\win32:Tiny-AMB
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\
@="Service"
"DisableMonitoring"=dword:00000001

URLs

Win32: Tiny-AMB may call the following URLs:

www.packtrackplus.com

Trending

Most Viewed

Loading...